Cloudflare says it intends to become a public certificate authority. The company announced the plan on September 29, the opening of its Birthday Week, and the milestones are concrete: applications filed with the Chrome, Apple, Microsoft, and Mozilla root programs, a definitive agreement to acquire an established root from GlobalSign, and a target of issuing production Merkle Tree Certificates in the first quarter of 2027. Cloudflare has spent more than a decade as one of the largest consumers of publicly trusted certificates on the Internet and, by its own admission, has never issued a single one. That changes now, or at least starts to.
The framing in the post is about redundancy for the encrypted web. Let’s Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025. Cloudflare calls that “one of the best things to happen to the Internet in twenty years” and then names the systemic risk: if the dominant free CA had a bad week, there is no comparable free, automated alternative ready to take the load. A public CA, in Cloudflare’s phrasing, is the same idea as its Universal SSL backup certificates, but at the scale of the whole Internet.
That is the stated reason. The more interesting one is buried two sections down, in a single clause: “as certificate maximum validity period decreases over the next few years, agentic activity increases, and PQ certs go mainstream, we expect the raw number of certificates we rely on annually to continue to grow, quickly.”
Read that again. Agentic activity. This is a certificate authority announcement that is, in part, an AI infrastructure announcement.
Why agentic traffic changes the certificate math
Certificate maximum validity periods are shrinking. The CA/Browser Forum has been ratcheting them down for years, and the trajectory is toward shorter and shorter lifetimes. When certificates last 90 days, you renew four times a year. When they last 47 days, you renew roughly eight times. The certificate count scales inversely with validity period, and it scales linearly with the number of distinct endpoints that need their own certificate.
Now add agents. An agent that spins up ephemeral services, calls tools across organizational boundaries, or terminates TLS on short-lived compute needs certificates at a cadence that human-operated sites never did. Cloudflare does not put a number on this. It does not need to. The direction is obvious, and Cloudflare is positioning to be the issuer for it.
The ACME-first commitment matters here. Cloudflare says automated issuance and renewal through ACME will be the only way to get a certificate from it, which means anyone already pointed at an existing free CA can migrate by changing a directory URL. More aggressive: Cloudflare will make renewal automation a condition of issuance, and will only issue to clients that support ACME Renewal Information, standardized as RFC 9773. Subscribers must poll the renewal endpoint, act on published renewal windows, and identify the certificate being replaced.
That is a hard requirement, and it is the right one. The failure mode Cloudflare is designing against is the one that has burned the WebPKI ecosystem repeatedly: a CA needs to revoke certificates, and too many subscribers cannot replace them fast enough, so the choice becomes timely revocation or keeping sites online. Cloudflare says it will bring forward renewal windows for affected certificates, spread replacements across the available time, and track replacement issuance. It calls this “fail small.” The phrase is doing real work.
Merkle Tree Certificates and the post-quantum problem
The Q1 2027 target for production Merkle Tree Certificates is the most technically specific claim in the post, and the one AI infrastructure teams should track. MTCs are a more compact way to deliver publicly trusted certificates, designed for a post-quantum world where traditional certificate chains grow large enough to strain TLS handshakes. Cloudflare has been championing the standards-based proposal at the IETF, and earlier this year Chrome named MTCs the preferred path for post-quantum authentication. Cloudflare says it plans to be one of the first CAs to issue them in production.
The handshake strain is not hypothetical. Post-quantum signature schemes produce larger keys and signatures than their classical counterparts. In a traditional certificate chain, that bloat compounds across every certificate in the path. For a browser loading a page, it is a latency tax. For an agent making thousands of TLS connections per minute, it is a throughput problem. MTCs are an attempt to keep the chain compact enough that the transition does not degrade performance.
Cloudflare’s plan is to carry both classic certificates and MTCs under one CA, with one lifecycle and one set of guarantees. The stated goal is that customers do not have to pick a side of a multi-decade migration or run two systems. That is the correct product decision and also a bet that MTC adoption will be gradual enough that a dual-stack CA is economically viable for years.
The certificate supply chain is AI infrastructure, whether or not the AI labs think of it that way.
The transparency commitments are the interesting part
Cloudflare says it will publish reproducible builds of the software that signs certificates, attest the hardware security modules that hold its keys, and run a public dashboard for issuance health and incidents. The line that lands: “Audits are point-in-time and tell you a CA passed, not how it runs on an ordinary Tuesday.”
That is a real critique of the WebPKI audit regime, and it applies with equal force to how the AI industry evaluates safety. Model cards are point-in-time. Evaluation reports are point-in-time. Neither tells you how a system behaves on an ordinary Tuesday under production load. Cloudflare is proposing continuous operational transparency as a substitute for periodic attestation, and the AI labs would be wise to steal the idea. A public dashboard for a certificate authority is not the same as a public dashboard for a model deployment, but the underlying argument is identical: the interesting information is in the between-audits behavior.
What to watch
Cloudflare is not issuing certificates yet, and it says it will be “a little while” before it does. The root program applications are open processes, and the GlobalSign acquisition needs to close. The first Merkle Tree Certificates are targeted for early 2027.
Three things to track. First, whether the root program applications clear without conditions that constrain the dual-root strategy. Second, whether the MTC timeline holds, because Q1 2027 is aggressive for a certificate format that is still being standardized at the IETF. Third, whether the ACME Renewal Information requirement becomes a de facto standard that other CAs adopt, because if it does, the certificate renewal problem for agentic workloads gets materially easier regardless of who issues the certificates.
Cloudflare will be Customer Zero for the new CA, exercising the infrastructure at its own scale before offering it broadly. That is the right sequencing, and it is also the tell: the company is building this because it needs it. The rest of the Internet, agentic or not, gets to ride along.