SSL Certificate Statistics 2026: HTTPS Adoption, Let's Encrypt and CA Market Share
Let's Encrypt issues the certificate on 63.9% of websites whose certificate comes from a publicly trusted authority: 70,152,849 of 109,784,103. On many of the largest hosts and platforms, the host picks the authority. Squarespace, Vercel and Hostinger put Let's Encrypt, and GoDaddy's site builder puts GoDaddy's own certificate, on between 94.2% and 98.2% of their websites with a trusted certificate.
On this page 13 sections
- 94.8% of websites present a trusted certificate, and 2.8% still answer only over HTTP
- Let's Encrypt issues 63.9% of trusted certificates
- Google Trust Services is mostly Cloudflare's choice
- Your web host chooses your SSL certificate
- At least 81.8% of trusted certificates are free, and the top of the web pays
- At least 97.4% of trusted certificates only prove control of the domain
- Country extensions follow their hosts: Actalis on .it, Sectigo on .de
- 379,202 websites serve a certificate that expired before the crawl
- 2,298,420 websites present a certificate no browser accepts
- 98.9% of Let's Encrypt websites crawled since 25 August 2026 carry its Generation Y chain
- 38.4% of websites with a trusted certificate send HSTS, most because their platform does
- Frequently asked questions
- Methodology and sources
- Let's Encrypt issues the certificate on 63.9% of websites with a publicly trusted certificate, 70,152,849 of 109,784,103, and on 60.6% of all websites. With Google Trust Services on 17.7% and GoDaddy on 6.5%, the three largest authorities issue 88.2% of trusted certificates.
- 94.8% of websites present a certificate from a publicly trusted authority, 109,784,103 of 115,839,436. 2,298,420 websites, 2.0% of the web, present one no browser accepts, and 3,288,919, 2.8%, answer only over plain HTTP.
- Google Trust Services is the second largest certificate authority, issuing 17.7% of trusted certificates, 19,472,641 websites. 82.9% of those websites, 16,149,947, sit behind Cloudflare, which chooses the authority for the free certificates it issues.
- On 13 of the 30 largest hosts and platforms, one certificate authority issues 90% or more of the certificates on their websites with a trusted certificate. Those hosts hold 30,644,804 websites, 26.5% of the web.
- 81.8% of websites with a trusted certificate, 89,823,769, get it from an authority that charges nothing: Let's Encrypt, Google Trust Services, TrustAsia's LiteSSL or Fastly's Certainly.
- Busier websites pay for their certificate more often. Between Tranco ranks 1,001 and 10,000, 50.7% of the 4,919 websites with a trusted certificate use a free authority, and DigiCert issues 723 of them, 14.7%, against 1.7% of trusted certificates across the web.
- At least 97.4% of trusted certificates, 106,885,721, prove only that the owner controls the domain. An intermediate named for extended validation issued the certificate on 22,367 websites, 0.02% of those with a trusted certificate.
- 379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began, because the intermediate behind it had expired or stopped issuing months earlier. 362,151 of them are Let's Encrypt certificates.
- 38.4% of websites with a trusted certificate send an HSTS header, 42,174,070 of them. Seven website platforms send 54.5% of those headers, and on every other website with a trusted certificate the rate is 22.1%.
- Only 0.65% of the 9,469,985 websites whose HSTS header meets the preload list's rules, 61,386, are on Chrome's preload list by name.
94.8% of websites present a trusted certificate, and 2.8% still answer only over HTTP
| What the website presents | Websites | Share of all websites |
|---|---|---|
| Trusted and current | 109,404,901 | 94.4% |
| Trusted issuer, already expired | 379,202 | 0.33% |
| Rejected by browsers | 2,298,420 | 2.0% |
| Plain HTTP only | 3,288,919 | 2.8% |
| Could not be read | 467,994 | 0.40% |
Embed this figure
We record the certificate, or its absence, each time our crawl fetches a website, and this chart sorts the web by what the latest fetch showed. It adds two groups the headline figures leave out: 379,202 websites whose issuer is trusted but whose certificate had already expired, and 467,994, 0.40% of the web, whose answer the crawl could not read. Take the expired out and 94.4% of the web is left with a certificate that is trusted and, as far as the issuer can show, current.
The web, in this report, is 115,839,436 websites. The latest fetch of 183.7 million domains answered 200, 125.9 million of them with a page the crawl could read; 119.9 million of those sit at the apex of a registration, which leaves out subdomains, and 115.8 million remain once parked domains are removed. The 158.2 million domains in our robots.txt report also count parked, broken and silent domains, so a share of them would be lower.
Chrome 154, stable since 22 September 2026, asks before the first visit to any public website without HTTPS. That reaches at least the 3,288,919 websites that answer only over plain HTTP, and a website whose certificate is rejected or expired falls back to plain HTTP and meets the same warning. Google counts visits rather than websites: 95 to 99% of navigations in Chrome have used HTTPS since about 2020, and most of the rest go to private addresses on local networks.
HTTPS is the default on the web, and a website without a working certificate now meets its visitors with a warning page.
