Defaults.Exposed

Defaults.Exposed보고서

Certificate Authority Race 2026: GoDaddy vs Google for Second Place

게시일 · 업데이트됨

Figures as of 2026-07-29 · methodology v8. Aggregate census data; we never publish an individual domain’s status or grade. Part of the July 2026 domain security census. See how we grade.

The war for the web’s certificates is over, and free won it. This edition, our scanners logged 212 million certificate observations. Each one is a domain that completed a TLS handshake with us and presented its certificate. A TLS handshake is the exchange that starts an encrypted connection. Let's Encrypt signs 52.6% of those observations. That is an outright majority: more than every other certificate authority combined. A majority is not a race. It is a result.

The real race is the one underneath. GoDaddy holds 18.6% and Google Trust Services holds 17.3%. Barely a length separates them. The prize is to be the web’s default issuer. Behind those two, the field falls off a cliff. Sectigo, the best of the rest, holds just 3.4%.

The July 2026 CA league table: one winner, one genuine race

A certificate authority, or CA, is the organisation that signs a certificate so that browsers will trust it. This edition we graded 297 million domains. From those graded domains we logged 212 million certificate observations, each a domain that completed a TLS handshake and presented a certificate. Counted once per domain, that comes to roughly 210 million TLS-reachable domains — the same set our TLS 1.3 report is built on.

Every share below is a share of that observed set, counted per domain observation. A certificate serving many domains counts once for each domain it fronts. About 1% of observations are re-scan duplicates; they do not move the shares.

Certificate authoritySharePosition in the race
Let's Encrypt52.6%Won the free war outright
GoDaddy18.6%Platform race — narrow leader
Google Trust Services17.3%Platform race — close challenger
Sectigo3.4%Best of the rest
DigiCert1.9%The chasing pack

Together, the top two issuers account for 71.2% of the observed set. They got there by opposite routes. One gives certificates away to anyone who can pass an automated check that they control the domain. The other bundles certificates into the registrar and hosting accounts its customers already hold. Below the GoDaddy–Google Trust Services platform race there is no third horse. The field drops to 3.4% and a scrap for what remains.

This is the July 2026 edition snapshot. The evergreen breakdown lives on our certificate authority market share page, and the headline figure has its own stat page.

Which of these names signs your certificate, and when does it expire? The free check shows your issuer and expiry in seconds, exactly as the outside world sees them.

Why did free win the certificate war?

Not on price. On defaults.

When Let’s Encrypt launched in 2015, the free certificate was only half the invention. The other half was the ACME protocol: a way for machines to request, validate, install and renew certificates with no human in the loop. Hosting panels, CDNs and cloud platforms wired ACME into their stacks. A certificate stopped being something you buy once a year. It became something that simply happens to your domain.

That is the whole story of the league table. A majority share is what a market looks like when the secure choice is also the zero-effort choice. This site exists because bad defaults quietly harm millions of domains. The certificate market is the best evidence we have for the reverse: make the good thing the default, and the good thing wins.

GoDaddy vs Google Trust Services: who gets to be your default issuer?

Look at the gap between GoDaddy (18.6%) and Google Trust Services (17.3%). A sliver of share separates them. It is the closest contest at the top of the table.

Neither company owes a share this size to over-the-counter sales. Google Trust Services, Google Trust Services in full, issues its certificates free of charge through a public ACME endpoint. A healthy slice of its share arrives through platforms that use it as a default issuer, including Cloudflare’s free plan. So the free model reaches further than the leader’s majority alone. Much of the second tier’s issuance is free too.

GoDaddy is a different case. It still sells certificates over the counter, and it runs one of the best-known retail SSL certificate businesses on the internet. But volume at this scale points to bundling. One caveat first: our census sees issuer names, not purchase channels. The distribution story that follows is inference, not measurement. The pattern is still well understood:

This is a platform race, not a certificate-sales race. It is the certificate-layer echo of the concentration we measure in DNS hosting. Second place goes to whichever platform provisions your certificate as a side effect. The customer often never sees the issuer’s name at all. That may well include you: most owners have never seen the name on their own certificate. Thirty seconds fixes that.

That leaves Sectigo (3.4%) and DigiCert (1.9%) splitting the leftovers. Part of that is hosting-panel automation, much of it now legacy. Sectigo long powered cPanel’s default AutoSSL; cPanel switched its default to Let’s Encrypt in 2024, but older panel installs still renew through Sectigo. Part is the traditional retail market: organisation-validated and extended-validation certificates, the dearer paperwork that vouches for a company’s legal identity rather than just its domain name. Add enterprise procurement, warranties and support contracts. Real business, but a small slice of a web that mostly gets its certificates without asking.

Does it matter who signs your certificate?

For security: mostly, no. A domain-validated certificate proves control of a domain and nothing more. Free or paid, it delivers the same TLS encryption and the same browser trust. No mainstream browser treats a free issuer’s certificate differently. Neither do we: our grading checks that your certificate is valid, trusted and correctly configured, never who signed it. The same default-driven force pushed TLS 1.3 to dominance.

What does matter is what the issuer model implies about renewal. In this edition, 18,602,449 domains presented a certificate that fails validation. Some had expired. Some were self-signed, meaning the server vouches for itself and no browser trusts it. Some arrived with a broken chain. A domain in that state risks greeting every visitor with a full-screen browser warning instead of a website.

