Defaults.Exposed

Defaults.ExposedReports

One CA to Rule Them All: The Certificate Monoculture Report

Published

Figures as of 2026-08-16 (August 2026 round) — methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or certificate details.

The headline: half the encrypted web depends on one issuer

One certificate authority — Let’s Encrypt — now secures 50.2% of the 231.5 million domains that presented a certificate in our August 2026 census. And in 23 of 302 domain endings with meaningful certificate volume (10,000 or more certificates), a single CA holds 80% or more of everything.

The question that matters is not who is biggest — it is what breaks, and where, if one issuer stops issuing? Market share tells you who won. Dependency tells you who is exposed. This report maps the dependency.

The answers, in brief:

A monoculture is not a scandal. It is a structure. Nobody chose it, nobody runs it, and nobody is on the hook when it fails. That is exactly why it is worth measuring.

How concentrated is the certificate ecosystem?

Across the 231.5 million graded domains that presented a certificate this round (206.9 million of them valid), the top issuers account for nearly all certificate records. Here is how the largest ones split.

IssuerCertificates observedShare of cert-presenting domains
Let’s Encrypt116,262,88350.2%
GoDaddy (both org strings combined)49,350,72021.3%
Google Trust Services38,261,78116.5%
Sectigo8,988,8183.9%
DigiCert (both org strings combined)4,581,7232.0%

(GoDaddy and DigiCert each appear under two organisation-name strings in raw certificate data; we combine them here. The shape of the encrypted web is set by the top three; together the remaining issuers cover a small fraction of what any one of the big three secures alone. Sectigo and DigiCert are serious operations — but between them they account for under a tenth of the observed base.)

Two of the big three are free. That is the engine of the concentration. Let’s Encrypt made certificates free and automated in a way nothing before it did; Google Trust Services and the free tiers bundled by hosts and registrars followed. Website owners did the rational thing, one domain at a time, and the aggregate result is a dependency graph nobody designed.

To be clear about what we are measuring: this is the share of graded domains presenting a certificate in this census round, not a count of all certificates ever issued. We make no claim against certificate-transparency logs. The population is the live, reachable web as we found it in August 2026.

The 80% club: where one CA is the whole zone

Concentration at the global level is an abstraction. Concentration inside a single country’s domain ending is not. We calculated the top-1 CA share for every TLD with at least 10,000 observed certificates — 302 endings in total — and found 23 of them at or above 80% dependency on a single issuer.

The most dependent zones:

TLDRegion / noteTop-1 CA share
.xn—p1ai (.рф)Russia (Cyrillic)92.7% — Let’s Encrypt
.irIran89.7%
.byBelarus89.2%
.nu(Swedish-operated)85.8%
.rsSerbia85.4%
.noNorway84.5%
.uzUzbekistan84.5%
.keKenya84.3%
.lyLibya84.2%
.hrCroatia84.0%
.seSweden83.8%
.tzTanzania83.3%
.roRomania83.2%
.baBosnia & Herzegovina82.2%
.suSoviet legacy82.0%
.huHungary82.0%
.ruRussia81.7%
.eeEstonia81.5%
.pyParaguay80.9%
.zaSouth Africa80.2%
.clChile80.1%

All 21 entries above have Let’s Encrypt as their top-1 CA. Two further TLDs with ≥80% single-CA dependency complete the 23-zone club.

At the other end of the spectrum sit the most diversified zones: .la at 30.6% (with GoDaddy on top), .fund at 30.7%, .mobi at 31.2%, .to at 31.6% and .global at 31.7%. One caveat on the diversified end: per-TLD top-1 shares are computed on raw issuer-name strings, not on combined corporate entities — so in zones where a GoDaddy string tops the table, the true single-organisation dependency may run somewhat higher than the figure shown. Even allowing for that, these zones are in a different structural class from the 80% club.

In Russia’s Cyrillic domain space, more than 9 in 10 encrypted sites hang off a single certificate authority. There is no plausible fast substitute at that scale. A zone at roughly 30% dependency has a bad week if its top CA fails; a zone at 92.7% has a crisis.

