This page tracks Certificate Authority issuance market share using the most rigorous, most frequently updated public dataset available: Certificate Transparency log analysis. It is intended to be revisited and updated each quarter as new data becomes available, rather than read once as a static snapshot. The methodology section below explains why different sources publish very different CA market share numbers for the same period, which is essential context before citing any single figure from this space.
Q1 2026 Snapshot: Certificate Issuance by CA (Certificate Transparency Log Data)
The most current and methodologically transparent dataset comes from TechnologyChecker.io’s analysis of Certificate Transparency log data sourced from Cloudflare Radar, covering Q1 2026 (January 1 through March 31, 2026). This measures actual new certificate issuance events recorded in CT logs, which have been mandatory for all publicly trusted certificates in Chrome since April 2018, making this one of the most complete and auditable data sources available for this question.
| Certificate Authority | Q1 2026 issuance share | Change from Q4 2025 |
| ISRG (Let’s Encrypt) | 54.4% | Down from 63.0%, an 8.6 percentage point drop, the sharpest single-quarter change on record in this dataset |
| Google Trust Services | 16.7% | Not specified in available data |
| Sectigo (ZeroSSL) | 11.7% | Up sharply, +41.2% quarter-over-quarter |
| DigiCert | 6.6% | Not specified in available data |
| GoDaddy | 5.9% | Not specified in available data |
| Amazon Trust Services | 3.8% | Not specified in available data |
| IdenTrust, SSL.com, Microsoft Corporation, GlobalSign (combined) | 0.9% | Not specified in available data |
The top three CAs in this dataset (ISRG/Let’s Encrypt, Google Trust Services, and Sectigo/ZeroSSL) together account for 82.8% of all global SSL/TLS certificate issuance in Q1 2026.
An Important Update: The Source Itself Revised Its Own Framing
TechnologyChecker.io published a follow-up note after its initial Q1 2026 report, explicitly softening its own original framing. The Q1 report’s headline framing suggested Let’s Encrypt was losing significant market share given the 8.6-point single-quarter drop. The April 2026 follow-up states this framing should be softened: ISRG (Let’s Encrypt) is plateauing in the high-50s percentage range, not collapsing. This kind of self-correction from the original data source is worth treating as more reliable than the initial headline framing, and is included here specifically because it demonstrates good practice: a primary research source revisiting and correcting its own prior interpretation as more data accumulated.
The same April 2026 follow-up reported on a related metric worth tracking alongside CA market share: the ECDSA versus RSA cryptographic algorithm crossover. As of the April data point, RSA stood at 51.0% and ECDSA at 49.0% of all certificates, a 2-percentage-point gap that was closing faster than the Q1 report had projected. The source’s own language describes this as a crossover that could occur within Q2 2026 if the pace observed in April continued, framed explicitly as a projection rather than a confirmed event.
Why Different Sources Report Wildly Different CA Market Share Numbers
Anyone researching this topic will quickly encounter contradictory figures. GoDaddy is reported at 5.9% in the Cloudflare Radar CT log dataset above, but other widely cited sources report GoDaddy at over 34%. Both figures can be accurate simultaneously, because they measure fundamentally different things. Understanding this distinction is the single most useful piece of context for interpreting any CA market share claim in this space.
Method 1: Certificate Transparency log issuance share (Cloudflare Radar, used above)
Counts new certificate issuance events recorded in CT logs during a specific time window. This measures issuance activity, meaning how many new certificates a CA issued during the period, which is heavily weighted toward CAs with short-lived, frequently-renewed certificates (Let’s Encrypt’s 90-day certificates generate far more issuance events per covered domain per year than a 1-year commercial certificate would).
Method 2: Crawled, detected-certificate counts (BuiltWith-style data, cited elsewhere as SSL Dragon’s January 2026 report showing Let’s Encrypt 54.73%, GoDaddy 34.62%, Sectigo 3.69%)
Counts certificates currently detected on websites that a web crawler actually visited and inspected, at a point in time, regardless of when that certificate was issued or how often it gets renewed. GoDaddy’s unusually high share under this method, compared to its low share in CT log issuance data, most plausibly reflects GoDaddy’s enormous base of registered, parked, and largely inactive domains that carry GoDaddy’s default certificate, which a web crawler counts as a detected certificate even though those domains generate comparatively few new issuance events relative to their total count, since parked domains are not actively renewing or reissuing certificates at the same pace as live, actively managed sites.
