Cloudflare moves to issue web certificates.
Cloudflare has applied to become a public certificate authority, the body that vouches a website is genuine, and has agreed to buy a trusted root from GlobalSign. It promises a second large free issuer, though not yet.
Cloudflare moves to issue web certificates
Cloudflare has announced that it intends to become a public certificate authority, issuing the certificates that tell a browser it has reached the genuine website.1 It has applied for inclusion in the root programmes run by Chrome, Apple, Microsoft and Mozilla.1 It has also signed a definitive agreement to acquire an established root from GlobalSign, which has been trusted across browsers, operating systems and devices since 2012.1 Tech Monitor reports that the GlobalSign deal is expected to close within two months, subject to customary closing conditions.3
Cloudflare is not issuing certificates yet, and says it will be a little while before it does.1 Ordinary certificates are planned once the browser root programmes have accepted its application.3 The reason for buying an old root is reach.1 Cloudflare says a brand new root takes years to spread and never reaches the devices that have stopped receiving updates, whereas the GlobalSign root already does.1
The company's case is that too much of the web depends on one issuer.1 It says Let's Encrypt issues around ten million certificates a day, serves more than 500 million sites and passed four billion active certificates in 2025.1 If the dominant free certificate authority had a bad week, Cloudflare argues, much of the web would have no comparable free, automated alternative ready to take the load.1 Cloudflare says it sits in front of more than 20 percent of global internet request traffic and already relies on millions of certificates a year from several authorities.1
Getting a certificate from it will work through ACME, the open standard that free certificate tools already use, so a site can move by changing one directory address.1 It will only issue to clients that support automated renewal signals under RFC 9773, so that certificates can be replaced quickly if they ever have to be withdrawn.1 Cloudflare also promises reproducible builds of its signing software and a public dashboard of issuance health and incidents.1
The second half of the plan is about quantum computing.2 Cloudflare plans to issue Merkle Tree Certificates, a compact format designed for a world where post-quantum certificate chains grow large enough to strain every secure connection, from the first quarter of 2027.1 It says standard Merkle Tree Certificates will be free, and it is aiming for inclusion in Chrome's new Quantum-resistant Root Store.2 Website owners will manage ordinary certificates and the new ones in one system, with no hard cutover.3 Matthew Prince, Cloudflare's chief executive, called upgrading the web's security before quantum computers can break it one of the biggest coordination challenges in the history of the internet.3
Nothing to do yet, but check renewals
For most of you this changes nothing this quarter. The padlock on your website comes from whoever your host or web agency uses, and Cloudflare will not issue a single certificate until the browser makers accept it. The announcement has no British angle: no UK regulator is named and no price in pounds is given. The useful part is the argument underneath it. A great deal of the web leans on one free issuer, and certificates are being renewed more often and more automatically every year.
So the sensible question for whoever runs your website is a dull one. Are your certificates renewed automatically, and would anyone notice if a renewal failed? An expired certificate puts a warning in front of every visitor. If the answer is a shrug, that is worth fixing well before 2027, whichever authority you end up using.
Also today
-
OpenAI blames Moonshot for an attempt to copy its models
OpenAI says it disrupted a campaign by more than 15,000 users to distil the model behind ChatGPT, and blames China's Moonshot AI for at least part of it.4
-
Dutch spies warn that connected cars can be used to snoop
The Dutch intelligence service AIVD warned that microphones, cameras and GPS in modern cars could let hostile states spy on drivers, as Chinese brands reach 15% of new UK registrations.5
-
Google counts 10,740 vulnerability disclosures in August alone
Google's threat researchers say monthly vulnerability disclosures have more than doubled this year to 10,740 in August, with exploited flaws up from 10.5 a month to 18.6
-
Fewer schools in England report a cyber incident
Ofqual found that 27% of schools and colleges in England had a cyber incident in 2025 to 2026, down from 29%, and that 66% could recover immediately.7
-
Inntelo AI puts its agents to work for a hospitality body
Inntelo AI will run agents across HFTP's websites, publications and events, answering members and exhibitors in more than 50 languages and passing harder queries to staff.8
Share this briefing
The week on one sheet, every Friday.
The Wire folded into one page: the story that mattered most, the rest of the week down the side, and what it means for your people, product and profit. Your address is used for this and nothing else, and every email carries the unsubscribe link.
We confirm the address by email first. How we handle it.
Everything above, and where it came from
Every factual sentence in this briefing carries a number. These are the numbers. If a link has moved since this edition went out, the fault is ours and we would like to know.
-
Building a post-quantum certificate authority with Merkle Tree Certificates
-
Cloudflare plans public CA for standard and post-quantum certificates
-
OpenAI reveals huge ‘co-ordinated campaign’ to attack ChatGPT
-
Tech in cars can be used to snoop on you, Dutch spy chiefs warn
-
Vulnerability disclosures are rocketing, but AI is changing the types of flaw being discovered
-
Inntelo AI signs deal to deploy AI agents across global hospitality association
How this page was made
This briefing was compiled and written at 14:00 UK time, the afternoon edition by one of our own agents, from the public feeds listed above. No person read it before it published. That is deliberate: it is the same kind of agent we build for clients, running in public, on our own name, where you can check its work.
What the agent is allowed to do is fenced. It may read public news feeds, write this page, and publish it. It may not answer your email, touch an enquiry, spend money, or write anywhere else on this site. Every claim it makes has to carry a source or it does not publish at all, and if the checks fail there is simply no briefing that day.
Our longer pieces, the ones listed as essays, are written by people. Those are marked as such and always will be. If anything here is wrong, tell us and we will change it and say that we did.
Tell us about those tasks that never land on time.
You do not need to know what an agent is, how it works, or which one you need. Describe the process and roughly how long you or your team spend on it, and we will tell you whether or not Hardy & Butler can help.