The CA/Browser Forum, formed in 2005, brought together certificate authorities and browser vendors to jointly develop industry-wide standards for certificate issuance and management — before its formation, issuance practices varied considerably across different CAs with no unified baseline.
What it actually established
Its Baseline Requirements document defines the minimum standards a CA must follow to issue publicly trusted certificates — covering domain validation methods, certificate content requirements, security practices, and audit obligations — and is the foundation browser vendors reference when deciding whether to include or remove a CA's root from their trust store.
Its ongoing role
Nearly every major policy shift in certificate practices over the past two decades — shortened validity periods, mandatory Certificate Transparency logging, specific validation method restrictions — has moved through CA/Browser Forum discussion and ballot processes before becoming industry-wide practice, making it the primary governance body shaping how certificate issuance actually works today.
How CA/Browser Forum decisions actually get made
The Forum operates through a ballot process where member organizations, CAs and browser vendors, each with voting rights, propose and vote on changes to the baseline requirements — reaching the required supermajority for a proposal to pass has, at various points in the Forum's history, proven difficult on genuinely contentious issues, as illustrated by the 2020 certificate validity dispute where a shortening proposal failed to pass through the normal ballot process entirely.
Why browser vendors ultimately hold more practical power than the voting structure suggests
Even when a CA/Browser Forum ballot doesn't pass, individual browser vendors retain the unilateral ability to simply refuse to trust certificates that don't meet their own preferred standards, regardless of the Forum's formal vote outcome — meaning the Forum functions more as a coordination and consensus-building mechanism than a body with binding enforcement authority independent of browser vendors' own trust-store decisions.
How the Forum's membership and structure has evolved since 2005
The Forum's membership has grown considerably since its 2005 founding, now including a broad range of CAs of varying sizes alongside every major browser vendor, and has added formal working groups focused on specific certificate categories (like the separate baseline requirements developed specifically for code signing certificates) beyond its original website-certificate-focused scope.
Notable instances where Forum consensus process visibly struggled
Beyond the 2020 certificate validity dispute, the Forum's ballot process has seen other periods of visible friction between CA members (who bear the operational cost of compliance changes) and browser vendor members (who generally push for stricter security requirements), illustrating the structurally different incentives these two categories of member bring to Forum governance.
How to find and read the Forum's current baseline requirements yourself
The CA/Browser Forum publishes its baseline requirements and ballot history publicly on its own website, offering genuinely primary-source insight into exactly how and why current certificate issuance rules came to be, for anyone wanting to go beyond secondary summaries like this one.
Its underappreciated role as a forum for competitors to cooperate
The CA/Browser Forum represents an unusual governance structure worth appreciating on its own terms: it requires commercially competing certificate authorities to sit in the same room, alongside the browser vendors whose trust decisions directly determine those CAs' viability, and reach working consensus on shared rules — a genuinely unusual degree of structured cooperation among market competitors, motivated by the shared recognition that the entire certificate ecosystem's credibility depends on baseline standards nobody can unilaterally lower.
Why understanding this governance body matters even for non-technical readers
Even readers with no direct technical involvement in certificate management benefit from understanding that the CA/Browser Forum exists, since virtually every rule governing how the padlock in their own browser actually gets earned traces back to a decision made within this comparatively obscure, industry-run governance body most internet users have never heard of.
Few governance bodies ask direct commercial competitors to cooperate as closely as the CA/Browser Forum does, and few succeed at it as consistently.