Let's Encrypt issues 63.9% of trusted certificates
| Certificate authority | Websites | Share of websites with a trusted certificate | Share of all websites |
|---|---|---|---|
| 70,152,849 | 63.9% | 60.6% | |
| 19,472,641 | 17.7% | 16.8% | |
| 7,173,334 | 6.5% | 6.2% | |
| 6,014,739 | 5.5% | 5.2% | |
| 1,890,899 | 1.7% | 1.6% | |
| 1,161,608 | 1.1% | 1.0% | |
| 787,190 | 0.72% | 0.68% | |
| 773,918 | 0.70% | 0.67% | |
| 692,839 | 0.63% | 0.60% | |
| 304,307 | 0.28% | 0.26% | |
| 163,588 | 0.15% | 0.14% | |
| 139,330 | 0.13% | 0.12% | |
| Every other trusted CA (119) | 1,056,861 | 0.96% | 0.91% |
Embed this figure
Let's Encrypt issues the certificate on 70,152,849 websites, 63.9% of those with a publicly trusted certificate and 60.6% of the whole web. Google Trust Services is second at 17.7% of trusted certificates, GoDaddy third at 6.5% and Sectigo fourth at 5.5%. The first three issue 88.2% between them, out of 131 issuing organisation names found on the web.
The chart counts each certificate under the brand printed on it. Several other brands issue from intermediates Sectigo certifies, ZeroSSL the largest: its intermediate is issued by one of Sectigo's roots. Counted by the company behind the intermediate, Sectigo closes to 6.3% of trusted certificates, against GoDaddy's 6.5%.
Published figures count differently. Let's Encrypt's own, more than 700 million websites, counts every hostname it certifies, and the HTTP Archive's Web Almanac puts it on 52.6% of the mobile pages it crawls, a share of pages from its own list. This report counts one website per registration.
One authority now holds nearly two thirds of the trusted web, and a root program change or an outage at Let's Encrypt would reach more websites than every other authority together.
Google Trust Services is mostly Cloudflare's choice
| Certificate authority | Websites on Cloudflare | Share of Cloudflare's websites with a trusted certificate |
|---|---|---|
| 13,458,671 | 78.6% | |
| 3,540,432 | 20.7% | |
| 29,665 | 0.17% | |
| 19,491 | 0.11% | |
| 17,178 | 0.10% | |
| 16,924 | 0.10% | |
| Every other CA | 40,240 | 0.24% |
Embed this figure
82.9% of the 19,472,641 websites with a Google Trust Services certificate sit behind Cloudflare, on its network or answering with its server header, and 69.1% on its network alone. Of the 17,379,961 websites on Cloudflare's network, 78.6% of those with a trusted certificate carry one from Google Trust Services and 20.7% one from Let's Encrypt.
Cloudflare gives every site on it a free certificate by default, and for those certificates it chooses the certificate authority itself, between Let's Encrypt, Google Trust Services and SSL.com. WE1, Google's largest intermediate with 15,146,023 websites, answers with a Cloudflare server header on 99.1% of them.
Away from Cloudflare, Google Trust Services is on 3,322,986 websites, and three hosts hold most of them: WordPress.com 28.9%, Wix 25.3% and Google 13.5%.
The second largest certificate authority on the web is, in practice, a setting inside Cloudflare, and its share moves whenever Cloudflare changes the mix.
Your web host chooses your SSL certificate
| Host or platform | Websites | Trusted share | With a trusted certificate | Most used CA | Second |
|---|---|---|---|---|---|
| 17,379,961 | 98.5% | 17,122,601 | |||
| 6,403,922 | 99.9% | 6,396,981 | |||
| 6,053,273 | 98.4% | 5,957,893 | |||
| 6,046,836 | 99.7% | 6,028,970 | |||
| 5,559,011 | 99.9% | 5,552,443 | |||
| 4,428,515 | 99.8% | 4,420,150 | |||
| 2,926,368 | 94.1% | 2,752,297 | |||
| 2,376,886 | 92.1% | 2,189,723 | |||
| 2,340,794 | 99.9% | 2,337,438 | |||
| 2,191,505 | 92.5% | 2,026,999 | |||
| 2,185,561 | 99.7% | 2,178,587 | |||
| 2,178,423 | 94.7% | 2,063,204 | |||
| 1,944,019 | 97.8% | 1,902,182 | |||
| 1,592,034 | 97.9% | 1,559,343 | |||
| 1,237,946 | 80.1% | 992,073 | |||
| 1,127,612 | 99.0% | 1,116,048 | |||
| 1,022,885 | 96.9% | 991,059 | |||
| 1,012,094 | 98.9% | 1,001,024 | |||
| 924,005 | 99.5% | 918,991 | CloudSecure8.7% | ||
| 906,947 | 99.3% | 900,417 | |||
| 901,842 | 99.6% | 898,404 | |||
| 821,268 | 97.7% | 802,369 | |||
| 774,905 | 98.0% | 759,355 | |||
| 750,296 | 82.4% | 617,943 | |||
| 731,388 | 99.2% | 725,188 | |||
| 702,990 | 85.1% | 598,301 | |||
| 687,032 | 99.5% | 683,872 | |||
| 663,578 | 62.6% | 415,206 | |||
| 647,295 | 99.1% | 641,183 | |||
| 580,172 | 69.2% | 401,450 |
Embed this figure
On 13 of the 30 largest hosts and platforms, one certificate authority issues 90% or more of the certificates on their websites with a trusted certificate. Hostinger puts Let's Encrypt on 94.7% of its websites with a trusted certificate, Vercel on 98.0%, Squarespace on 94.2% and OVH on 93.7%, and WordPress.com puts Google Trust Services on 96.4%.