The 80% club is dominated by two very different groups. The first is sanctioned or isolated economies — Russia, Belarus, Iran, Libya, the Soviet-legacy .su. The second is small, well-run European and other registries — Estonia, Sweden, Croatia, Serbia, Norway — where a single free CA simply won by being the obvious default. Same number, opposite stories. The league table tells you where the dependency is; it does not by itself tell you why, and the why matters for what anyone should do about it.

The sanctions pattern: Let’s Encrypt as accidental critical infrastructure

The top of the dependency table is not random. Russia (.рф and .ru), Belarus, Iran, Libya and the Soviet-legacy .su cluster at the extreme end for a reason that has nothing to do with technology preference: commercial certificates became hard to obtain in those markets, and Let’s Encrypt — free, automated, and available to anyone with a domain — remained available.

The consequence is worth stating plainly. A California non-profit is now the de facto national HTTPS infrastructure of the sanctioned world. Not by policy, not by mandate — by default.

For ordinary users in those countries, it is mostly good news. Encryption survived the commercial withdrawal. Shops, newspapers, schools and personal sites in .ir and .by still serve HTTPS because one issuer remained available. Had certificates remained a paid product, the sanctioned web would likely have gone dark or gone unencrypted.

For resilience, it is a genuine single point of dependency. If Let’s Encrypt ever stopped issuing to those regions — through a policy change, a legal compulsion, or a plain technical failure — there is no commercial fallback waiting. The 92.7% figure for .рф is what “no plan B” looks like in data.

We want to be careful with causality here. Our census observes the outcome — extreme single-CA concentration in sanctioned zones — and the reduced availability of commercial certificates in those markets is the well-documented backdrop. But a certificate census cannot see motive: we can say the pattern is consistent with sanctions-driven market withdrawal, not that we measured the withdrawal itself. The correlation is stark; the mechanism is inferred.

What actually happens if the big one breaks

“What if Let’s Encrypt goes down” is a question that is usually asked sloppily, so let us frame it precisely — because the precise version is more interesting than the scare version.

A CA failure does not switch off existing certificates. If Let’s Encrypt’s issuance stopped tomorrow, every certificate it has already issued would keep working until its own expiry date. Browsers would not throw a single new warning on day one. The failure mode of a certificate monoculture is not a blackout. It is a slow-motion expiry wave.

The speed of that wave depends on certificate lifetime, and this is where the modern web’s two big trends collide. Let’s Encrypt certificates live for 90 days by design — short lifetimes are genuinely good security practice, and automation makes them painless. But short lifetimes also mean the fleet is always close to its next renewal. Assuming certificate ages are spread evenly across the 90-day lifetime, roughly half of Let’s Encrypt’s 116.3 million certificates would expire within 45 days of a sustained issuance failure. In practice most clients renew at around day 60, so visible breakage would begin around day 30. No certificate authority failure in history has put a nine-digit number of domains on a 90-day expiry clock.

The same arithmetic applies to the other failure mode: distrust. CAs have been distrusted by browsers before, when audits failed or mis-issuance came to light. Distrust events are usually phased precisely because browser vendors understand the dependency. But phased or not, a distrust of any top-three issuer would force tens of millions of domains to re-issue elsewhere — and the 80% club shows which countries’ webs would be holding the longest queue.

None of this is a prediction. Let’s Encrypt has run reliably for a decade and is transparent about its engineering. The point of the exercise is not that the big issuer is fragile; it is that the web has quietly re-organised itself so that one organisation’s bad month is everyone’s bad month, and that this happened without anyone deciding it should.

The big zones: .com is nearly half Let’s Encrypt too

Concentration is not just a small-country story. Among the largest zones on the internet:

The Netherlands and France are wealthy, well-administered domain spaces with strong registries — and they are more concentrated than .com, not less. Concentration is not a symptom of neglect. It is what a well-automated, price-sensitive market converges on when one option is free and excellent. That is precisely why it will not fix itself.

