Certificate Authority Companies: The Complete List of SSL CAs (2026)
Every certificate authority company that issues browser-trusted SSL/TLS certificates, ranked by current market share, with who owns what, who is still trusted, and how to choose between them.
Short answer
Around 50 certificate authority companies operate publicly trusted roots, but eight of them issue the certificates on more than 95% of the web. As of 31 July 2026 (W3Techs): Let's Encrypt 64.7%, GlobalSign 19.6%, Sectigo 4.9%, GoDaddy Group 3.5%, DigiCert Group 1.6%, Actalis 0.6%, Certum 0.5% and Secom Trust 0.2%. Everyone else is below 0.1%.
Those numbers count websites, not money. DigiCert is the largest CA by revenue even though it appears fifth here, because enterprise OV, EV and private PKI contracts don't show up in a website survey. And the list is shorter than it looks: many familiar brands (GeoTrust, RapidSSL, Thawte, PositiveSSL, AlphaSSL) are resold roots belonging to four parent groups — see the ownership map below.
How many certificate authorities are there?
The Common CA Database, which the browser root programs all feed from, lists roughly fifty organisations with publicly trusted roots. W3Techs monitors about thirty-five of them in its daily website survey. Both numbers overstate how much choice you actually have: once you filter for CAs that issue at meaningful volume, sell to the public, and support ACME, the practical shortlist is under a dozen names.
Choosing between them stopped being a price question in March 2026. With certificates capped at 199 days and heading to 47 days by 2029, the cost that matters is renewal labour, and the differentiator is whether the CA can issue into your automation. Trust stability is the second filter — the Entrust distrust proved that a root can be removed from under you, and that migrating in a hurry is expensive.
Price still sets the floor for single-domain work, where every CA on this list issues essentially the same domain-validated product; you can compare our DV SSL certificate pricing to see what that tier costs before you weigh a CA's automation story against it.
What this guide covers
- • Profiles of the ten certificate authority companies that matter commercially
- • A complete list of every CA in the browser root stores, with current share
- • Who owns which brand — the consolidation map behind the marketing names
- • Market share as of 31 July 2026 and what moved since March
- • Trust status, including where Entrust stands two years after distrust
- • How the 199-day lifetime cap should change your selection criteria
Need SSL Certificates Now?
Don't wait - secure your website today with trusted SSL certificates
DV SSL Certificate
Starting at $3.99/year
- Instant issuance
- 256-bit encryption
- 99.9% browser compatibility
- 24/7 support
Detailed Certificate Authority Profiles

#1 DigiCert
Specializations
Company Overview
DigiCert is the world's largest commercial Certificate Authority by enterprise revenue, known for premium enterprise-grade certificates, a mature certificate lifecycle management platform and strong support. Its W3Techs website share is only 1.6% (31 July 2026) because raw website counts favour free DV issuers; DigiCert's business sits in the high-value enterprise, EV and private-PKI segments where per-certificate revenue is orders of magnitude higher.
Unique Features & Facts
- Largest commercial Certificate Authority by enterprise revenue
- Acquired Symantec's certificate business in 2017
- First CA to invest heavily in post-quantum cryptography readiness
- Powers certificates for the majority of Fortune 500 companies
- Leading provider of Extended Validation and organization-validated certificates
- Strong ACME automation support for the new 199-day certificate lifecycle

#2 Sectigo (formerly Comodo CA)
Specializations
Company Overview
Sectigo is the largest commercial CA by paid certificate volume and holds a 4.9% website market share (W3Techs, 31 July 2026). It combines low prices with a full enterprise product line, and its reseller channel is the reason so many hosting panels default to a Sectigo-issued certificate.
Unique Features & Facts
- Largest commercial CA by volume of paid certificates issued
- Provides certificates in over 100 countries
- Offers the PositiveSSL brand for budget-conscious buyers
- Strong reseller and partner channel ecosystem
- Comprehensive certificate lifecycle management (CLM) platform
- Full ACME protocol support for automated renewals under new 199-day rules

