Insights / Technical notes
Cloudflare Universal SSL vs ACM: When You Need Paid Certificates
Cloudflare’s former paid option "Dedicated SSL Certificates" was renamed and expanded in 2021 as "Advanced Certificate Manager (ACM)." This article explains the differences from free Universal SSL and when ACM is needed.

Table of contents
Start comparing Universal SSL and ACM by matching required hostnames to the certificate actually served before purchasing. Check the limitations in Cloudflare: Advanced Certificates; for Pages or R2 custom domains, evaluate the certificate route provided by that product.
Cloudflare upgraded the former Dedicated SSL Certificates offering to Advanced Certificate Manager (ACM) in 2021. Choose a certificate after checking the hostnames and DNS setup involved.
Where Universal SSL is enough
On a full DNS setup, free Universal SSL normally covers the apex and first-level subdomains. *.example.com covers www.example.com, but not api.staging.example.com. On a CNAME (partial) setup, Cloudflare provisions a Universal certificate for each proxied hostname regardless of depth. A deep subdomain therefore does not always require ACM.
Cloudflare now describes Universal certificates as free and unshared. The old claim that they are shared across unrelated sites is outdated.
- Full DNS setup Typically covers the apex and one subdomain level; deeper names fall outside that wildcard.
- CNAME / partial setup Issued per proxied hostname, regardless of subdomain depth.
When to consider ACM
ACM is a paid add-on. It lets you select the CA, validation method, validity period, and covered hostnames. One advanced certificate can contain up to 50 hostnames, including the zone apex. Available validity periods depend on the CA and plan; one year is limited to Enterprise customers using SSL.com. Not every plan can freely choose any period from 14 to 365 days.
For automatic coverage of deeper proxied hostnames on a full DNS setup, consider Total TLS. For selected hostnames, an advanced or custom certificate may suffice. Total TLS requires a full DNS setup and excludes hostnames used with some other Cloudflare products, including Tunnel.
Advanced certificates do not apply to Cloudflare Pages or R2 custom domains. Those products use a different certificate path. Buying ACM for a Pages website will not apply its advanced certificate to the Pages hostname.
Check before purchasing
- List the hostnames and identify whether the zone uses full DNS or CNAME setup.
- Check actual Universal SSL coverage.
- Confirm the CA, validity, and Total TLS conditions you need.
- Check current pricing and purchase terms in the Cloudflare dashboard for your plan.
Do not buy solely for how the certificate common name appears; verify that the required hostnames are covered by its SAN entries.