Historically, Chrome relied on the underlying operating system's trust store on most platforms rather than maintaining its own independent list of trusted root certificates. The Chrome Root Program, rolled out starting around 2022-2023, shifted this — giving Chrome its own trust store and certificate policy requirements, independent of the OS.
Why this shift mattered
It gave Google direct control over CA trust decisions in the world's most widely used browser, rather than depending on Microsoft, Apple, or a Linux distribution's own trust store policies — meaning a CA's inclusion in Chrome no longer automatically followed from being trusted by the underlying OS, and vice versa.
Part of a broader trend
This mirrors a longer-running pattern of major browsers (Firefox has long maintained its own independent trust store) taking direct ownership of trust decisions rather than delegating to the OS — reflecting the reality that browser vendors, not operating system vendors, are often the ones setting the pace on certificate policy today.
What specifically differs in Chrome's own trust requirements versus relying on the OS
The Chrome Root Program introduced its own specific technical and operational requirements for CA inclusion, in some respects more stringent than what some operating systems' own trust stores required, including requirements around Certificate Transparency logging, specific audit standards, and incident response expectations tailored to Chrome's own risk tolerance.
Why this move increases the practical influence of browser vendors specifically
By each maintaining independent trust stores with their own specific requirements, major browsers, Chrome and Firefox both notably, now exercise more direct, granular control over CA trust decisions than they would by simply deferring to operating system vendors, reinforcing the broader pattern of browser vendors functioning as the primary practical enforcers of certificate ecosystem security standards.
How Mozilla's independent trust store compares to Chrome's newer one
Firefox's independent trust store predates the Chrome Root Program by many years and has long operated with its own specific policy requirements separate from any operating system — Chrome's move essentially brought it into closer alignment with Firefox's longer-standing independent approach, rather than being an entirely novel concept within the browser industry.
What this means for CAs seeking broad browser trust going forward
A CA today generally needs to separately satisfy Chrome's, Firefox's, Apple's (for Safari), and Microsoft's (for Edge) individual trust-store requirements rather than assuming inclusion in one automatically grants inclusion in the others — increasing the overall compliance burden for new or smaller CAs seeking to achieve the broad browser compatibility a major commercial CA needs.
What this means practically for a typical site owner
For most site owners, this shift is invisible in practice, since certificates from any well-established CA already meet both Chrome's and other browsers' trust requirements — it mainly matters if you're evaluating a newer or smaller CA, where confirming broad multi-browser trust-store inclusion specifically is worth checking before committing to it for anything business-critical.
How this fits the broader theme of browser vendors as de facto internet governance bodies
The Chrome Root Program is one more concrete example of a theme running through much of this history section: major browser vendors, through their practical control over what gets trusted, function as genuine, consequential governance bodies for large parts of internet security infrastructure, exercising real regulatory-style authority despite operating as private companies without any formal governmental mandate to do so.
A brief closing thought on where CA trust governance seems to be heading
The direction suggested by the Chrome Root Program, individual browser vendors taking more direct, granular ownership of trust decisions rather than deferring broadly to shared industry or OS-level defaults, appears likely to continue, meaning CAs increasingly need to satisfy several distinct, independently governed trust requirements rather than one unified standard.
Individual browser vendors increasingly function as de facto governance bodies for internet trust infrastructure, whether or not that role was ever formally assigned to them.