The junk drawer: 700,000 sites trusted by nobody

At the bottom of the issuer table sits a museum of default configuration.

Those four strings alone sum to roughly 717,000 domains, and they are a non-exhaustive sample — the raw issuer table contains further default-configuration strings beyond these. These certificates still encrypt the connection; what they cannot do is prove who is on the other end. Visitors reaching these sites over HTTPS are met with a full-screen browser warning. The same Let’s Encrypt whose dominance this report examines would issue any of them a real, browser-trusted certificate in about a minute, for nothing. The barrier is not cost — it is that the padlock the owner saw on their own machine was never the padlock their visitors see.

What, if anything, should anyone do?

For an individual site owner, the honest answer is: probably nothing dramatic. Using Let’s Encrypt is a good decision, which is exactly why 116.3 million domains made it. Diversifying your personal certificate supply is rational only if your availability requirements are unusual — and if they are, the useful move is capability, not switching: make sure your automation can point at a second ACME-compatible CA, so a change of issuer is a config line and not a crisis project.

For registries, hosting platforms and national CERTs, the 80% club is a planning document. If your zone is in it, the question to ask is not “is our top CA trustworthy” — it is “what is our re-issuance surge capacity if we ever have to move 85% of our encrypted web inside a certificate lifetime.”

For everyone else, this report is a measurement of a bargain the web made mostly without noticing: free, automated, short-lived certificates made encryption near-universal, and the price is that one organisation’s bad month is now everyone’s bad month. On the evidence, it was a good bargain. It is still worth knowing where the dependency lives.

How we measured it

FAQ

How is this different from your CA market-share article?

Market share asks “who is biggest.” This report asks “where does one issuer’s failure hurt most” — dependency per domain ending, the 80% club, and the expiry arithmetic of an outage. Same underlying census, different and, we think, more consequential question.

Is Let’s Encrypt’s dominance a bad thing?

Not in itself. Making encryption free and automatic is why HTTPS became the norm rather than the exception. The finding of this report is not “the big CA is bad” — it is that dependency this concentrated deserves to be measured, mapped and planned for.

Would the web go down if Let’s Encrypt had an outage?

Not immediately. Existing certificates keep working until they expire, so the risk profile is a compounding expiry wave rather than a blackout — the full arithmetic is in the outage section above.

My site uses Let’s Encrypt. Should I switch?

For almost everyone, no. If you have unusual availability requirements, the resilient move is to make sure your certificate automation can switch to another ACME-compatible issuer — capability, not migration. And if your server presents one of the default self-signed certificates described above, replacing it with a real one is free and takes minutes.

What should my organisation actually do about CA concentration risk?

For most businesses running a handful of domains, the practical action is to verify that your certificate renewal is automated and that you have a tested runbook for switching CAs if you ever need to. ACME-compatible automation (Certbot, acme.sh, Caddy’s built-in client) can point at a different CA with a single config change — the investment is in making sure the change is tested before you need it urgently. For larger operations managing thousands of domains, or for national registries and hosting platforms, the 80% club figures are a direct input to business continuity planning: if your zone is in it, “what is our re-issuance surge capacity” is the question to put to your infrastructure team this quarter, not next year.

How does this compare to the July 2026 census?

The July 2026 round was our prior census measurement. CA concentration at this level is a structural condition, not a month-to-month fluctuation — the economics that drove Let’s Encrypt to 50%+ share (free, automated, ACME-compatible) have been in place for years and do not reverse quickly. What changes between rounds is fine-grained TLD-level shifts as hosting platforms update their defaults, new registrations come in, and zones grow or shrink. The 80% club’s composition and the headline 50.2% figure represent the accumulated outcome of years of rational individual decisions, not a recent spike. We will track whether the figure rises or plateaus as this becomes a recurring report.

Why does certificate authority concentration matter for IT and security teams specifically?