#3 GlobalSign
Specializations
Company Overview
GlobalSign is the largest commercial CA by website count, at 19.6% (W3Techs, 31 July 2026) — second only to Let's Encrypt overall. That share slipped from 24.2% in March 2026, which tracks with hosting platforms shifting bundled certificates towards free ACME issuance. Owned by Japan's GMO Internet Group, it is known for cloud PKI, IoT device identity and European compliance work.
Unique Features & Facts
- Europe's oldest SSL Certificate Authority
- Largest commercial CA by website market share (19.6%, W3Techs 31 July 2026 — down from 24.2% in March)
- Pioneer in cloud-based Public Key Infrastructure
- Specializes in IoT device identity and PKI automation at scale
- Operates a globally distributed, highly redundant CA infrastructure
- Strong focus on European compliance, GDPR, and eIDAS

#4 GoDaddy
Specializations
Company Overview
GoDaddy focuses on making SSL certificates accessible to small businesses and individual website owners with user-friendly interfaces and integrated domain services. The GoDaddy Group (GoDaddy plus Starfield Technologies roots) holds a 3.5% website market share.
Unique Features & Facts
- Tight integration with domain registration and hosting services
- Simplified SSL setup for non-technical users
- 24/7 phone support in multiple languages
- Automatic SSL installation for many hosting platforms
- Popular among small businesses and startups
- 3.5% of all websites, counting the GoDaddy and Starfield roots (W3Techs, 31 July 2026)
#5 Amazon Trust Services
Specializations
Company Overview
Amazon Trust Services represents the future of cloud-integrated PKI, offering seamless, free certificate management for AWS customers. Its W3Techs market share appears low (<0.1%) because ACM certificates are typically terminated at AWS load balancers, not directly visible on surveyed websites.
Unique Features & Facts
- Newest major CA, launched specifically for cloud services
- Seamlessly integrated with AWS Certificate Manager (ACM)
- Provides free, auto-renewing DV certificates for AWS customers
- Built from ground up for cloud-native applications
- Automatic renewal eliminates 199-day lifetime concerns for ACM users
- W3Techs share is low because ACM certs are behind load balancers, not directly on surveyed sites

#6 SSL.com
Specializations
Company Overview
SSL.com is a trusted Certificate Authority providing digital certificates, cloud signing services, and enterprise PKI solutions. It saw increased interest in 2024–2025 as organizations migrated away from Entrust following the browser distrust actions.
Unique Features & Facts
- International Trust Services Provider serving 180+ countries
- Specializes in document signing and digital identity solutions
- Offers both cloud-based and on-premises PKI solutions
- Strong focus on compliance and regulatory requirements
- Comprehensive certificate lifecycle management
- Gained attention as an Entrust migration alternative in 2024–2025

#7 Entrust (Distrusted)
Specializations
Company Overview
⚠️ Important: in mid-2024 Google Chrome, Mozilla Firefox and Apple stopped trusting new TLS certificates from Entrust's public roots after a run of compliance failures and slow incident responses. As of July 2026 that is settled history rather than breaking news — Entrust's surveyed website share is under 0.1%, and its public TLS offering is fulfilled from a partner CA's roots. Its private PKI and HSM business remains substantial. Listed here because it is still one of the certificate authority companies people search for, and because the episode is the clearest illustration of how CA trust actually works.
Unique Features & Facts
- ⚠️ Distrusted for new public TLS by Chrome (Nov 2024), Mozilla Firefox, and Apple Safari
- Two years on, its public TLS share sits below 0.1% of surveyed websites
- Formerly a pioneer in commercial PKI and government-grade certificates
- Now fulfils public TLS orders through certificates issued from another CA's roots
- Private PKI, HSM (nShield), identity and non-TLS products are unaffected
- Any Entrust-rooted TLS certificate still in production should have been replaced by now

#8 IdenTrust
Specializations
Company Overview
IdenTrust plays a crucial behind-the-scenes role in PKI, historically enabling Let's Encrypt's browser trust through cross-signing. It specializes in financial services, government PKI interoperability, and cross-certification between CAs.
Unique Features & Facts
- Historically cross-signed Let's Encrypt's root, enabling its early browser trust
- Specializes in financial services and payment card industry PKI
- Operates the Federal Bridge Certification Authority
- Critical infrastructure for government PKI interoperability
- Let's Encrypt now uses its own ISRG Root X1, reducing IdenTrust's visible role
- Enables trust relationships between different certificate authorities