Method 3: Top-sites web crawl share (W3Techs-style data, historical comparison)
A related but distinct crawling methodology, typically reporting two separate numbers: share among ‘all sites’ surveyed and share among ‘top sites’ (the most-visited, highest-traffic domains specifically). A September 2024 snapshot using this method showed GlobalSign at 15.2% (all sites) and 16.3% (top sites), Sectigo at 6.3% and 6.7%, IdenTrust at 4.6% and 4.9%, DigiCert at 4.6% and 4.9%, and GoDaddy at 4.1% and 4.4%. The ‘all sites versus top sites’ split exists because certificate authority preference can differ meaningfully between the long tail of low-traffic websites and the small number of highest-traffic destinations, which tend to skew toward more established commercial CAs with enterprise support relationships.
None of these three methods is wrong. They are answering different questions. ‘Which CA issues the most certificates per quarter’ (CT log issuance share) is a different question from ‘which CA’s certificates are currently installed on the most websites a crawler can find’ (BuiltWith-style detection) which is again different from ‘which CA dominates among the most-visited sites specifically’ (W3Techs-style top-sites data). When citing any CA market share figure, specifying which of these three questions it answers is necessary for the number to be meaningfully interpreted, and most casual citations of this data fail to make that distinction, which is exactly how the same time period produces GoDaddy figures ranging from under 6% to over 34% depending on source.
Update Cadence for This Tracker
This page is intended to be revisited and updated each time a new quarterly Certificate Transparency log analysis becomes available from Cloudflare Radar or an equivalent primary source. Q2 2026 covers April 1 through June 30, 2026; data and analysis covering that period is expected to become available in the weeks following quarter close, consistent with the publication pattern observed for the Q1 2026 report (published early May 2026, roughly one month after quarter end) and its April follow-up correction.
- Q1 2026 (Jan-Mar): covered in this update, published by source early May 2026
- Q2 2026 (Apr-Jun): expected source publication in July-August 2026
- Q3 2026 (Jul-Sep): expected source publication in October-November 2026
This tracker will be updated with each new quarterly data release as it becomes available, with prior-quarter figures retained for trend comparison.
Frequently Asked Questions
Which single number should I cite if I need one CA market share figure?
Specify the methodology alongside the number. ‘Let’s Encrypt issued 54.4% of new SSL/TLS certificates in Q1 2026, per Cloudflare Radar Certificate Transparency data’ is a precise, citable, defensible claim. ‘Let’s Encrypt has 54% of the SSL market’ without specifying issuance share versus detected-certificate share versus top-sites share is the kind of unqualified claim that leads to exactly the GoDaddy 6%-versus-34% contradiction described in the methodology section above.
Why did Let’s Encrypt’s issuance share drop 8.6 percentage points in one quarter? Is Let’s Encrypt failing?
No evidence in the available data supports a failure narrative. The most plausible explanation, consistent with the same dataset’s finding that Sectigo/ZeroSSL grew 41.2% quarter-over-quarter in the same period, is competitive share shift toward alternative free and low-cost ACME-compatible providers, not a decline in absolute Let’s Encrypt issuance volume or service quality. The source’s own April follow-up explicitly cautions against the ‘losing market share’ framing, describing the pattern as plateauing rather than declining, which is the more accurate characterization based on the same underlying data viewed with one additional month of perspective.
Does this CA issuance market share have anything to do with which CA’s certificates are ‘better’ or more trustworthy?
No. Issuance volume measures market share and adoption patterns, not certificate quality, security, or trustworthiness. All publicly trusted CAs covered in this tracker are required to meet identical CA/B Forum Baseline Requirements for issuance, validation, and certificate technical standards. A certificate from a CA with 0.9% issuance share provides identical cryptographic security and browser trust to a certificate from a CA with 50% issuance share, provided both are properly issued under current Baseline Requirements.
