Sectigo and its ZeroSSL brand combined surged 41.2% in certificate issuance between Q4 2025 and Q1 2026, the largest single-quarter gain of any commercial CA in the Certificate Transparency data. Sectigo now holds 11.7% of new certificate issuance globally. For a buyer deciding whether to trust a $4.99-per-year Sectigo certificate from an authorized reseller, understanding why this happened matters more than the headline number.
The growth is not evidence that Sectigo suddenly became a better CA. It is evidence that a competitor became a worse one. And the safety argument for buying Sectigo is not the growth figure. It is the 15-year compliance record, the root store standing, and the reseller price structure that gives buyers the same certificate for $4.99 that Sectigo charges $110 for directly.
Why Sectigo Surged 41%: The Three Actual Causes
Cause 1: The Entrust Distrust Migration
The dominant cause of Sectigo’s Q1 2026 surge is the Entrust distrust. Google announced on June 27, 2024 that Chrome would stop trusting Entrust certificates with SCTs from November 11, 2024. Apple followed with a November 15, 2024 cutoff. Mozilla followed with November 30, 2024. Entrust had held approximately 3.5% of global certificate issuance.
Sectigo announced on January 7, 2025 that it had acquired Entrust’s public certificate business. Former Entrust customers needed to migrate their certificates to a new CA before their current certificates expired. Sectigo was the natural first choice: it acquired Entrust’s customer relationships, support infrastructure, and business, positioning it as the migration destination. The Q1 2026 surge in Sectigo issuance is a direct measurement of Entrust migration completions flowing through Q4 2024 and Q1 2025.
The key distinction: Sectigo’s growth is explained by an Entrust failure, not a Sectigo breakthrough. This does not make Sectigo a worse choice. It makes Entrust a worse choice. But a buyer should understand the reason for the growth rather than inferring that Sectigo’s quality improved.
Cause 2: ZeroSSL and Cloudflare Integration
Sectigo’s Q1 2026 CT data includes ZeroSSL certificates, which Sectigo owns as a brand. ZeroSSL’s ECDSA issuer surged 51.1% in Q1 2026, the fastest growth of any major issuing CA. This growth is primarily attributable to Cloudflare integration: ZeroSSL ECC certificates are the default for Cloudflare-integrated hosting environments. When a hosting provider adds Cloudflare integration or an operator enables Cloudflare proxy, ZeroSSL ECDSA certificates appear at scale automatically.
The Cloudflare-ZeroSSL integration explains the ECDSA-specific nature of the surge. Cloudflare uses ECDSA certificates by default through its infrastructure. ZeroSSL’s ECDSA issuer is the back-end for Cloudflare’s certificate provisioning. This is infrastructure adoption, not individual buyer decisions , but it confirms that Sectigo’s (ZeroSSL’s) ECDSA infrastructure is trusted at Cloudflare’s scale.
Cause 3: Q4 2025 Calendar Distortion
TechnologyChecker.io’s updated analysis noted that Q4 2025’s unusually large total certificate count (11.94 billion certificates) partially reflected year-end provisioning bulk and the long tail of pre-policy 200-plus-day certificates being issued before the March 2026 CA/B Forum deadline. This means Q4 2025 was abnormally large, making the percentage change from Q4 2025 to Q1 2026 appear more dramatic than a trend comparison would show. The Sectigo/ZeroSSL surge is real and continues, but the magnitude should be understood in this context.
The Real Safety Argument for Sectigo Certificates
The correct argument for buying a Sectigo certificate is not the Q1 2026 growth figure. It is the CA’s compliance record, root store standing, and the price structure at authorized resellers. These are the dimensions that actually determine whether a certificate is safe to trust.
Root store standing: all four programs, continuously
Sectigo (formerly Comodo CA) has been included in all four major browser root store programs without interruption: Chrome Root Store, Apple Root Certificate Program, Mozilla CA Certificate Program, and Microsoft Trusted Root Certificate Program. Continuous root store inclusion over 15-plus years without a distrust event is the primary indicator of CA compliance reliability. Compare this to the CA distrust history: DigiNotar (bankrupt), CNNIC (distrusted), WoSign/StartCom (distrusted and ceased operations), Entrust (distrusted). Sectigo is not on this list.