Some hosts use a commercial authority instead. IONOS puts Sectigo on 74.0% of its websites with a trusted certificate and Strato on 91.5%. Aruba puts Actalis on 79.7%, and Actalis has been part of the Aruba Group since 2009. Namecheap splits between Let's Encrypt on 65.7% and Sectigo on 28.3%, and Wix between Let's Encrypt on 69.7% and Google Trust Services on 30.2%.
The GoDaddy Website Builder, counted by its address blocks in this table, puts GoDaddy's own certificate on 98.2% of its websites with a trusted certificate; counted by its fingerprint in the platform table below, the share is 91.9%. That builder is where GoDaddy's rank comes from: 76.0% of every website with a GoDaddy certificate, 5,450,226, sits on it, and another 11.5% on GoDaddy's hosting.
Four names in these tables have a low trusted share. DreamHost's is 62.6% because its servers' own default certificate sits on 240,373 websites. Host Europe's 69.2% comes mostly from its ispgateway default certificate and from certificates that name no organisation, and certificates that name no organisation also pull GoDaddy's network outside its builder and hosting down to 80.1%. Jimdo's 80.3% comes mostly from answers the crawl could not read.
| CMS or site builder | Websites | Trusted share | With a trusted certificate | Most used CA | Second |
|---|---|---|---|---|---|
| 26,787,121 | 98.3% | 26,337,153 | |||
| 6,375,614 | 99.8% | 6,365,541 | |||
| 6,172,103 | 99.4% | 6,135,094 | |||
| 4,704,896 | 99.7% | 4,690,198 | |||
| 3,719,829 | 98.9% | 3,680,213 | |||
| 2,311,853 | 99.4% | 2,298,499 | |||
| 658,052 | 99.9% | 657,124 | |||
| 601,178 | 96.5% | 580,052 | |||
| 525,324 | 99.9% | 524,721 | |||
| 488,835 | 99.0% | 484,125 | |||
| 474,957 | 98.9% | 469,933 | |||
| 434,572 | 97.3% | 422,710 | |||
| 411,770 | 99.4% | 409,294 | |||
| 336,338 | 99.7% | 335,292 | |||
| 310,040 | 80.3% | 248,875 | |||
| 282,117 | 96.3% | 271,578 | |||
| 210,364 | 99.1% | 208,500 | |||
| 177,351 | 99.7% | 176,816 | |||
| 176,639 | 96.4% | 170,217 | |||
| 163,631 | 98.2% | 160,651 | |||
| 154,117 | 97.8% | 150,763 | |||
| 146,114 | 99.6% | 145,579 | |||
| 142,508 | 98.2% | 139,920 | |||
| 118,452 | 98.0% | 116,094 | |||
| 111,173 | 98.6% | 109,638 | |||
| 103,440 | 99.2% | 102,604 | |||
| No CMS or builder detected | 63,435,836 | 91.6% | 58,102,661 |
Embed this figure
Content management systems that run on any host follow the host. WordPress websites with a trusted certificate carry Let's Encrypt on 70.0%, Google Trust Services on 17.0% and Sectigo on 6.9%, close to the mix across the whole web. Hosted builders look like their host: Jimdo puts Google Trust Services on 97.8% of its websites with a trusted certificate, and MyWebsite Creator, the IONOS builder, puts Sectigo on 98.9%.
A certificate authority's market share is mostly a hosting market share. A host that changes its default moves millions of websites to another authority in one renewal cycle, and none of their owners has to do anything.
At least 81.8% of trusted certificates are free, and the top of the web pays
| Kind of certificate authority | Websites | Share of websites with a trusted certificate |
|---|---|---|
| Free by design | 89,823,769 | 81.8% |
| Amazon, free inside AWS | 1,161,608 | 1.1% |
| Free from the host | 40,287 | 0.04% |
| Free tier or paid, cannot tell | 1,430,248 | 1.3% |
| Sold or bundled by a host | 17,328,191 | 15.8% |
Embed this figure
81.8% of websites with a trusted certificate, 89,823,769, get it from an authority that charges nothing for it: Let's Encrypt, Google Trust Services, TrustAsia's LiteSSL or Fastly's Certainly, which Fastly issues to its customers at no extra cost. Counting Amazon, whose certificates cost nothing inside AWS services, the free share is 82.9%. Amazon is not wholly free: since June 2025 it also sells certificates that can be exported and used anywhere.
That share is a floor. 1.3% of trusted certificates come from authorities that run a free tier beside paid plans, ZeroSSL's free plan and Actalis's free domain certificates among them, and the certificate does not say which one a site used. The remaining 15.8% are sold outright or bundled into a hosting plan.
| Tranco rank | Websites with a trusted certificate | Share from a free CA |
|---|---|---|
| Top 1,000 | 456 | 35.3% |
| 1,001 to 10,000 | 4,919 | 50.7% |
| 10,001 to 100,000 | 52,007 | 59.7% |
| 100,001 to 1 million | 567,932 | 77.0% |
| 1,000,001 to 4,360,305 | 1,789,259 | 85.8% |
| Not in the list | 107,369,530 | 81.8% |
Embed this figure
Busier websites pay more often. Between Tranco ranks 1,001 and 10,000, 50.7% of the 4,919 websites with a trusted certificate use a free authority, against 85.8% between rank one million and the end of the list, and DigiCert issues 14.7% of them against 1.7% across the web. The top 1,000 goes further, 35.3% free and DigiCert on 114 of its 456 websites with a trusted certificate, but on a base that small the direction is clear and the size is not, and it counts only the top sites that let a crawler in.
