Defaults.Exposed

Defaults.ExposedStats › TLS & certificates

TLS & certificates

6 statistics · figures as of September 5, 2026 · census snapshot 2026-09-05 · September 2026 edition

HTTPS, certificate health, TLS versions and who issues the certificates the web runs on.

MeasureAs of September 5, 2026
HTTPS adoption 67.0%
TLS 1.3 adoption 94.4%
Valid certificate share 89.1%
HSTS adoption 21.1%

Transport security is the one area where the census records something close to success. 67.0% of graded domains serve their site over HTTPS, and of the domains presenting a certificate, 89.1% present one that is valid and trusted. Version adoption has followed: 94.4% of HTTPS-serving domains negotiate TLS 1.3, with 5.6% topping out at TLS 1.2. Compared with every other section on this site, that is a different internet.

It got that way through defaults and free issuance rather than through persuasion. Let’s Encrypt now issues for 55.73% of certificate-presenting domains, and the largest authority overall is Let's Encrypt at 55.73%. When the cost of a certificate went to zero and hosting platforms started provisioning them automatically, adoption followed without anybody having to be convinced. It is the clearest natural experiment the census contains, and the lesson generalises: controls get adopted when they become the default, not when they become well understood.

The residue is instructive. 104,446,408 domains still serve over plain HTTP with no HTTPS at all, and 4,160,496 present a self-signed certificate, which produces a browser warning and trains users to click through it. Neither is a hard problem in 2026. They persist on hosts nobody has touched in years, which is exactly the population most likely to be running other things nobody has touched in years.

The gap that undercuts the rest is HSTS. Only 21.1% of HTTPS-serving domains send a Strict-Transport-Security header, leaving 167,470,119 domains that serve HTTPS perfectly well and remain downgradable on a visitor’s first connection. Having a certificate protects the connection you make securely; HSTS is what stops an attacker talking a browser out of making it that way in the first place.

What remains after the HTTPS battle was won is the unglamorous part. Certificates expire, and an expired certificate produces the same browser interstitial as an attack would. Hostname mismatches do the same. Protocol and cipher configuration drifts out of date on hosts nobody revisits, and shortening certificate lifetimes across the industry means any host still renewing by hand now fails more often. Almost all of it is solved by automation that already exists and costs nothing.

The pattern worth carrying into the other sections is how this was won. Nobody persuaded millions of site owners that transport security mattered. Certificates became free, issuance became automatic, hosting platforms turned it on by default, and browsers started marking the alternative as insecure. Four changes to defaults and incentives, no change at all to what individual owners knew or believed. Every low number elsewhere on this site is waiting for the same treatment.

HSTS is one response header on a site that already has a certificate. The scan checks yours along with the certificate behind it.

Every statistic in this section

Each has its own citable permalink and a machine-readable twin at /stats/s/<id>.json, resolved from the same census files as the figures above.

← All sections · how we grade · data & downloads