Cloudflare Announces Plan to Become a Public Certificate Authority, Targeting Free and Post‑Quantum TLS Certificates
What Happened – Cloudflare disclosed its intent to operate as a public Certificate Authority (CA). The company has applied for root‑program inclusion with Chrome, Apple, Microsoft and Mozilla, and signed an agreement to acquire GlobalSign’s trusted root to achieve immediate device coverage. It also announced a roadmap to issue post‑quantum‑resistant certificates once the industry‑wide Quantum‑Resistant Root Program matures.
Why It Matters for Trust & Control Assurance
- The addition of a new, widely‑used CA expands the supply‑chain of trust; continuous monitoring of CA root‑program status becomes a core control‑assurance activity.
- Organizations must capture evidence of CA onboarding, policy compliance and root‑program acceptance to satisfy third‑party risk and audit requirements.
- Post‑quantum certificate plans introduce new cryptographic controls that need to be tracked in a defensible, auditable way.
Who Is Affected – Cloud service providers, SaaS platforms, enterprises that rely on TLS certificates for web, API and internal communications, and any organization that includes CA trust in its third‑party risk register.
Recommended Actions
- Add Cloudflare’s CA to your third‑party risk register and begin continuous monitoring of its root‑program inclusion status.
- Collect and retain evidence of GlobalSign root acquisition and future post‑quantum policy publications for audit readiness.
- Review internal certificate‑issuance processes to ensure they can ingest certificates from a new public CA without breaking compliance controls.
Source: Cloudflare Security Blog
Technical Notes – Cloudflare’s strategy combines acquisition of an existing GlobalSign root (trusted across browsers, OSes and legacy devices since 2012) with a new root built for future programs that may deprecate older roots. The company aims to issue free, automated TLS certificates and later support quantum‑resistant algorithms as defined by Chrome’s upcoming Quantum‑Resistant Root Program. No certificates are being issued today. Source: same as above