Cloudflare, the US company that sits between millions of websites and their visitors to speed them up and protect them, plans to start issuing the digital certificates that keep web browsing secure.
The move puts Cloudflare into a small club of organisations, known as certificate authorities, that the entire web relies on to confirm websites are who they say they are.
It is also designed to prepare the internet for quantum computers, which Cloudflare says could break today's encryption within years.
What a certificate does
Every time a browser shows a padlock next to a web address, a certificate is working in the background.
The certificate does two jobs: it scrambles the data passing between the visitor and the site, and it proves the site is genuine rather than an impostor.
Certificates are only trusted if they come from an authority that browsers and devices already recognise.
Cloudflare says that trust is currently concentrated in a small number of dominant issuers, which creates a risk for the whole web if one of them fails or is compromised.
Buying its way in
Winning recognition from scratch can take years.
To speed things up, Cloudflare has agreed to buy existing trusted "root" key material from GlobalSign, an established certificate authority.
A root is the master credential that tells browsers and devices whether to trust an issuer, so owning one means Cloudflare's certificates should work straight away, including on older phones and computers that no longer receive updates.
The deal is expected to close within two months, subject to the usual conditions.
Cloudflare has also applied to join the approved lists run by Google's Chrome, Apple, Microsoft and Mozilla, the maker of Firefox.
It will start issuing standard certificates once those applications are accepted.
The quantum problem
Quantum computers work in a fundamentally different way from ordinary machines and, once powerful enough, are expected to crack the maths that protects most online traffic.
Encryption designed to resist them already exists, but its digital signatures are much bulkier, which could slow down every connection.
Cloudflare's answer is a new format called Merkle Tree Certificates, which it helped draft through the Internet Engineering Task Force, the body that sets internet standards.
Instead of sending heavy signatures each time, these certificates use small proofs showing they are recorded in a trusted public register.
Cloudflare plans to begin issuing them in the first quarter of 2027, after a trial with Chrome.
Website owners will be able to manage old and new certificates in one place, so they do not have to switch overnight.
A familiar playbook
Cloudflare has done something similar before.
In 2014 it began giving free encryption certificates to millions of websites, which it says doubled the amount of encrypted traffic on the web overnight.
Matthew Prince, its chief executive, described upgrading the web before quantum computers can break it as one of the biggest coordination challenges in the internet's history.
The company has also promised a live public dashboard showing how the service is running, and a system that can replace certificates across millions of sites automatically if a security problem forces a mass swap.