#9 Certum
Specializations
Company Overview
Certum is a leading European Certificate Authority with over 30 years of experience, specializing in SSL certificates, qualified digital signatures, code signing, and S/MIME for the European market. It holds a 0.5% website market share (W3Techs, 31 July 2026), seventh among all CAs.
Unique Features & Facts
- One of the largest Certificate Authorities in Europe
- 30+ years of experience in digital certificate services
- Provides eIDAS-compliant qualified certificates
- Strong presence in Central and Eastern Europe
- Offers certificates in multiple European languages
- Growing as an Entrust migration destination for European organizations
#10 Actalis
Specializations
Company Overview
Actalis is Europe's premier CA for regulatory compliance, holding a 0.6% website market share (sixth-largest globally per W3Techs, 31 July 2026). It specializes in eIDAS-qualified certificates and European digital signature requirements.
Unique Features & Facts
- Leading European CA for eIDAS-compliant certificates
- 0.6% website market share — sixth-largest globally (W3Techs, 31 July 2026)
- Offers qualified certificates for legally binding digital signatures
- Specializes in Italian and European regulatory compliance
- Provides certified email services (PEC) in Italy and free S/MIME certificates
- Owned by Aruba S.p.A., Italy's largest hosting provider
SSL Certificate Market Analysis (March 2026)
Major Industry Event: Entrust Distrust (2024)
In mid-2024, Google Chrome, Mozilla Firefox, and Apple Safari announced they would no longer trust new TLS certificates issued from Entrust's public roots due to a pattern of compliance failures. The Chrome distrust took effect in November 2024. This is the most significant CA distrust event since Symantec (2017–2018) and has reshaped the competitive landscape, with DigiCert, Sectigo, and GlobalSign absorbing migrating customers.
Action required: Organizations still using Entrust TLS certificates should migrate to an alternative CA immediately.
Website Market Share (W3Techs, March 2026)
Note: W3Techs measures websites using each CA. Let's Encrypt dominates by volume (free DV certs). Commercial CA value is better measured by enterprise adoption and revenue.
Geographic Distribution
Industry Trends and Insights (2026)
The SSL certificate industry is undergoing its most significant transformation in years. The Entrust distrust event, shorter certificate lifetimes (199 days as of March 2026, heading to 47 days by 2029), and mandatory DNSSEC validation are forcing organizations to rethink their CA relationships and invest in automation.
Key Market Developments in 2025–2026
- 199-Day Certificate Lifetimes (March 2026): CA/Browser Forum Ballot SC-081v3 reduces maximum SSL validity to 199 days, with further cuts to 100 days (2027) and 47 days (2029). ACME automation is now essential.
- Entrust Distrust (2024): Chrome, Firefox, and Safari distrusted Entrust's public TLS roots—the biggest CA trust event since Symantec, reshaping the competitive landscape.
- DNSSEC Validation Required (March 2026): Ballot SC-085v2 requires CAs to verify DNSSEC signatures during domain validation, adding a new layer of trust.
- Automation Revolution: ACME protocol adoption is no longer optional—shorter lifetimes make manual renewal impractical for most organizations.
- Enterprise Focus: Commercial CAs emphasize high-value services like EV certificates, PKI consulting, and certificate lifecycle management (CLM) platforms.
- Cloud Integration: AWS Certificate Manager, Google Cloud, and Azure increasingly handle certificates natively, reducing traditional CA touchpoints.
Choosing the Right Certificate Authority in 2026
With shorter lifetimes and the Entrust shake-up, your choice of CA in 2026 should prioritize automation support, trust stability, and lifecycle management. Here's how to evaluate CAs based on different needs:
For Small Businesses & Personal Sites
- • Sectigo (affordable, strong ACME support)
- • GoDaddy (integrated with domains/hosting)
- • SSL.com (competitive pricing, growing trust)
- • Certum (excellent value for European users)
For Enterprise & High-Security
- • DigiCert (premium support, EV, CLM platform)
- • GlobalSign (PKI solutions, IoT identity)
- • Sectigo (enterprise CLM at competitive pricing)
