What Cloudflare's certificate post has not issued
Cloudflare says it has applied to four browser root programs and agreed to acquire a GlobalSign root. The post says it is not issuing certificates yet.
The short version
No. The September 29 post says Cloudflare has applied to four root programs and agreed to acquire a GlobalSign root, and that it is not issuing certificates yet.
What happened
On September 29, 2026, Cloudflare posted that it intends to become a public certificate authority. The post says the company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and that it has signed a definitive agreement to acquire an established GlobalSign root so certificates could reach devices that already trust that root. The post also says Cloudflare is not issuing certificates yet. InfoQ's October 5 item and Dark Reading's September 29 item both report that announcement. The page filing the post, rather than a claim that issuance has started, is Futureweb.
Two roots, and no issuance yet
The post distinguishes an acquired root from a new one. It says the GlobalSign root has been trusted across browsers, operating systems, and devices since 2012, including older clients a fresh root would not reach. It says the new root, still to be submitted, is meant for root programs that are starting to cap how old a trusted root may be. Neither sentence is a certificate a site can install today. The post says the work with root programs happens in the open and that the company will share milestones as they land. A reader who needs the binding between a name and a key, once a certificate exists, is on what a TLS certificate binds.
What the post requires of a subscriber
The post says issuance will be ACME-first, so a client already pointed at another free authority could switch by changing a directory URL. It also says Cloudflare will issue only to clients that support ACME Renewal Information, standardized in RFC 9773. Subscribers, the post says, must poll a renewal endpoint, act on the renewal windows Cloudflare publishes, and identify the certificate being replaced. Those are conditions on a future issuer. They are not a certificate chain a reader can fetch from a log today. The post says Cloudflare will publish reproducible builds of the signing software, attest the hardware modules that hold the keys, and run a public dashboard for issuance health.
Why it matters on this desk
This desk files what a name in a certificate is bound to, and who is allowed to issue that binding. Cloudflare's post is an application and an acquisition agreement, plus a design for later issuance. It is not a new root already present in a browser. The post argues that free automated certificates are concentrated, and it cites Let's Encrypt as issuing on the order of ten million certificates a day, serving more than 500 million sites, and passing four billion active certificates in 2025. Those figures are Cloudflare's account of another authority. They explain why Cloudflare says it wants a second free issuer. They do not show that the second issuer is live. The desk for the trust decision is Networking.
Where the dates sit
Dark Reading reported the announcement on September 29, the day of the Cloudflare post. InfoQ's item is dated October 5 and describes the same plan: a public authority for quantum-safe certificates, not a certificate already issued. The post's own calendar for Merkle Tree Certificates is the first quarter of 2027, and it says classic certificates would continue under the same authority so a site would not have to pick one format on a single day. A headline that collapses application, acquisition, and issuance into one finished fact is ahead of the post. The security desk's account of how an advisory names a flaw is a different document, on Security.
What a reader can check
The check is the September 29 post. Does it say certificates are being issued? It says they are not. Does it name the four root programs applied to? Yes. Does it name the GlobalSign agreement? Yes. Does it name RFC 9773 as a condition of issuance? Yes. Does it give a first date for production Merkle Tree Certificates? The first quarter of 2027. A protocol note that is not this announcement stays on Open Source.
What to watch next
The page changes when a root program publishes a decision on the application, when Cloudflare names the first certificate it has actually issued, or when the GlobalSign agreement's closing is disclosed as done or withdrawn. Until then the post is a statement of intent and of two roots, one acquired on paper and one not yet submitted. The company says it will keep using the partner authorities it already relies on, and it counts those partners at sixteen. A later story that says the web has switched issuers is not this post. Let's Encrypt's later notice on how long a certificate lasts, which is not this application, is what Let's Encrypt's 64-day notice changes.
What would change the record
An inclusion notice from Chrome, Apple, Microsoft, or Mozilla would change the application sentence into a decision. A certificate transparency entry that names this authority would change the not-issuing sentence. A statement that the GlobalSign agreement did not close would change the acquired-root sentence. None of those documents is the September 29 post. InfoQ and Dark Reading do not supply them either. They report the post.
What stays a certificate story
What stays specific is the stage of the work. Cloudflare has applied, has agreed to acquire one existing root, and has described ACME issuance and a 2027 target for Merkle Tree Certificates. It says it is not issuing yet. A container host, a model weight file, and a handset app are not this announcement. The record is the post, and the outlets that restated it.
Sources
The reports this brief is filing. Futureweb did not republish them.
Questions
Is Cloudflare issuing certificates from this new authority yet?
No. The September 29 post says Cloudflare is not issuing certificates yet and that issuance is still ahead of the root-program process.
Which root programs does Cloudflare say it has applied to?
Chrome, Apple, Microsoft, and Mozilla. The post says those applications are in progress, not that inclusion has been granted.
Which existing root does Cloudflare say it agreed to acquire?
An established GlobalSign root that the post says has been trusted since 2012, under a definitive agreement, plus a new root Cloudflare says it will submit.
What issuance protocol does the Cloudflare certificate post require?
ACME, and the post says Cloudflare will issue only to clients that support ACME Renewal Information, RFC 9773.
When does Cloudflare say production Merkle Tree Certificates would start?
The post targets the first quarter of 2027 for the first production Merkle Tree Certificates, and says classic certificates continue alongside them.