Websites outside the list use free certificates less often than the ranked tail, 81.8% against 85.8%, and rank does not explain it. Bundled certificates do: GoDaddy issues 6.7% of the unranked websites' trusted certificates against 1.3% of the ranked tail's, and Sectigo 5.5% against 3.6%.
Free certificates won wherever a host makes the choice. The paid market that remains is the busiest websites and the hosts that put a commercial authority on every site they sell.
At least 97.4% of trusted certificates only prove control of the domain
| What the issuing intermediate says | Websites | Share of websites with a trusted certificate |
|---|---|---|
| Domain validated | 106,885,721 | 97.4% |
| Organisation validated | 507,518 | 0.46% |
| Extended validation | 22,367 | 0.02% |
| Not stated | 2,368,497 | 2.2% |
Embed this figure
At least 97.4% of websites with a trusted certificate, 106,885,721, carry a domain validated certificate. Under the Baseline Requirements such a certificate names no organisation: it proves that whoever asked for it controls the domain, and nothing about who they are.
An intermediate named for organisation validation issued the certificate on 507,518 websites, 0.46% of those with a trusted certificate, and one named for extended validation on 22,367, 0.02%. Both are floors, because 2.2% come from intermediates that issue more than one kind, so organisation and extended validation together cover between 0.48% and 2.6% of trusted certificates.
| Tranco rank | Websites | With a trusted certificate | Free CA | Let's Encrypt | DigiCert | EV named | OV named |
|---|---|---|---|---|---|---|---|
| Top 1,000 | 467 | 456 | 35.3% | 18.9% | 25.0% | 2.4% | 9.0% |
| 1,001 to 10,000 | 5,036 | 4,919 | 50.7% | 22.9% | 14.7% | 2.1% | 7.1% |
| 10,001 to 100,000 | 53,378 | 52,007 | 59.7% | 30.8% | 10.8% | 1.5% | 4.7% |
| 100,001 to 1 million | 582,728 | 567,932 | 77.0% | 48.0% | 5.1% | 0.54% | 1.9% |
| 1,000,001 to 4,360,305 | 1,855,590 | 1,789,259 | 85.8% | 58.9% | 2.4% | 0.16% | 0.74% |
| Not in the list | 113,342,237 | 107,369,530 | 81.8% | 64.1% | 1.7% | 0.01% | 0.45% |
Embed this figure
The busiest websites still buy identity. Between Tranco ranks 1,001 and 10,000, extended validation is named on at least 2.1% and organisation validation on at least 7.1% of the 4,919 websites with a trusted certificate. In the top 1,000 the counts are 11 and 41 of 456, where the direction is clear and the size is not. Browsers stopped rewarding it years ago: Chrome 77 moved the extended validation badge out of the address bar into the page information panel.
The padlock on nearly every website says the connection reaches the domain in the address bar. Who runs that domain is a question the certificate no longer answers for almost anyone.
Country extensions follow their hosts: Actalis on .it, Sectigo on .de
| Kind of extension | Websites | Trusted share | Plain HTTP share | With a trusted certificate | Most used CA | Second |
|---|---|---|---|---|---|---|
| Legacy generic, such as .com | 70,927,049 | 95.4% | 2.6% | 67,667,031 | ||
| New generic, such as .xyz | 12,338,887 | 94.5% | 3.2% | 11,657,304 | ||
| Country code | 32,569,127 | 93.5% | 3.2% | 30,456,641 |
Embed this figure
Every share in this section is of the websites on the domain extension named, and every authority share of those with a trusted certificate. Legacy generic extensions such as .com hold 61.2% of the web's websites, and 95.4% of them present a trusted certificate. Country code extensions hold 28.1% at 93.5%, and the new generic extensions released since 2013 hold 10.7% at 94.5%.
New generic extensions lean on Google Trust Services, at 27.7% of their trusted certificates, and Cloudflare is the largest host on 9 of the ten largest. Country codes carry the most Sectigo, 9.3%, and 51.7% of that Sectigo is on .de.