Compliance history: one incident in 15 years
Sectigo’s compliance history under its Comodo CA name includes one documented significant incident: the March 2011 reseller account compromise where fraudulent certificates were issued for google.com, yahoo.com, live.com, skype.com, and others. Nine fraudulent certificates were issued. They were identified and revoked the same day. Comodo retained trust store standing. No browser distrust occurred.
In the 15 years since, Sectigo has not experienced a browser distrust event, a significant mis-issuance incident, or a compliance failure that produced formal browser program action. This track record compares favorably to most commercial CAs of similar scale.
Scale: world’s largest commercial CA by volume
Sectigo is the world’s largest commercial CA by active certificate count, issuing across DV, OV, EV, and code signing categories. Scale creates both risk (a large CA failure has wider impact) and safety (a large CA has more invested in maintaining compliance, more resources for audit response, and more organizational capacity to maintain the infrastructure that browser programs review). Sectigo has the operational scale to maintain WebTrust audits, CT log compliance, and CA/B Forum participation at the level browser programs expect.
The Price Structure: Why $4.99 at a Reseller Is the Same as $110 Direct
Sectigo’s retail price for a single-domain PositiveSSL DV certificate through sectigo.com is approximately $110 per year. Authorized resellers offer the same certificate for $4.99 to $9 per year. This is not a discount on a different product. It is the authorized reseller channel that Sectigo itself operates for volume distribution.
What is identical between the $4.99 reseller certificate and the $110 direct certificate:
- The issuing CA: Sectigo. The Issuer field in the certificate details shows Sectigo regardless of which reseller processed the order.
- The root certificate: Sectigo’s root certificates are in all four major browser trust stores. The reseller does not add or change the root.
- The browser trust: Chrome, Firefox, Safari, Edge, and all major browsers trust Sectigo root certificates identically regardless of purchase channel.
- The encryption: SHA-256, TLS 1.3 compatible, AES-256 session encryption. Algorithm quality does not vary by purchase channel.
- The warranty: Sectigo PositiveSSL DV includes a $50,000 warranty from Sectigo at the certificate level.
- The CT log entries: the certificate appears in Sectigo’s CT logs with Sectigo as Issuer, visible on crt.sh.
What differs between the $4.99 and $110 purchase:
- The reseller’s portal UX and customer service quality
- The reseller’s documentation and knowledge base
- Multi-year subscription discounting (resellers offer up to 30% off on 3-year plans)
- The reseller margin: the reseller keeps the markup between their wholesale cost and the sale price
The authorized reseller channel exists because Sectigo’s retail pricing is designed for enterprise and direct procurement relationships. Small businesses and individual developers are not the intended audience for the direct purchase path. The $4.99 reseller price is the correct market-clearing price for DV certificates in the volume reseller channel. Paying $110 direct buys nothing additional in certificate quality, trust, or security.
What ‘Comodo SSL’ and ‘Sectigo SSL’ Mean for Buyers Who Remember Both Names
Sectigo was formerly named Comodo CA. In 2018, Comodo’s Certificate Authority business was acquired by Francisco Partners private equity and rebranded as Sectigo. The entity that issues Sectigo certificates is the same entity that issued Comodo certificates under the old name. The root certificates are the same. The browser trust is continuous.
Resellers may still list products as ‘Comodo PositiveSSL’ or ‘Sectigo PositiveSSL.’ They are the same product. A ‘Comodo SSL’ certificate issued in 2018 and a ‘Sectigo SSL’ certificate issued in 2026 are both issued by the same CA infrastructure, trusted by the same root certificates, and listed under the same CA/B Forum membership. A buyer who searches for ‘Comodo SSL’ is searching for what is now sold as ‘Sectigo SSL.’
