dns.pizza research

Certificate Authority Market Share 2026: three CAs sign 71.5% of the web's top domains

We read the TLS certificate presented by 57,732 domains of the Tranco top 100,000. Two issuers account for 60.5% of them, 62.4% of the web already runs on 90-day certificates — and the biggest sites are the ones still paying for the long-lived kind.

Published August 15, 2026 · data collected June 2026August 2026 · download the data

31.8%

Google Trust Services — the largest issuer

28.8%

Let's Encrypt — the largest free issuer

71.5%

of certificates come from three CAs (Google Trust Services, Let's Encrypt, Amazon)

62.4%

are short-lived certificates (≤ 100 days)

Key findings

  1. Two issuers sign six in ten certificates. Google Trust Services (31.8%) and Let's Encrypt (28.8%) together issue 60.5% of the certificates the top 100,000 domains present. Add Amazon (11%) and three CAs hold 71.5%; add DigiCert (9.9%) and four hold 81.5%. Google Trust Services sells almost nothing to site owners directly — its lead is the CDN edge, where Cloudflare's default certificate provider is Google Trust Services.
  2. The web has already moved to 90-day certificates. 62.4% of certificates are valid for 100 days or less 100% of Google Trust Services' and 100% of Let's Encrypt's certificates are short-lived. Only 20.7% still carry a lifetime over 200 days. Since March 15, 2026 the CA/Browser Forum baseline forbids issuing anything longer than 200 days, so that fifth of the web is a shrinking stock that expires out by spring 2027; the cap drops to 100 days in March 2027 and 47 days in March 2029. Not one trusted certificate in the corpus exceeds 400 days.
  3. The biggest sites are the ones still paying. In the top 1,000, DigiCert holds 20.6% — within a point of Google Trust Services' 22% — and Let's Encrypt only 15.2%. In the 10,001 – 100,000 tail DigiCert falls to 9.5% and Let's Encrypt rises to 29.6%. Short-lived certificates follow the same gradient: 42.4% of the top 1,000 versus 63.6% of the tail. Scale, compliance regimes and organisation-validated certificates keep the largest sites on paid, longer-lived certificates.
  4. The commercial CAs are caught mid-transition. Amazon's certificates split 50.6% at 101 – 200 days against 49.4% at the old 13-month lifetime; DigiCert 47.6% against 50.7%. Sectigo still has 62.1% of its certificates on lifetimes over 200 days. Those are the CAs whose customers renew by hand once a year — and the ones with the most automation left to build before the 100-day cap.
  5. The market looks different where US CAs are hard to buy from. In .ru, Let's Encrypt (51.7%) and GlobalSign (39.9%) account for nine in ten certificates, and Google Trust Services — the global leader — is at 5.2%. In .ir it is Let's Encrypt (60.3%) and Certum (36.6%). Japan and China are the paid, long-lived holdouts: only 21.8% of .jp and 12.9% of .cn certificates are short-lived, with Amazon (32.4%) leading .jp and DigiCert (40.8%) leading .cn. .gov is DigiCert territory (38.2%), and in .edu — the one TLD where this happens — "everyone else" out-counts every named CA (32.7%): the InCommon programme's white-label intermediates, counted here under their own name.
  6. The leaderboard is the same almost everywhere else. Google Trust Services leads 16 of the 35 TLDs with enough data for a row and Let's Encrypt 12; DigiCert leads 6 (.au, .ca, .gov, .cn, .id, .tr). .com — 27,567 certificates, the bulk of the corpus — has Google Trust Services at 34.5% and Let's Encrypt at 27%.

Certificate authority market share by popularity tier

Share of trusted certificates in each Tranco rank tier. The 3 largest CAs are named; the full breakdown of 11 named CAs is in the tables below.

Source: dns.pizza TLS handshakes · snapshot August 15, 2026

Certificate lifetime by issuing CA

Validity period (notAfter − notBefore) of the certificate each domain presented. Since March 15, 2026 no publicly trusted CA may issue longer than 200 days.

Source: dns.pizza TLS handshakes · snapshot August 15, 2026

Market share and lifetime by CA

Every CA family with at least 200 trusted certificates in the corpus. The remaining 98 issuer names are folded into "everyone else".

IssuerCertificatesShare≤ 100 d101 – 200 d201 – 400 d
Google Trust Services18,33031.8%100%0%0%
Let's Encrypt16,62128.8%100%0%0%
Amazon6,35611%0%50.6%49.4%
DigiCert5,7449.9%1.7%47.6%50.7%
Sectigo3,1445.4%0.6%37.3%62.1%
GlobalSign3,0335.3%8.8%33.2%58%
GoDaddy1,2792.2%7.7%42.1%50.2%
HARICA4680.8%0%41.7%58.3%
ZeroSSL3440.6%93.3%1.7%4.9%
Certum (Asseco)3220.6%0%40.1%59.9%
Entrust2540.4%1.2%39.8%59.1%
Everyone else1,8373.2%15.7%35.4%48.8%

By popularity tier and TLD

Share of each segment's trusted certificates. The four largest CAs are named and the largest of the four in each row is bold; "rest" is every other issuer combined, so it can exceed the bold cell. All 35 TLDs with at least 200 certificates are listed, largest sample first.

