Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare plans to become a public certificate authority (CA), but its new service has not launched: the company said on September 29, 2026, that it was not yet issuing certificates. Its proposal could add another free issuer alongside Let’s Encrypt, with a longer-term plan to support post-quantum Merkle Tree Certificates. For now, website owners should distinguish that future public CA from Cloudflare’s existing managed Universal SSL service.

What Cloudflare announced

On September 29, 2026, Cloudflare announced that it intends to operate a public CA—an organization that issues certificates browsers and other clients can use to establish encrypted connections to websites. Cloudflare said it had applied to the root programs operated by Chrome, Apple, Microsoft, and Mozilla, and had signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign. These are steps toward wider trust, not confirmation that the applications have been accepted or that the acquisition is complete. Cloudflare’s announcement said: “We are not issuing certificates yet, and it will be a little while before we do.”

Cloudflare’s stated rationale is to add an independent, high-scale issuer to a market where, in the company’s view, much automated free issuance depends on a relatively small number of providers. That is Cloudflare’s characterization of the market, not an independently established measurement. The practical point for site owners is that a new issuer could eventually offer another route to obtain trusted certificates; it does not change which CA issues a certificate today.

How this differs from Cloudflare Universal SSL

Cloudflare already offers free managed certificates through Universal SSL, but that product is not the announced public CA. Universal SSL issues and renews publicly trusted, unshared, domain-validated certificates for domains added to and activated on Cloudflare. Coverage depends on how the domain is connected: a full setup covers the root domain and first-level subdomains, while a partial CNAME setup issues a certificate for each proxied subdomain. See Cloudflare’s Universal SSL documentation for the product’s current setup details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Cloudflare’s current certificate products can use multiple certificate authorities, depending on product and certificate type. Its documentation names Let’s Encrypt, Google Trust Services, SSL.com, and Sectigo as partners. That means the announcement does not establish that Cloudflare will replace Let’s Encrypt. Let’s Encrypt remains among the providers Cloudflare identifies for current certificate products, while the new CA is a separate effort that has not started issuing.

How Cloudflare plans to establish trust

A public CA must issue certificates that client software trusts. Cloudflare’s stated approach combines two routes: seek inclusion in four major root programs and acquire already trusted root material through its agreement with GlobalSign. Root-program applications are reviews, not automatic approvals; signing an acquisition agreement is not the same as completing the transaction. Cloudflare says the acquired root is intended to help certificates work on older phones, operating systems, and other devices that no longer receive updates. The eventual reach will depend on completed milestones and the trust stores present on clients.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Compatibility can vary by client and certificate chain. Cloudflare’s documentation notes that some older Android and Java clients may not trust the applicable Let’s Encrypt ISRG Root X1 chain. It also says Google Trust Services cross-signs with a GlobalSign root installed on client devices for more than 20 years. These are Cloudflare’s descriptions, not a guarantee for every device or configuration; consult current vendor compatibility guidance before choosing an issuer for a legacy environment. Cloudflare’s CA reference describes its current partners and caveats.

What Merkle Tree Certificates are—and why they matter

Cloudflare’s technical plan includes conventional certificates and Merkle Tree Certificates (MTCs). MTCs are intended as a post-quantum approach: rather than transmitting large post-quantum signatures with every connection, a certificate can use lightweight proofs tied to a trusted registry. This is a design direction described by Cloudflare, not a capability currently available from its new CA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Cloudflare says it is targeting production MTC issuance in early 2027, with the goal of inclusion in Chrome’s quantum-resistant root store. Early 2027 is a target, not a guaranteed release date or confirmation of Chrome acceptance. The company says standard MTC issuance will have no charge. Cloudflare’s MTC engineering article explains the proposed approach.

Certificate Transparency (CT) logs publicly record issued certificates so issuance can be audited. Cloudflare’s engineering article says each certificate must be submitted to at least two public CT logs, and describes its Nimbus log family and planned Raio static log family. It estimates that post-quantum signatures could make CT logs store 40 times as much data. That 40x figure is Cloudflare’s projection, not an independently confirmed measurement. The log plans and capacity estimate are part of the proposed system, not operating results from the new CA.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Planned automation and operational visibility

Cloudflare says it wants the CA to provide detailed operational and technical visibility, reproducible code builds, and a public health dashboard. It also points to automated renewal signaling under RFC 9773, intended to prompt background certificate replacement during routine updates or incidents. These features could help make certificate operations more observable and responsive, but they remain planned capabilities until the service is operating and their implementation can be evaluated.

What site owners should do now

  • If you already use Cloudflare Universal SSL: treat it as the current managed certificate service; the announcement does not require a configuration change.
  • If you use Let’s Encrypt directly: there is no announced replacement requirement. Continue using your existing issuance and renewal process unless your compatibility or operational needs call for a change.
  • If you support older clients: check the actual trust chain and client versions in your environment. General statements about root-store reach are not a substitute for testing your supported devices.
  • If you are evaluating post-quantum readiness: regard MTCs as a future option under development, not a certificate you can deploy from this CA today.

The meaningful milestones to watch are completion of the GlobalSign transaction, decisions by the four root programs, start of classical certificate issuance, and whether MTC issuance meets its stated early-2027 target. Until then, comparisons with Let’s Encrypt are about intended design and trust strategy, not demonstrated performance or reach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.