How can my organization become a Root CA?

I suspect you will find that it is too expensive to do so in terms of auditing requirements. Also, there is no single definition of what it means to be trusted. Each application is free to define their own trust, and to use their own root certificates. Practically speaking, you may only care about getting your CA certificate in the Windows root certificate program, in the Mozilla program, in the Java cacerts file, Opera, and maybe a few smaller ones. I think Chrome uses either Windows root certs or the Mozilla root certs.

Mozilla just issued a new policy for CAs.

Here a few link to articles about Microsoft's program:
Microsoft Root Certificate Program
Windows root certificate program members
Microsoft Root Certificate Program Members

Here is an article on getting into Opera's root certificates.


According to http://www.mozilla.org/projects/security/certs/policy/InclusionPolicy.html (access date: June 2013) it is possible for anyone to become a CA FOR FREE.

Once You get Your certificate bundled with the browser, You are technically as trusted as it gets, in the same league with VeriSign and major banks.

The hard part is, probably, fulfilling all the requirements.