| Extension | Websites | Trusted share | Plain HTTP share | With a trusted certificate | Most used CA | Second |
|---|---|---|---|---|---|---|
| .com | 60,767,125 | 95.6% | 2.5% | 58,064,743 | ||
| .de | 4,975,670 | 93.0% | 2.0% | 4,627,533 | ||
| .org | 4,483,030 | 95.7% | 2.2% | 4,291,977 | ||
| .net | 3,763,313 | 94.0% | 3.3% | 3,538,387 | ||
| .ru | 2,156,759 | 88.0% | 5.8% | 1,898,208 | ||
| .co.uk | 1,900,505 | 93.3% | 4.3% | 1,773,707 | ||
| .nl | 1,552,039 | 94.5% | 1.4% | 1,467,425 | ||
| .fr | 1,255,277 | 96.1% | 2.4% | 1,205,806 | ||
| .com.br | 1,152,316 | 98.2% | 0.74% | 1,131,851 | ||
| .ch | 1,150,851 | 96.7% | 1.1% | 1,112,734 | ||
| .it | 1,106,775 | 97.1% | 1.1% | 1,075,134 | ||
| .online | 1,099,472 | 89.4% | 5.5% | 983,386 | ||
| .shop | 1,017,923 | 95.7% | 1.9% | 974,396 | ||
| .info | 935,682 | 91.6% | 5.6% | 857,304 | ||
| .top | 927,060 | 93.7% | 2.8% | 868,340 | ||
| .xyz | 885,648 | 91.8% | 6.0% | 813,106 | ||
| .com.au | 827,834 | 97.4% | 1.4% | 806,000 | ||
| .pl | 760,948 | 96.5% | 0.93% | 734,512 | ||
| .ca | 752,281 | 97.1% | 0.91% | 730,696 | ||
| .se | 731,763 | 96.3% | 1.7% | 704,652 | ||
| .eu | 715,562 | 91.1% | 3.8% | 651,786 | ||
| .app | 687,785 | 98.1% | 1.3% | 674,569 | ||
| .site | 632,487 | 95.5% | 2.4% | 604,143 | ||
| .cn | 587,590 | 61.5% | 29.9% | 361,592 | ||
| .cz | 577,526 | 92.3% | 2.6% | 532,947 | ||
| .store | 535,843 | 91.7% | 6.1% | 491,521 | ||
| .in | 505,521 | 97.3% | 0.90% | 491,770 | ||
| .es | 502,567 | 95.3% | 2.4% | 478,764 | ||
| .jp | 498,871 | 95.9% | 2.7% | 478,229 | ||
| .be | 485,727 | 95.3% | 1.9% | 462,794 | ||
| .at | 468,467 | 92.8% | 3.2% | 434,926 | ||
| .co.za | 438,436 | 95.8% | 1.1% | 419,971 | ||
| .us | 424,646 | 95.8% | 1.7% | 406,867 | ||
| .dk | 392,113 | 95.9% | 2.4% | 376,156 | ||
| .pro | 353,163 | 95.8% | 2.4% | 338,257 | ||
| .vip | 347,377 | 91.6% | 5.2% | 318,176 | ||
| .co | 345,774 | 96.6% | 1.7% | 334,017 | ||
| .biz | 303,350 | 93.4% | 3.8% | 283,254 | ||
| .hu | 302,200 | 93.9% | 1.7% | 283,765 | ||
| .рф | 300,456 | 76.6% | 17.8% | 230,228 |
Embed this figure
On .it, Actalis issues 28.6% of trusted certificates, and Aruba, which owns Actalis, hosts 37.4% of .it websites. On .de, Sectigo issues 31.7%, the certificate IONOS and Strato put on their customers' sites. On .us, Amazon issues 23.8% and AWS hosts 27.7% of the websites. On .jp, counting second levels such as co.jp, GlobalSign issues 9.8% of trusted certificates and JPRS, Japan's registry, 7.3%.
Poland's own authority, Certum, is the clearest case of a national authority. The Certum family, Certum itself and the sub-authorities Polish hosts such as home.pl and nazwa.pl run under it, issues 22.6% of the trusted certificates on .pl, counting its second levels such as com.pl. HARICA, the Greek academic authority, issues 15,144 websites' certificates, but only 80 on .gr. Its largest extension is .de, at 18.6% of its websites: Germany's research network, DFN, gets its certificates through GÉANT's certificate service, supplied by HARICA since 2025.
Two extensions stand apart. 29.9% of .cn websites answer only over plain HTTP and 61.5% present a trusted certificate; on .рф the figures are 17.8% and 76.6%. On both, a few hosts hold most of the plain HTTP: the five largest hold 63.1% of the plain HTTP websites on .cn, RAKsmart alone 42.3%, and 92.5% on .рф, REG.RU alone 56.8%. A national habit is possible, but the concentration points at those hosts first.
A national certificate authority wins where a national host bundles it, and nowhere else. The extension a website is registered on predicts its certificate only as far as it predicts its host.
379,202 websites serve a certificate that expired before the crawl
| Intermediate | Why every certificate from it had expired | Websites | Share of websites with a trusted certificate |
|---|---|---|---|
| Let's Encrypt R3 | Intermediate expired 15 Sep 2025 | 135,025 | 0.12% |
| Let's Encrypt X3 | Intermediate expired 6 Oct 2021 | 40,249 | 0.04% |
| Let's Encrypt R10 | Issuance ended 20 Aug 2025, certificates last 90 days | 73,993 | 0.07% |
| Let's Encrypt R11 | Issuance ended 20 Aug 2025, certificates last 90 days | 83,035 | 0.08% |
| Let's Encrypt E5 | Issuance ended 20 Aug 2025, certificates last 90 days | 18,797 | 0.02% |
| Let's Encrypt E6 | Issuance ended 20 Aug 2025, certificates last 90 days | 10,974 | 0.01% |
| Older Let's Encrypt | X1, X2, X4, E1, E2 and R4, expired 2020 to 2025 | 78 | under 0.01% |
| AlphaSSL SHA256 G2 | Intermediate expired 20 Feb 2024 | 5,674 | 0.01% |
| GlobalSign DV SHA256 G2 | Intermediate expired 20 Feb 2024 | 5,477 | under 0.01% |
| GlobalSign OV SHA256 G2 | Intermediate expired 20 Feb 2024 | 4,119 | under 0.01% |
| Other expired intermediates | GTS CA 1D2, GlobalSign DV G2, Gandi and Network Solutions, expired 2021 to 2024 | 1,781 | under 0.01% |
Embed this figure
379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began. 362,151 are Let's Encrypt certificates, 0.52% of its websites, and 17,051 come from GlobalSign, Google, Gandi and Network Solutions. Their intermediates prove it without an expiry date: R3 expired on 15 September 2025, Let's Encrypt Authority X3 in 2021, and GlobalSign's AlphaSSL, DV and OV SHA256 G2 intermediates on 20 February 2024.
