Daily certificates issued by Let's Encrypt, as Cloudflare describes it: ~10 million (Source: Cloudflare blog (September 29, 2026))
Certificate safety depends on how fast you can swap one
Few executives think about the certificates that keep their websites encrypted. Sometimes one has to be retired. Cloudflare names two causes: a compliance issue or a security incident. Then the question is how fast every holder can replace it.
Cloudflare says it intends to become a public certificate authority (CA). A CA is a company that browsers trust to vouch for a website's identity. The new issuer is the headline. The more useful part is a condition. No automated renewal, no certificate.
What Cloudflare announced
Cloudflare has applied to four trust programs run by Chrome, Apple, Microsoft and Mozilla. These programs decide which CAs devices will trust. It has also signed a definitive agreement to acquire a trusted root from GlobalSign. A root is the anchor certificate that others trace back to.
Cloudflare is not issuing certificates yet. It targets the first quarter of 2027 for its first Merkle Tree Certificates. Everything here is an application, an agreement or a plan. None of it is approved.
How it works: why buy a root
Devices ship with a built-in list of trusted roots. A certificate works only if it traces back to one of them. A brand-new root takes years to spread. Devices that no longer get updates never receive it.
Cloudflare says much of the world's traffic comes from such older devices. The GlobalSign root has had broad trust since 2012, including on those devices. Buying it is meant to give Cloudflare reach from the first day it issues.
Cloudflare also plans new roots. Some trust programs are starting to limit how old a root may be. The new roots are meant to fit those rules.
The rule that matters: renewal on demand
Cloudflare says it will be "ACME-first". ACME is an open standard that lets software request and renew certificates without a person. A site using another free CA could switch by changing one directory URL, Cloudflare says.
The firmer rule involves ACME Renewal Information (ARI), defined in RFC 9773. Cloudflare will issue only to clients that support it.
Here is how it works. The CA publishes a suggested renewal window for each certificate. The customer's software checks Cloudflare's renewal endpoint on a schedule and reads that window. When it renews, it names the certificate it is replacing.
That loop gives the CA control. Because clients keep checking, it can pull a window forward for affected certificates. It can spread replacements across the time available. And it can track which certificates have been replaced.
Cloudflare gives its reason. It says it has watched CAs face a hard choice: revoke a faulty certificate on time, or keep customer sites online. In its telling, the bind arose when customers were too slow to swap in new certificates.
This is our interpretation. When a certificate must be retired, the limit is how fast customers can replace it. Cloudflare gives no figures on how often this has happened.
A second issuer, and a new question
By Cloudflare's count, Let's Encrypt serves more than 500 million sites. Its active certificates passed four billion in 2025. Cloudflare praises it. It also argues that if this dominant free CA had a bad week, no comparable free, automated option could take the load.
Cloudflare already ships each Universal SSL certificate with a backup from a different authority. It relies on 16 partner CAs today. A CA of its own would add one more issuer.
A fair question follows. Cloudflare sits in front of over a fifth of global request traffic. A CA of its own could put more of the trust chain in one company's hands. The post does not discuss that.
It does promise outsiders a view inside. Anyone should be able to rebuild the signing software and check the result. The hardware that stores its keys will come with attestation. A public page will show how issuance is running and when things go wrong. These are promises. Cloudflare says it is still working through the approval processes.
Post-quantum certificates, in brief
Post-quantum cryptography is designed to resist future quantum computers. Cloudflare says classic certificate chains grow large enough to strain the TLS handshake, the opening exchange of a secure connection. Merkle Tree Certificates are a far more compact design.
Cloudflare says Chrome named them the preferred path for post-quantum authentication earlier this year. It also expects much of the Internet to stay on classic certificates for many more years.
What leaders should ask their teams
First: how many certificates do we hold, and who renews each one? Cloudflare expects maximum validity periods to fall over the next few years. Each manual renewal would then come around more often.
Second: how quickly could we replace every certificate if an issuer had to retire them? Cloudflare gives no benchmark. Our suggestion is to set your own target and test it.
Third: do we have a second issuer ready, as Cloudflare does for its own customers? Fourth: do our older devices and partner systems trust the roots we depend on?
When a certificate must be retired, the limit is how fast customers can replace it. Build the automation before the day you need it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.





