Big Tech & Innovation

Cloudflare Plans Free Certificate Authority as an Alternative to Let’s Encrypt

The internet infrastructure company is seeking browser approvals and preparing post-quantum certificates as shorter renewal cycles increase the importance of automation.

By Emma Clarke Edited by Michael Foster Published: Updated:
Cloudflare Plans Free Certificate Authority as an Alternative to Let’s Encrypt
Cloudflare plans free, automated TLS certificates and a new post-quantum format, expanding the choice of providers for secure web connections. Illustration: Cloudflare

Key Notes

  • Cloudflare plans to add a free certificate authority with automated issuance and renewal for website operators.
  • The GlobalSign root acquisition and browser trust applications remain pending before the planned service can begin.
  • Production post-quantum certificates are targeted for early 2027 as businesses prepare for changing security standards.

Cloudflare plans to offer free, automatically renewed TLS certificates through its own public certificate authority, adding another provider to the infrastructure that keeps websites and online transactions secure.

The company announced the initiative on September 29. It is seeking recognition from major browser and operating-system vendors and preparing a new certificate format designed for the post-quantum era.

For businesses, the proposal touches a routine but essential operational task: keeping the credentials behind encrypted connections valid. Cloudflare had not begun issuing certificates through the new authority at the time of the announcement.

A New Provider for a Critical Internet Service

Certificate authorities verify the identities used in secure web connections. Browsers rely on trusted roots to decide whether to accept those certificates, making compatibility a prerequisite for a new issuer to reach customers.

Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs. It has also agreed to acquire publicly trusted root certificate authority key material from GlobalSign. The relevant root has been trusted since 2012, helping address compatibility with older devices.

The transaction remains pending. Cloudflare’s press release says closing is expected within two months, subject to customary conditions. Conventional certificate issuance is due to follow the browser application and acceptance process.

The free model already has an established precedent. Let’s Encrypt, operated by the nonprofit Internet Security Research Group, provides certificates at no charge and automates issuance and renewal through an open protocol. Cloudflare’s entry would give website operators an additional choice within that model.

Shorter Lifetimes Raise the Value of Automation

The timing matters because certificate management is becoming more demanding. A schedule approved by the CA/Browser Forum reduces maximum public TLS certificate lifetimes in stages, reaching 47 days in March 2029.

Shorter lifetimes limit how long outdated certificate information can remain valid. They also make dependable replacement systems more important: organizations with large numbers of domains and services will need to handle renewals more frequently.

Cloudflare plans to build around ACME, the standard for automated certificate management, and require support for ACME Renewal Information. That mechanism lets an issuer signal when a certificate should be replaced, including before its normal expiry.

For an online retailer or financial-services platform, the practical value would lie in reducing manual maintenance and interruption risk. A free certificate still needs working renewal software, monitoring and a tested response when something fails.

Post-Quantum Certificates Target Early 2027

Cloudflare is targeting the first quarter of 2027 for production issuance of Merkle Tree Certificates, or MTCs. That date applies to the new format, rather than a confirmed launch date for every part of the certificate authority.

Google’s Chrome roadmap explains the technical rationale. Post-quantum signatures can increase the amount of data exchanged when a secure connection starts. MTCs use compact proofs that a certificate belongs to a signed tree, instead of sending a conventional chain of large signatures.

Google began testing the approach with Cloudflare while retaining traditional certificates as a fallback. Its plan places initial public MTC participation in the first quarter of 2027, followed by broader onboarding requirements for a dedicated quantum-resistant root program.

That staged deployment means adoption will depend on browser support and operational testing. Introducing the format does not make every existing device or connection quantum-resistant immediately.

Another Layer of Cloudflare’s Infrastructure Strategy

The proposal sits alongside Cloudflare’s work on services such as its Monetization Gateway, which is intended to help businesses charge for access to online resources. The certificate initiative addresses a different prerequisite for digital commerce: trusted connections.

For customers, the next milestones are concrete: completion of the GlobalSign transaction, acceptance by root programs and reliable production issuance. Those steps will determine when the announced option becomes a service that businesses can deploy.

Big Tech & Innovation, Business, News