The 186,799 Let's Encrypt certificates from R10, R11, E5 and E6 had expired too. Let's Encrypt moved issuance off those four on 20 August 2025 and issued 90-day certificates, so the last of them had lapsed by November 2025, six months before the crawl's first day.
This is a floor. The certificate's own expiry date is not stored, so a lapsed certificate from an intermediate still in use cannot be seen, and the true number is higher. Expired certificates gather in the long tail: 0.35% of unranked websites with a trusted certificate serve one, against 0.13% in the Tranco top million.
A certificate renews itself only as long as someone keeps the machinery that renews it running, and on these sites nobody has for months.
2,298,420 websites present a certificate no browser accepts
| Certificate browsers reject | Websites | Share of websites |
|---|---|---|
| Server default or test certificate | 1,175,312 | 1.0% |
| No organisation named | 632,428 | 0.55% |
| Other untrusted issuer | 283,499 | 0.24% |
| Failed verification in May | 163,318 | 0.14% |
| Cloudflare Origin CA certificate | 33,755 | 0.03% |
| Distrusted CA, Symantec era | 7,470 | 0.01% |
| Let's Encrypt staging certificate | 2,580 | under 0.01% |
| Fake Let's Encrypt or Google issuer | 58 | under 0.01% |
Embed this figure
2,298,420 websites, 2.0% of the web, present a certificate no browser accepts. 1,175,312 carry a server default or test certificate and 632,428 one whose issuer names no organisation; the largest named defaults are DreamHost's, on 240,373 websites, and the Plesk control panel's, on 214,494. Another 283,499 come from other untrusted issuers, which may include newer legitimate names the verifying pass never met, such as a newer Certum sub-authority.
163,318 failed verification in May, a group that may include incomplete chains a browser repairs by itself. 33,755 websites serve a Cloudflare Origin CA certificate straight to visitors, which Cloudflare warns produces untrusted certificate errors once its proxy is off. 7,470 still serve a certificate from an authority browsers have distrusted, Symantec's brands among them, and 2,580 a Let's Encrypt staging certificate, which exists for testing. Apart from all of these, 467,994 websites answered without the crawl recording an issuer at all, after a timeout or a failed handshake.
A website with a rejected certificate shows a full-page warning to anyone who visits over HTTPS, and most of these are servers that were never given a real certificate.
98.9% of Let's Encrypt websites crawled since 25 August 2026 carry its Generation Y chain
| Week crawled | Generation Y | Previous generation | Retired | Other | Let's Encrypt websites crawled |
|---|---|---|---|---|---|
| 15 Jun | 35.5% | 64.1% | 0.44% | 0% | 4,444,306 |
| 22 Jun | 44.5% | 55.0% | 0.50% | 0% | 2,716,858 |
| 29 Jun | 52.6% | 46.9% | 0.53% | 0% | 1,246,712 |
| 6 Jul | 66.4% | 33.1% | 0.54% | 0% | 1,241,661 |
| 13 Jul | 76.7% | 22.6% | 0.79% | 0% | 132,905 |
| 20 Jul | 91.2% | 8.0% | 0.73% | 0% | 2,373,041 |
| 27 Jul | 94.7% | 4.5% | 0.79% | 0% | 6,281,592 |
| 3 Aug | 96.7% | 2.5% | 0.85% | 0% | 3,718,063 |
| 10 Aug | 97.5% | 2.1% | 0.40% | 0% | 4,710,262 |
| 17 Aug | 99.2% | 0.68% | 0.16% | 0% | 3,917,218 |
| 24 Aug | 0 | ||||
| 31 Aug | 98.7% | 0.94% | 0.33% | 0% | 341,933 |
| 7 Sep | 0 | ||||
| 14 Sep | 5 | ||||
| 21 Sep | 98.9% | 0.62% | 0.53% | 0% | 23,846,794 |
| 28 Sep | 98.9% | 0.60% | 0.46% | 0% | 13,974,152 |
Embed this figure
Let's Encrypt switched its default profile to a new set of intermediates, which it calls Generation Y, on 27 May 2026, after a delay announced on its community forum. 98.9% of the Let's Encrypt websites crawled since 25 August 2026, 37,769,318 of 38,194,363, carry a certificate from one of them.
Key type is still mostly RSA: 66.2% of Let's Encrypt websites whose intermediate was recorded use an RSA key and 33.8% an ECDSA key.
38.4% of websites with a trusted certificate send HSTS, most because their platform does
| Platform | Websites with a trusted certificate | Send HSTS | Effective policy | Meet the preload rules |
|---|---|---|---|---|
| 6,264,135 | 99.9% | 81.5% | 0.01% | |
| 5,604,145 | 100.0% | 100.0% | 100.0% | |
| 4,639,579 | 100.0% | 100.0% | under 0.01% | |
| 2,830,223 | 100.0% | 100.0% | 7.4% | |
| 2,358,282 | 100.0% | 100.0% | 0.01% | |
| 1,131,715 | 98.4% | 98.4% | 3.2% | |
| 177,889 | 100.0% | 100.0% | 0.05% | |
| Every other website | 86,778,135 | 22.1% | 21.7% | 4.2% |
Embed this figure
38.4% of websites with a trusted certificate, 42,174,070, send a Strict-Transport-Security header, which tells a browser to use HTTPS for that site from then on (RFC 6797), and 37.0% send a policy that lasts longer than zero. The Web Almanac finds the header on 36% of mobile pages, a share of pages rather than of websites.
