Reference guide · cloudflare · Published 2026-08-16 · 3 min read

Cloudflare Universal SSL versus a custom certificate

Cloudflare Universal SSL versus custom certificate: who issues each, coverage limits, and when to switch for your origin and brand.

Flat editorial illustration showing a planetary shield with concentric orbit rings, one radial segment glowing as a small request dot climbs.
Illustration: this article at a glance.

Universal SSL is the automatic path

Every Cloudflare zone gets a free, automatically-issued SSL certificate covering the site between the visitor and the Cloudflare edge. It is issued for the domain during onboarding, kept renewed, and requires no action from you. That certificate is what powers the "padlock" for most sites on the platform.

The SSL modes article covers how that edge certificate interacts with your origin, and the edge-side certificate itself is the subject here. Universal SSL typically covers the apex and immediate names, sometimes via a shared certificate that broadens to certain delegated names, and its coverage rules are the main reason to consider a custom certificate.

When a custom certificate earns its keep

A custom certificate is one you supply, either a certificate you purchased that you upload, or a certificate generated for your brand through a broader-cover flow such as Advanced Certificate Manager or the SSL for SaaS add-on. You would reach for it when Universal SSL's automatic coverage is not enough:

NeedUniversal SSLCustom certificate
CostFree, automaticUploaded or paid, requires setup
CoverageCommon apex and delegated namesYou control exactly which names are covered
Brand / BYO certNoUse your own issued certificate
Non-standard namesMay not cover every hostAdd exactly the names you need

Real sites most often move to a custom certificate because a subdomain, a regional host, or a wildcard-style set of names is either not covered by Universal SSL's automatic set or needs to match a certificate their own security policy issued. Importing your own cert also lets you keep a single, trusted identity across everything you serve.

The origin side still matters

Whichever edge certificate you choose, the connection from Cloudflare back to your origin is governed by the SSL mode setting, such as Full (strict). A strong edge certificate does not secure a clear-text origin link, so the edge certificate and the origin connection are two separate decisions:

An edge certificate on its own does not make the site-wide SSL story complete, and the certificate types context explains the difference between edge and origin trust.

The practical decision

Start with Universal SSL; for the overwhelming majority of zones it covers the site and it is maintained for you. Move to a custom certificate only when you need explicit coverage of names the automatic certificate does not carry, when your security team already issues certificates you should reuse, or when you are serving a set of hosts that must all appear under one trusted identity. Keep the origin validated with Full (strict) in either case, so the edge certificate you chose actually secures the whole connection rather than just the first hop.

Need a website built, fixed, optimised, migrated or replaced?

This technical resource is written by CSMBAC, a small design and development studio. If you would rather hand the problem to a professional, the website service page explains how we build enquiry-ready websites.

Explore website services