Home › Intelligence › Brief
BREACH BRIEF⚪ Informational Advisory

Cloudflare Announces Plan to Become a Public Certificate Authority, Targeting Free and Post‑Quantum TLS Certificates

Cloudflare announced its intent to become a public certificate authority, acquiring GlobalSign’s trusted root and seeking inclusion in major browser and OS root programs. The move will broaden free TLS availability and introduce post‑quantum certificates, prompting organizations to reassess third‑party trust and certificate‑management controls.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 blog.cloudflare.com
⚪
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
blog.cloudflare.com

Cloudflare Announces Plan to Become a Public Certificate Authority, Targeting Free and Post‑Quantum TLS Certificates

What Happened – Cloudflare disclosed its intent to operate as a public Certificate Authority (CA). The company has applied for root‑program inclusion with Chrome, Apple, Microsoft and Mozilla, and signed an agreement to acquire GlobalSign’s trusted root to achieve immediate device coverage. It also announced a roadmap to issue post‑quantum‑resistant certificates once the industry‑wide Quantum‑Resistant Root Program matures.

Why It Matters for Trust & Control Assurance

  • The addition of a new, widely‑used CA expands the supply‑chain of trust; continuous monitoring of CA root‑program status becomes a core control‑assurance activity.
  • Organizations must capture evidence of CA onboarding, policy compliance and root‑program acceptance to satisfy third‑party risk and audit requirements.
  • Post‑quantum certificate plans introduce new cryptographic controls that need to be tracked in a defensible, auditable way.

Who Is Affected – Cloud service providers, SaaS platforms, enterprises that rely on TLS certificates for web, API and internal communications, and any organization that includes CA trust in its third‑party risk register.

Recommended Actions

  • Add Cloudflare’s CA to your third‑party risk register and begin continuous monitoring of its root‑program inclusion status.
  • Collect and retain evidence of GlobalSign root acquisition and future post‑quantum policy publications for audit readiness.
  • Review internal certificate‑issuance processes to ensure they can ingest certificates from a new public CA without breaking compliance controls.

Source: Cloudflare Security Blog

Technical Notes – Cloudflare’s strategy combines acquisition of an existing GlobalSign root (trusted across browsers, OSes and legacy devices since 2012) with a new root built for future programs that may deprecate older roots. The company aims to issue free, automated TLS certificates and later support quantum‑resistant algorithms as defined by Chrome’s upcoming Quantum‑Resistant Root Program. No certificates are being issued today. Source: same as above

📰 Original Source
https://blog.cloudflare.com/cloudflare-certificate-authority/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →