If a Cloud API phone number shows "waiting" and asks for a certificate association, ignore the certificate. That prompt comes from the legacy on-premises API, which is sunsetting; its docs are not relevant to Cloud API numbers. For Cloud API, associating no certificate at all is correct. Just register the number: POST https://graph.facebook.com/v20.0/{phone-number-id}/register with your bearer token. The registration reference is at developers.facebook.com/docs/whatsapp/cloud-api/reference/registration. The number moves to connected once registration succeeds.

Context: Stack Overflow #79136951 (accepted answer, 6 votes): a verified company number shows "waiting" in WhatsApp Manager asking for a certificate to be associated, but the linked docs point at the on-premises API docs. The accepted answer says Meta's docs are stale here: certificates are on-prem legacy, the Cloud API only needs the register endpoint.