Twelve years ago Cloudflare doubled the number of encrypted websites worldwide overnight; this week it announced something more fundamental — issuing digital certificates itself.
Cloudflare has signed an acquisition agreement with GlobalSign and applied to join the root certificate programs of Chrome, Apple, Microsoft, and Mozilla (the browsers and operating systems that decide which CAs to trust). This means it is shifting from "certificate consumer" to "certificate issuer."
What this is
A Certificate Authority (CA) is the entity that issues digital certificates, which prove "this website isn't a counterfeit." Cloudflare simultaneously announced plans to become one of the first providers of post-quantum certificates — next-generation encryption certificates designed to resist cracking by future quantum computers.
Acquiring GlobalSign's established trust roots is a key step. Newly created root certificates take years to be trusted by global devices and systems; GlobalSign's roots have been widely recognized since 2012, allowing Cloudflare to cover even legacy devices that no longer update, from day one.
Industry view
Supporters view this as natural evolution — Cloudflare is already one of the world's largest consumers of TLS (Transport Layer Security, the underlying standard for HTTPS encryption) certificates, and self-issuing can cut costs and speed things up. Cloudflare also promises free issuance, meaning small and medium website owners will benefit too.
We note skepticism centers on two points. First, the "trust concentration" risk: the CA industry is already dominated by a few players, and Cloudflare's entry makes infrastructure more dependent on a single company. Second, a conflict of roles — Cloudflare is both a CDN (Content Delivery Network, the intermediary that delivers website content to users) handling massive global traffic, and is now also seeking to be a CA, creating a conflict of interest. Historical cases of CA trust abuse are not isolated.
Impact on regular people
For enterprise IT: limited short-term impact, but if you use Cloudflare's full product suite, you may by default get cheaper post-quantum certificates in the future.
For individual careers: unless you work in security or compliance, you'll barely notice this. It's the foundation — when the foundation holds, the upper structure doesn't collapse.
For consumer markets: once post-quantum certificates are widespread, the "encryption strength" of going online in 5-10 years will be higher; but there's no direct impact today.