The announcement matters, but it does not make today's TLS certificates obsolete. The more interesting shift is operational: Cloudflare wants to build a certificate authority designed around automation, continuous transparency and the transition to post-quantum authentication.
What Cloudflare actually announced
On September 29, 2026, Cloudflare announced its intent to become a public certificate authority and said it had applied to the Chrome, Apple, Microsoft and Mozilla root programs.
It also signed an agreement to acquire an established, broadly trusted root from GlobalSign, with the goal of providing wide device compatibility when public issuance starts.
Key point
Cloudflare is not yet a new generally available public CA. The announcement describes an application process, an architecture and a rollout plan.
Automation becomes a requirement, not an option
One of the most practical parts of the announcement is certificate renewal. Cloudflare says it intends to issue only to clients that support ACME Renewal Information (ARI), standardized as RFC 9773.
ARI lets a CA publish recommended renewal windows. During a revocation event or compliance issue, automated clients can be instructed to replace certificates earlier instead of waiting for normal expiry.
The operational lesson is straightforward: infrastructure that still relies on manual certificate renewal becomes increasingly fragile as certificate lifetimes shorten and emergency replacements need to happen quickly.
A CA that can be observed between audits
Cloudflare also says it plans reproducible builds for signing software, attestations for the hardware security modules that protect keys, and a public dashboard covering issuance health and incidents.
That matters because compliance audits are snapshots. For critical infrastructure such as a certificate authority, day-to-day visibility into changes and incidents can become an additional trust signal.
Merkle Tree Certificates move toward production
Cloudflare plans to issue its first production Merkle Tree Certificates (MTCs) in the first quarter of 2027 and targets compatibility with Chrome's new quantum-resistant root store.
MTCs address a practical problem with post-quantum authentication: post-quantum signatures can be much larger than classical signatures. A direct migration could therefore add bandwidth and latency overhead, especially to short-lived connections.
It is important to separate post-quantum key exchange, which protects session confidentiality, from post-quantum certificates and signatures, which authenticate the server. The former is already much more widely deployed than the latter.
Should you change TLS configuration today?
Not because of this announcement alone. MTCs are not yet generally available, and Cloudflare targets initial production issuance for 2027.
The useful actions today remain conventional:
- automate certificate issuance and renewal with ACME;
- monitor expiry and certificate-chain errors;
- avoid obsolete TLS protocols and algorithms;
- keep servers and TLS libraries up to date;
- identify applications and appliances that still depend on manual certificate workflows.
What this could mean for InfraCheck
This announcement does not justify a blocking score today. A domain should not be penalized for not using technology that is not yet broadly available.
It does, however, point toward useful future visibility:
- surface certificate and chain signature algorithms more clearly;
- make issuer and trust-chain characteristics easier to inspect;
- identify whether certificate renewal is automated;
- prepare an informational post-quantum compatibility signal when browser and CA support becomes mature enough.
The sensible path is visibility first, recommendations second, and scoring only when the ecosystem is sufficiently established.
Post-quantum migration is becoming an operations topic
This is no longer only a research discussion. After hybrid key exchange in TLS and SSH, the certificate trust chain is starting to evolve as well.
For web and infrastructure teams, the immediate priority is not to replace every PKI. It is to remove manual dependencies and make cryptographic posture observable, so that new mechanisms can be adopted without urgency when browsers, CAs and servers are ready.
Sources
- Cloudflare — Building a certificate authority for the whole Internet, September 29, 2026
- Cloudflare — Building a post-quantum certificate authority with Merkle Tree Certificates, September 29, 2026
- Cloudflare — Post-quantum TLS visibility, September 29, 2026
Published September 30, 2026. Cloudflare's rollout and the MTC timeline may evolve.