Seven platforms send 54.5% of the HSTS headers sent by websites with a trusted certificate, because they put one on effectively every site they host; Squarespace documents it as part of its default setting. On every other website with a trusted certificate, 22.1% send the header. The ten most common header values account for 88.1% of every website that sends one.
| Tranco rank | Websites with a trusted certificate | Send HSTS | Effective policy | Send HSTS, the seven platforms left out |
|---|---|---|---|---|
| Top 1,000 | 456 | 71.7% | 70.2% | 70.4% |
| 1,001 to 10,000 | 4,919 | 60.4% | 59.3% | 59.1% |
| 10,001 to 100,000 | 52,007 | 50.1% | 48.9% | 47.8% |
| 100,001 to 1 million | 567,932 | 38.6% | 37.5% | 33.5% |
| 1,000,001 to 4,360,305 | 1,789,259 | 30.8% | 30.0% | 25.8% |
| Not in the list | 107,369,530 | 38.5% | 37.1% | 22.0% |
Embed this figure
HSTS falls down the rank list, from 71.7% of the top 1,000 websites with a trusted certificate to 30.8% between rank one million and the end of the list. Websites outside the list break the pattern at 38.5%, above the ranked tail, and the platforms explain it: leave the seven out and the unranked share falls to 22.0%, below the tail's 25.8%.
| How long the policy lasts | Websites | Share of websites with a valid HSTS header |
|---|---|---|
| max-age=0 (switch HSTS off) | 1,498,077 | 3.6% |
| Under a day | 184,970 | 0.44% |
| A day to under six months | 9,141,382 | 21.7% |
| Six months to under a year | 1,247,281 | 3.0% |
| A year to under two | 19,171,010 | 45.5% |
| Two years or more | 10,902,512 | 25.9% |
Embed this figure
71.4% of valid policies last a year or more. 1,498,077 websites send max-age=0, which under RFC 6797 tells a browser to forget the site's HSTS policy, and 77.1% of them are on Squarespace: it sends the header on 99.9% of its websites with a trusted certificate but a policy longer than zero on only 81.5%.
| Step | Websites | Share of websites with a trusted certificate |
|---|---|---|
| A trusted certificate | 109,784,103 | 100.0% |
| Send HSTS | 42,174,070 | 38.4% |
| Valid policy above zero | 40,647,155 | 37.0% |
| At least a year | 30,073,522 | 27.4% |
| And includeSubDomains | 13,376,134 | 12.2% |
| And preload: ready | 9,469,985 | 8.6% |
| On the list by name | 61,386 | 0.06% |
| Covered by the list | 145,506 | 0.13% |
Embed this figure
8.6% of websites with a trusted certificate, 9,469,985, send a header that meets the preload list's rules: a year or more, includeSubDomains and the preload directive. 59.2% of them are GoDaddy Website Builder sites, whose header meets those rules on 5,602,567 of the builder's 5,604,145 websites with a trusted certificate, although hstspreload.org asks projects not to switch the preload directive on by default; the Web Almanac finds HSTS on 95.97% of the builder's pages. Only 61,386 of the ready websites, 0.65%, are on Chrome's preload list by name, and 1.5% counting parent and whole-extension entries.
HSTS is a platform setting that happens to live in a header. Where a platform switches it on, nearly every site has it; where the owner has to, about one in five does, and almost nobody finishes the step that puts a site on the list browsers ship with.
Frequently asked questions
How many websites use HTTPS in 2026? 94.8% of websites present a certificate from a publicly trusted authority, 109,784,103 of 115,839,436, and 96.8% complete an HTTPS connection of any kind. Counted by visits rather than websites, Google measures 95 to 99% of Chrome navigations over HTTPS.
What percentage of websites use Let's Encrypt? Let's Encrypt issues the certificate on 63.9% of websites whose certificate comes from a trusted authority, 70,152,849 websites. That is 60.6% of all websites, counting those without HTTPS.
Which certificate authority is the most popular? Let's Encrypt, at 63.9% of trusted certificates, ahead of Google Trust Services at 17.7% and GoDaddy at 6.5%. The three issue 88.2% of trusted certificates between them.
How many websites still use HTTP only? 3,288,919 websites, 2.8% of the web, answer only over plain HTTP. Since Chrome 154, released on 22 September 2026, Chrome asks users before their first visit to any of them.
Are free SSL certificates as secure as paid ones? A free domain validated certificate proves the same thing as a paid domain validated one, control of the domain, and encrypts the connection the same way; organisation and extended validation certificates also name the company, after checks on its legal existence. 81.8% of trusted certificates come from a free authority, and at least 97.4% of all trusted certificates, paid ones included, are domain validated.
How long do SSL certificates last in 2026? Under the CA/Browser Forum's ballot SC-081, now part of the Baseline Requirements, a publicly trusted certificate may last at most 200 days from 15 March 2026, falling to 100 days in March 2027 and 47 days in March 2029. Let's Encrypt's default classic profile issues 90-day certificates and its opt-in tlsserver profile 45-day ones since 13 May 2026, and the default moves to 64 days in February 2027 and 45 days in February 2028.
How many websites have an expired SSL certificate? At least 379,202 websites, 0.35% of those with a publicly trusted certificate, serve a certificate that had expired before the crawl began. The true number is higher, because only certificates from an intermediate that had itself expired or stopped issuing can be counted.
What percentage of websites use HSTS? 38.4% of websites with a trusted certificate send an HSTS header, 42,174,070 websites, which is 36.4% of all websites. Seven hosted platforms send 54.5% of those headers.