SegmentCertsGoogle TSLet's EncryptAmazonDigiCertRest≤ 100 d
All domains57,73231.8%28.8%11%9.9%18.5%62.4%
Top 1,00051922%15.2%16.6%20.6%25.6%42.4%
1,001 – 10,0005,58729.2%22.5%13.4%12.8%22.2%53.8%
10,001 – 100,00051,62632.1%29.6%10.7%9.5%18%63.6%
.com27,56734.5%27%13.3%10.2%15%63.6%
.org2,73439.3%33.8%7.5%5.8%13.6%75.5%
.net2,56637.9%33.4%7.2%7.1%14.5%72.9%
.ru2,1515.2%51.7%0%0%43.1%57.3%
.de1,22514.4%38.4%9%13.2%25%54.2%
.io99945%28%16%2.2%8.7%74.1%
.uk84223.8%24.8%16.4%15.1%20%50.6%
.br84225.3%27.2%12.2%11.6%23.6%53.6%
.jp7907%13.2%32.4%13.7%33.8%21.8%
.in67625.4%30.5%11.2%11.1%21.7%58.6%
.fr63516.5%27.7%10.2%11.5%34%46.9%
.it57618.8%32.5%15.5%11.5%21.9%52.8%
.edu57110.3%25.4%8.6%9.3%46.4%38%
.pl54426.3%19.7%3.5%18%32.5%48%
.co49640.5%27.4%15.9%4.6%11.5%69.6%
.nl43619.7%33.3%7.8%14.9%24.3%53%
.au36215.5%27.9%17.4%29.3%9.9%45%
.es33118.4%17.2%13.6%14.8%36%40.8%
.tv32842.7%29.9%9.8%4%13.7%73.8%
.ca31119.9%17.4%13.2%24.4%25.1%39.5%
.gov29611.1%19.3%6.1%38.2%25.3%33.1%
.me28644.1%27.3%12.6%7.7%8.4%74.5%
.ai27950.2%24.4%14%4.3%7.2%75.3%
.cn2723.3%6.6%2.2%40.8%47.1%12.9%
.cz26420.1%44.3%3%14.4%18.2%65.9%
.ua25847.7%27.1%2.7%5%17.4%77.1%
.id24427.9%17.2%2.9%28.3%23.8%47.1%
.tr22520%12.9%2.7%26.7%37.8%33.3%
.app22553.8%28.9%11.6%1.3%4.4%84%
.ir2240.9%60.3%0%0%38.8%62.1%
.info22150.7%30.8%3.2%2.7%12.7%83.7%
.se21629.6%25%9.3%13.9%22.2%56.5%
.gr21343.2%25.8%2.3%7.5%21.1%70.4%
.eu20323.6%33.5%11.8%12.3%18.7%59.6%
.ro20235.1%32.2%4%9.4%19.3%67.8%
Download the full dataset (CSV)

Methodology

dns.pizza performs a live TLS handshake (port 443, SNI set to the domain, from a single vantage point) while generating domain intelligence reports across the Tranco top 100,000, and records the leaf certificate the server presented: issuer, validity window, subject names, negotiated protocol and cipher. This report aggregates the latest handshake per domain that returned a certificate — 60,293 domains measured between June 11, 2026 and August 15, 2026.

Market share is computed over the 57,732 certificates that chain to a root in the Mozilla-derived trust store bundled with Node.js. The other 2,561 (4.2%) — expired, name-mismatched, chains served without their intermediate, and 252 self-signed certificates — are counted here and excluded from every denominator; a self-signed "localhost" certificate is not a certificate authority. Because the check does not fetch missing intermediates the way browsers do, a server that omits its chain shows as untrusted even if browsers repair it.

The CA is the organization named on the issuing intermediate certificate (issuer O, falling back to CN). Spelling and legal-entity variants of one company are folded together — DigiCert Inc / DigiCert, Inc. / DigiCert Ireland; GoDaddy and its Starfield subsidiary; Comodo under its Sectigo name — but white-label intermediates keep their own name, so an InCommon, GoGetSSL or TrustAsia certificate counts for that brand rather than the root operator behind it. This understates the root operators, Sectigo most of all. A CA gets its own row with at least 200 trusted certificates; 98 smaller issuer names are folded into "everyone else".

A domain whose handshakes never returned a certificate is simply absent: unknown is not "no certificate". Most such failures in our data are our own resolver refusing under bulk load rather than anything about the domain, which is why this report makes no claim about HTTPS adoption — only about which CA signs the certificate where one was presented. Per-TLD rows require at least 200 trusted certificates, which yields 35 TLD rows; the gate excludes 9,122 certificates across 549 smaller TLDs (15.8% of the corpus) from the per-TLD table. They remain in the overall, per-tier and per-CA numbers.

Limitations: the corpus is the top-ranked slice of the web (Tranco aggregates several popularity signals; it is not a literal visit count), and the certificate we see is the one served on the registrable domain itself, not on www or other subdomains — for CDN-fronted sites that is the CDN's certificate, which is precisely why Google Trust Services leads. Certificate lifetimes are the validity window as issued, not the time remaining. The top-1,000 tier holds 519 certificates and its shares carry a wider margin than the tail's. Per-country TLD figures reflect the domains popular enough to rank, not every registration in that registry.

The data is free to cite and reuse (CC BY 4.0, credit "dns.pizza"). For questions or the raw per-domain data, get in touch.

Who signed your certificate — and for how long?

Run a live handshake: issuer, expiry countdown, chain and protocol. If it is still a one-year certificate, the 200-day cap already applies to its renewal.

Check your certificate