A certificate issued by an untrusted or distrusted CA throws the same full-page browser warning as an expired certificate — from the visitor’s perspective, the effect is identical. If your organisation’s TLS certificates all come from one provider and that provider faces a distrust event or extended outage, every HTTPS endpoint you run is simultaneously affected, at the same moment, with a re-issuance deadline set by the certificate lifetime clock. Most security teams have incident playbooks for a single certificate failing; very few have tested what a forced fleet-wide re-issuance looks like under time pressure. That gap is what this data is asking you to close.


What this means for IT managers, security teams, and business owners

The CA concentration data in this report is not an abstract infrastructure concern — it has direct operational implications for anyone responsible for keeping a website or application online.

For IT managers and security teams, the central question is readiness, not risk avoidance. Using Let’s Encrypt or any other dominant CA is not a mistake; it is the rational choice for most environments. The issue is whether your certificate automation has been tested for a forced migration. A CA distrust event or extended issuance outage does not ask whether you are ready — it sets a clock based on your certificate lifetime. If your certificates live for 90 days, your window to re-issue everything without visible breakage is measured in weeks, not months. The organisations that navigate that smoothly are the ones that already know which systems issue certs, how to change the CA endpoint, and who owns the approval chain. The ones that do not are the ones running bridge calls at 2am.

For business owners operating websites without dedicated IT support, the practical implication is simpler: make sure you know who manages your certificates, and make sure renewal is automated. The majority of expired certificate failures — and the CA concentration risk — trace back to the same root cause: the person who set up the server is gone, and nobody else knows where the certificate comes from or when it renews. A five-minute conversation with whoever hosts your website, confirming that auto-renewal is on and pointed at a current CA, eliminates most of the risk described in this report.

The 375,842 domains presenting “Internet Widgits Pty Ltd” test certificates represent a specific and entirely fixable failure: these sites are already serving HTTPS, the infrastructure is in place, but the operator either never finished the setup or never knew there was a difference between a self-signed certificate and a browser-trusted one. Every one of those sites could have a real, free, browser-trusted certificate installed in under ten minutes. The barrier is awareness, not cost or complexity.

Data to cite

“Let’s Encrypt issued 116,262,883 certificates — 50.2% of all 231.5 million certificate-presenting domains in the August 2026 census, making it the largest certificate authority in the history of the public web.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“Three organisations — Let’s Encrypt, GoDaddy, and Google Trust Services — account for 88.1% of the certificate-presenting web, meaning the encrypted internet runs almost entirely on a list of three issuers.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“23 of 302 domain endings with at least 10,000 observed certificates are 80% or more dependent on a single certificate authority, making a single issuer’s failure a national-scale event in those zones.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“Russia’s Cyrillic .рф ending is 92.7% dependent on Let’s Encrypt, Iran’s .ir is 89.7%, and Belarus’s .by is 89.2% — sanctioned economies where commercial certificate withdrawal left one free issuer carrying the entire national encrypted web.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“.com — the largest zone on the internet, with 111,937,121 certificates observed — is 48.3% Let’s Encrypt, meaning nearly half of all dot-com HTTPS depends on a single certificate authority.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“375,842 live domains are presenting a certificate issued by ‘Internet Widgits Pty Ltd’ — the OpenSSL placeholder name — meaning those sites are serving an untrusted self-signed test certificate to every visitor.” — defaults.exposed August 2026 Domain Security Census (432M domains)


Check your domain free at defaults.exposed — see exactly how your domain scores on certificate trust, issuer, validity, and 31 other externally observable security checks. Takes 30 seconds. No account needed. Read the full State of Domain Security 2026 report →

Aggregate data only. Data stored and processed in the EU.


How to cite this report

Press / blog: defaults.exposed (2026). One CA to Rule Them All: The Certificate Monoculture Report. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/certificate-authority-monoculture-report

Academic: defaults.exposed. (2026, August 18). One CA to Rule Them All: The Certificate Monoculture Report. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/certificate-authority-monoculture-report

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=231,455,163 certificates)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026