These failures are rarely about who signed the certificate. Self-signed certificates make up 17.8% of the failures; the rest split across expiry, broken chains and name mismatches. The expired ones trace back to renewal nobody automated — an expiry date nobody was watching. Broken chains are deployment mistakes: someone forgot to install the intermediate certificate that links theirs to a trusted root. Self-signed certificates are often a deliberate server default, a configuration failure of a different kind. We track the validity split on its own stat page.

The certificate check in the free scan shows whether yours validates from the outside. Run it before your visitors run it for you.

Issuer choice does deserve one deliberate decision, though. A CAA record lets you declare which authorities are allowed to issue certificates for your domain. Most domains have never set one. See the CAA check; the free scan tells you whether yours has one.

So the honest answer is this: the name on your certificate is close to irrelevant. The machinery that renews it is close to everything.

From 90-day to 47-day certificates: automation stops being optional

The free leader’s certificates already live for roughly 90 days. That lifetime was chosen partly because it is too short to manage comfortably by hand. It was a deliberate push toward automation from day one. The rest of the industry is converging on the same logic. The CA/Browser Forum, the industry body where browsers and certificate authorities set these rules, has adopted a roadmap that shrinks maximum certificate lifetimes step by step. It reaches 47-day certificates by 2029.

Play that forward against the standings above. Annual manual renewal, the workflow the commercial CA market was built on, cannot survive lifetimes that short. Every certificate on the web becomes an automated certificate or a broken one. That compounds the free leader’s structural advantage. It also makes the race for second an even purer contest of bundling and platform integration: the certificates left standing will be the ones a platform renews for you.

Which side of that line is your domain on already? The free check shows your issuer and how long your current certificate lives. A roughly 90-day certificate from a platform issuer is the signature of automation. A one-year certificate is a countdown someone has to remember.

What this means for your business: automate SSL certificate renewal now

The certificate question for a business is no longer “which CA should we buy from?” It is “what renews our certificate, and would we notice if it stopped?”

The top three issuers’ volumes fit provisioning through hosting panels, registrars and platforms rather than direct sales — so there is a reasonable chance your certificate renews itself. That is inference from issuer names, not a measured fact, which is why verifying beats assuming. The free check shows your issuer, expiry and chain exactly as the outside world sees them.

Manual renewal is a different matter. If a human being is responsible for renewing your certificate on a schedule, you are carrying a countdown to an outage. When it hits zero, nothing fails gracefully: visitors, checkouts and paid ad clicks meet a full-screen security warning instead of your site, and revenue stops until someone notices — often hours later, because everything looks fine from inside the office. The shrinking-lifetime roadmap is about to make that countdown considerably shorter. Wiring up ACME automation now costs less in time than one incident will.

Check expiry from the outside, and keep checking. The free defaults.exposed check is that outside view — run it now, and again before any renewal window. It shows the countdown your internal calendar misses, before your customers meet the warning page. Expired certificates are one of the most common serious failures we see, and one of the most fixable.

The rule the data keeps repeating: automation or outage. The roadmap leaves no third option.

Want to know what your domain shows the world right now, certificate validity included? Run the free domain security check. One scan shows whether your certificate is valid and trusted, and how long it has left. That is the outside view your visitors and every browser get, and it never asks who you bought from. We never publish individual results, and the grade reflects only what browsers and attackers can see from the outside. If you don’t like the grade, the report shows which defaults to change to improve it.

Quick answers

What is the certificate authority market share in July 2026? In the July 2026 defaults.exposed census, Let's Encrypt signs 52.6% of the 212 million certificate observations we logged. Counted once per domain, those observations cover roughly 210 million TLS-reachable domains. GoDaddy follows on 18.6%, then Google Trust Services on 17.3%. For the evergreen, edition-independent breakdown, see our certificate authority market share page.

Who are the biggest certificate authorities after Let’s Encrypt? GoDaddy (18.6%) and Google Trust Services (17.3%), separated by under a point and a half in our July 2026 data. The scale of both points to platform distribution rather than over-the-counter sales: registrar and hosting bundles, plus cloud and CDN integration. Our census sees issuer names, not purchase channels, so that is inference from the pattern, not a measured sales split. Google Trust Services certificates are themselves free to obtain.

Are free SSL/TLS certificates as secure as paid ones? For the connection itself, yes. A domain-validated certificate delivers the same encryption and browser trust whatever it costs. That is how Let's Encrypt came to sign the certificate in a majority (52.6%) of the 212 million certificate observations in our census. Paid products differ in identity vetting (the organisation checks sold as OV and EV certificates), warranties and support. They do not differ in the strength of the encryption.

How long will SSL/TLS certificates last in the future? Under the CA/Browser Forum roadmap, maximum certificate lifetimes shrink step by step to 47 days by 2029. Let’s Encrypt certificates already last roughly 90 days. At 47 days, automated renewal is effectively mandatory.

How do I check which CA signs my domain’s certificate — and whether it is valid? Run the free check at defaults.exposed. It shows your issuer, expiry and certificate chain from the outside in seconds, along with your domain’s overall security grade.