Sectigo Certificate Products and Verified Reseller Pricing
| Certificate type | What it validates | Best for | Reseller price (annual) | Sectigo direct price |
| Sectigo PositiveSSL DV | Domain control only | Personal sites, blogs, developer projects, internal tools | $4.99/yr (Certera, SSLs.com) to $7.66/yr (SSL Dragon) | ~$110/yr |
| Sectigo PositiveSSL Wildcard DV | Domain + all subdomains | Sites with multiple subdomains on same domain | $34.99/yr (Certera) to $49.99/yr (Namecheap) | ~$299/yr |
| Sectigo OV SSL | Domain + verified organization | Business sites collecting customer data, professional service firms | $49/yr (Certera) to $65/yr (SSL Dragon) | ~$170/yr |
| Sectigo OV Wildcard | Organization + all subdomains | Multi-subdomain business sites | $120-200/yr (Certera/Namecheap) | ~$380/yr |
| Sectigo EV SSL | Domain + extended organization + legal verification | Regulated sectors, enterprise, specific compliance frameworks | $61.60/yr (SSL2BUY) | ~$270/yr |
All prices verified June 2026. Reseller prices shown for 1-year term; multi-year subscriptions reduce per-year cost further. All products are issued by Sectigo regardless of reseller. The Issuer field in the certificate will show Sectigo.
What Sectigo’s 41% Growth Means for the 47-Day Validity Future
Sectigo’s growth coincides with two market transitions that will affect all Sectigo certificate buyers: the Entrust migration and the CA/B Forum Ballot SC-081v3 validity reduction schedule. Both matter for buyers choosing certificate strategy in 2026.
At current 199-day maximum validity (Sectigo implemented the DigiCert 199-day standard in March 2026), a Sectigo certificate from a reseller is valid for approximately 6.6 months. A 3-year subscription from an authorized reseller produces approximately 5-6 issuances (the initial certificate plus renewals) over the subscription term, all included in the subscription price.
As validity reduces to 100 days (approximately March 2027) and then 47 days (March 2029), the same 3-year subscription will produce more certificates at shorter intervals. The subscription price remains the same. The operational implication is increased renewal frequency that favors ACME automation. Sectigo supports ACME via its commercial API for paid certificates. Buyers who configure ACME automation now are prepared for the 47-day trajectory.
The combination that provides the most value from Sectigo’s current position: a 3-year Sectigo OV subscription from Certera at approximately $37/year effective annual rate on a 3-year plan, with ACME automation configured for renewals. The OV certificate provides CA-verified business identity. The 3-year subscription locks in the current price through the validity reduction schedule. ACME automation handles the increased renewal frequency as validity shortens. This configuration is operationally ready for 2029 without requiring a strategy change.
Frequently Asked Questions
Is a Sectigo certificate from Certera or SSLs.com really the same as buying from Sectigo directly?
Yes. Certera, SSLs.com, Namecheap, SSL Dragon, and the other authorized Sectigo resellers listed in this article purchase certificates from Sectigo’s wholesale API and sell them to end customers. The certificate that arrives is issued by Sectigo’s CA infrastructure. The Issuer field shows Sectigo. The root certificate is Sectigo’s. After installation, you can verify this independently by checking the certificate details in your browser or querying crt.sh with your domain , the issuing CA will be Sectigo regardless of which reseller you used.
Sectigo acquired Entrust’s certificate business. Does that mean Entrust certificates are now trusted again?
No. Entrust certificates with SCTs (Signed Certificate Timestamps) from before Chrome’s November 11, 2024 cutoff remain trusted until their natural expiry. New certificates issued under Entrust’s roots after that cutoff are not trusted by Chrome, Apple, or Mozilla. Sectigo’s acquisition of Entrust’s business means Sectigo now issues replacement certificates for former Entrust customers, using Sectigo’s own roots, which are fully trusted. A certificate issued by Sectigo after the acquisition is a Sectigo certificate trusted by all browsers , not an Entrust certificate.
What happened to the Comodo brand resellers I used to buy from?
Resellers that previously sold ‘Comodo SSL’ now sell ‘Sectigo SSL.’ The product is the same certificate from the same CA, renamed following the 2018 rebranding. Some resellers still list the product as ‘Comodo PositiveSSL’ in their catalog even in 2026, because the underlying certificate issuer identifier persists and some customers search for the old name. Whether the product page says Comodo or Sectigo, the issued certificate will show Sectigo as the Issuer in current certificate details.
