Building a certificate authority for the whole Internet
Cloudflare is transitioning to become a formal Certificate Authority (CA) to issue its own SSL/TLS certificates. The new infrastructure integrates ACME protocol automation with Merkle Tree Certificates to support post-quantum cryptographic standards.
Verified State Diff
Impact & Verification Analysis
Web developers, enterprise infrastructure teams, and organizations relying on Cloudflare for edge security and TLS termination.
This shift reduces dependency on external CAs, allows for faster certificate issuance cycles, and positions Cloudflare to lead the industry transition toward post-quantum secure web infrastructure.
Full Fact Overview
Cloudflare is moving beyond its role as a managed PKI provider to operate as a root Certificate Authority. By implementing Merkle Tree Certificates, the company aims to solve the scalability issues inherent in traditional Certificate Transparency logs. The architecture is designed to be 'ACME-first,' prioritizing automated certificate issuance and renewal, while explicitly incorporating post-quantum cryptographic primitives to future-proof web security against quantum computing threats.