Market Insights

Cloudflare wants a public CA. GlobalSign root key material is the shortcut — price Undisclosed.

Cloudflare (NYSE: NET) Sep 29: intent to become a public CA; definitive deal for GlobalSign Root CA key material (price Undisclosed; close ~2 months). Applied Chrome/Apple/Microsoft/Mozilla. Classical after acceptance; MTCs targeted Q1 2027. Not issuing yet.

Sep 30, 2026 · 5 min read

Twelve years after Universal SSL, Cloudflare is no longer content to be the Internet’s largest free-certificate consumer. On September 29, 2026, Cloudflare, Inc. (NYSE: NET) announced its intent to become a public Certificate Authority — and a definitive agreement to acquire established, publicly trusted Root CA key material from GlobalSign. Deal price: Undisclosed. Close targeted in the next two months, subject to customary conditions. Primary: Cloudflare press release + engineering blog (Birthday Week), both Sep 29. Not issuing yet.

What “public CA” means here — and what it does not. Cloudflare has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. That is application status, not trust-store acceptance. Classical certificate issuance begins only after those processes complete. Production Merkle Tree Certificates (MTCs) — Cloudflare’s preferred post-quantum path, co-authored as an IETF draft and named by Chrome as a preferred PQ authentication approach (company blog) — are targeted for Q1 2027. Until acceptance and go-live: no Cloudflare-issued public certs.

Why buy an old root. A brand-new root can take years to propagate and never reaches devices that stopped receiving updates. Cloudflare’s blog states the GlobalSign root has been trusted across browsers, OSes, and devices since 2012 and covers that long tail. A parallel new root is for root-program policies that may cap how old a trusted root can be. Dual path: reach on day one + standing under future rules. Important framing: this is acquisition of root key material, not a full GlobalSign company takeout. GlobalSign enterprise value: Undisclosed.

Concentration argument, in Cloudflare’s own numbers. The press release argues WebPKI trust is concentrated in a small number of dominant issuers, creating systemic risk. The blog is more specific on the free/automated stack: Let’s Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025 — figures Cloudflare attributes in its CA blog. Cloudflare’s own position: it sits in front of more than 20 percent of global Internet request traffic and terminates TLS for millions of domains (Cloudflare blog claim, not a CyberMerge traffic census). Universal SSL in 2014 “nearly doubled” encrypted sites overnight (company). Those are primary-source claims about why NET wants a third high-scale free issuer, not CyberMerge market-share figures.

Operating design — company-stated. ACME-first issuance (change a directory URL). Renewal automation as a condition of issuance via ACME Renewal Information (RFC 9773). Glass-box transparency: reproducible builds, HSM attestation, public issuance-health dashboard. Classical TLS and MTCs under one CA lifecycle so customers do not run two systems through a multi-year PQ migration. Cloudflare says it will be Customer Zero for the new CA.

POV — does NET owning a public CA change trust economics? DigiCert-class commercial CAs sell assurance and liability. Let’s Encrypt-class free CAs sell ubiquity and automation. Cloudflare entering as an ACME-first public CA with GlobalSign reach plus an MTC PQ roadmap is a bet that the free/automated layer needs a second scaled issuer — and that connectivity-cloud distribution is the distribution advantage. Boards and root-program watchers should ask: Does Cloudflare’s dual role as TLS terminator for a large traffic share and as issuer create new concentration — or reduce it by diversifying free issuance? Underwrite the definitive GlobalSign key-material agreement and two-month close window as stated. Deal dollars: Undisclosed. Root-program applications are an open process. Watch: close, first classical issuance after acceptance, and whether Q1 2027 MTC production holds. No traffic percentage beyond Cloudflare’s primary blog claim.

Underwrite sheet — sourced only: Cloudflare press Sep 29, 2026 — intent to become public CA; acquire GlobalSign Root CA key material; classical + MTC; applied Chrome/Apple/Microsoft/Mozilla; classical after acceptance; MTC production Q1 2027; GlobalSign close next two months / customary conditions; Prince quote on free/automatic encryption → open CA. Cloudflare Blog Sep 29 (Steve Goldsmith) — definitive agreement for GlobalSign root trusted since 2012; not issuing yet; Let’s Encrypt ~10M certs/day, >500M sites, 4B active certs in 2025 (CF blog attribution); CF >20% global request traffic claim; ACME-first; ARI/RFC 9773; glass-box ops; Customer Zero. Price of key material Undisclosed.

Sources