Methodology and sources
| Step | Domains | Share of the domains that answered 200 |
|---|---|---|
| Latest fetch answered 200 | 183,672,331 | 100.0% |
| Returned a readable page | 125,945,084 | 68.6% |
| At the apex of a registration | 119,918,539 | 65.3% |
| Parked domains removed | 115,839,436 | 63.1% |
Embed this figure
The population. Every share is of the 115,839,436 websites whose latest fetch answered 200 with a readable page, at the apex of a registration, with parked domains removed, or of a part of them the sentence names. The apex is a registrable domain as the Public Suffix List defines it. Parked domains come out on four signals: the crawl's parking pass (2,743,795), known parking networks (1,170,557) and the address blocks of GoDaddy's parking and aftermarket services and HugeDomains (163,839). The fourth, the fetch-time parking verdict, removes nothing, because the pages it marks never reach the readable step.
What a stored issuer can show. The crawl keeps the issuer of the certificate each website presented: country, organisation and common name of the intermediate. It does not keep the expiry date, the subject, the names the certificate covers, the TLS version or the rest of the chain. The fetch does not verify the certificate, so trust is judged from the issuer: a certificate counts as trusted when its issuing organisation is one the crawler accepted under full verification in its May pass, or one of three names added by hand, Cloudflare, Inc., Comodo CA Limited and Google Trust Services LLC. Let's Encrypt staging certificates, Cloudflare origin certificates, Symantec-era and other distrusted issuers, and certificates that imitate a trusted issuer's name are rejected even under a trusted organisation name. 1,207,329 Let's Encrypt websites have no recorded intermediate; they count toward Let's Encrypt and not toward the intermediate figures.
The host the certificate comes from. The certificate is the one on the host the fetch finished on. Where that host was recorded, for 50.9% of websites, it was the www address on 60.3% of them, partly because a fetch that fails over HTTPS is tried again at the www address over HTTP.
Hosts, platforms and headers. A host is found by its address blocks, a platform in the platform table by its fingerprints, and the seven HSTS platforms by the response headers they send, so one name can carry three counts: Vercel has 2,337,438 websites with a trusted certificate by address and 2,830,223 by its x-vercel-id header. A CA is counted under the brand on the certificate; the operated view folds white-label brands into the company that runs their intermediate. A website on two platforms counts under both.
Crawl window and plain HTTP. Websites were crawled on 84 days between 23 May 2026 and 29 September 2026, one row per domain at its latest fetch. The May fetches stored no intermediate for Let's Encrypt, so the weekly chart starts in June, and the Generation Y figures use websites crawled since 25 August 2026, by when every certificate issued before the switch had expired or been renewed. On 7 crawl days more than 5% of websites answered only over plain HTTP, and those days hold 33.0% of all plain HTTP websites. To test them, a random sample of 200 plain HTTP websites from the worst day, 4 August 2026, and a control of 200 from the ordinary days were fetched again on 29 September 2026, once over each scheme. Of those, 6 from the worst day and 8 from the control now answer over HTTPS with a trusted certificate, so the busy days crawled real plain HTTP websites. Squarespace, Wix and Shopify issue a certificate for every site they host, so a plain HTTP result from one of them would be a crawl error; it happened on 5,803 of their 13,018,701 websites.
Popularity. Rank bands use the Tranco list 38LNL, generated on 24 August 2026, 4,360,305 entries, each band excluding the ones above it. Only 467 of the top 1,000 names are websites in this base. Of the other 533, 258 never answered, 141 blocked or challenged the crawler with a status such as 403, 429 or 202, 66 answered 200 without a readable page, 44 answered 404, and 24 redirected, failed on the server, were parked or are not at the apex. Many of the names that block crawlers are large commercial sites, so the top 1,000 figures describe the websites that let a crawler in.
HSTS and the preload list. HSTS figures come from the same pass as every other figure, reading the header value of the 109,784,103 websites with a trusted certificate; a policy is effective when max-age is above zero. The preload list is Chromium's transport_security_state_static.json at commit d5e6fd5, dated 11 September 2026, with 94,778 entries.
Why subdomains have no figure. The crawl holds 5,962,579 subdomain hosts under 3,228,280 registered domains, but they are not a sample of subdomains. 69.9% entered from a ranked host list and 20.9% from links on crawled pages, so they were selected for being linked, and no zone file lists subdomains to measure them against. Hosting platforms fill the top by how often they are linked, wordpress.com with 69,478 hosts, and single parents skew the plain HTTP rate: free.fr alone holds 12.1% of the 169,210 plain HTTP subdomains.
Technology pages. The Let's Encrypt technology page counts 97,541,342 domains against 70,152,849 websites here, and GoDaddy SSL's counts 13,923,026 against 7,173,334: both count every domain the detection reads, and every domain whose CAA record names the authority. The Google Trust Services page counts 2,023,618 against 19,472,641, because its rule matches the issuer name Google Trust Services LLC, which only 1,049 of the certificates here carry; Google's current intermediates name Google Trust Services alone.
Not measured here. Certificate lifetimes and expiry dates, which the crawl does not store; the rules are moving fast, from ballot SC-081's limit of 200 days to 47 days by 2029, to Let's Encrypt's 64 and then 45 day default. TLS versions and cipher suites. Whether HTTP redirects to HTTPS. Wildcard and multi-name certificates, and whether the certificate matches the name. Revocation and certificate transparency. Mixed content on HTTPS pages. A year-on-year trend: this is the first crawl of its kind, and the next will be compared with it.