- • ⚠️ Avoid Entrust for new public TLS certificates
Validation level is a separate decision from the CA itself, and it is the one that usually decides the invoice. If you are still working out whether domain, organization, or extended validation fits the site, our guide to the SSL certificate types sets out what each tier proves and who it suits.
Ready to Secure Your Website?
Choose from our curated selection of SSL certificates from trusted CAs
OV SSL Certificate
Starting at $39.99/year
- Organization validation
- 256-bit encryption
- $500K warranty
- Trusted by 99.9% browsers
Certificate Authority Feature Comparison
| Certificate Authority | DV | OV | EV | Wildcard | Multi-Domain | Warranty |
|---|---|---|---|---|---|---|
| DigiCert | Up to $1.75 million | |||||
| Sectigo (formerly Comodo CA) | Up to $500,000 | |||||
| GlobalSign | Up to $1.5 million | |||||
| GoDaddy | Up to $1 million | |||||
| Amazon Trust Services | - | No warranty (internal use) | ||||
| SSL.com | Up to $2 million |
Complete list of browser-trusted certificate authority companies
The ten profiles above cover the CAs most people are choosing between. This is the wider field: every certificate authority company W3Techs tracks, plus the notable regional and government roots in the CCADB. Shares are the 31 July 2026 survey.
| Certificate authority | Based in | Share | Notes |
|---|---|---|---|
| Let's Encrypt (ISRG) | United States | 64.7% | Free, DV only, ACME-native. The default for most of the web. |
| GlobalSign | Belgium / Japan (GMO) | 19.6% | Largest commercial CA by website count; heavy hosting-platform presence. |
| Sectigo | United Kingdom | 4.9% | Largest commercial CA by paid certificate volume; PositiveSSL, InstantSSL. |
| GoDaddy Group | United States | 3.5% | Includes GoDaddy and Starfield Technologies roots. |
| DigiCert Group | United States | 1.6% | Includes DigiCert, GeoTrust, RapidSSL, Thawte and the former Symantec roots. |
| Actalis | Italy | 0.6% | Aruba-owned; eIDAS-qualified certificates and free S/MIME. |
| Certum (Asseco) | Poland | 0.5% | Largest Central-European CA; qualified signatures and code signing. |
| Secom Trust | Japan | 0.2% | Dominant in the Japanese enterprise market. |
| SSL.com | United States | <0.1% | Document and code signing specialist; eSigner cloud signing. |
| HARICA | Greece | <0.1% | Academic and research CA; free certificates for the education sector. |
| IdenTrust | United States | <0.1% | Financial-services and federal PKI; historically cross-signed Let's Encrypt. |
| ZeroSSL | Austria | <0.1% | Free ACME-based DV issuance; roots operated with Sectigo. |
| Buypass | Norway | <0.1% | Free ACME DV certificates as a Let's Encrypt alternative. |
| D-Trust (Bundesdruckerei) | Germany | <0.1% | German state printer; qualified eIDAS certificates. |
| SwissSign | Switzerland | <0.1% | Swiss Post subsidiary; Swiss data-residency guarantees. |
| TWCA | Taiwan | <0.1% | Taiwan-CA; banking and government issuance. |
| Chunghwa Telecom | Taiwan | <0.1% | Telecom-operated public CA. |
| Deutsche Telekom | Germany | <0.1% | T-Systems Trust Center roots. |
| WISeKey Group | Switzerland | <0.1% | Includes the OISTE roots; IoT identity focus. |
| Amazon Trust Services | United States | <0.1% | Free certificates inside AWS; usually terminated at load balancers so surveys under-count it. |
| Google Trust Services | United States | <0.1% | Free ACME issuance for Google Cloud and public use. |
| Microsoft (Azure) | United States | <0.1% | Azure-native issuance via the Microsoft roots. |
| Entrust | United States | <0.1% | Distrusted for new public TLS from Nov 2024; private PKI and HSM business continues. |
| Certigna (Dhimyotis) | France | <0.1% | French qualified trust service provider. |
| Microsec | Hungary | <0.1% | e-Szigno qualified certificates. |
| Izenpe | Spain (Basque) | <0.1% | Regional public-sector CA. |
| Firmaprofesional | Spain | <0.1% | Qualified certificates for Spanish businesses. |
| NetLock | Hungary | <0.1% | One of the oldest CAs in Central Europe. |
| Disig | Slovakia | <0.1% | Slovak qualified trust service provider. |
| CertSIGN | Romania | <0.1% | Romanian qualified CA. |
| Hongkong Post | Hong Kong | <0.1% | Government-operated CA (Hongkong Post e-Cert). |
| TÜBİTAK Kamu SM | Turkey | <0.1% | Turkish public-sector research CA. |
| GoGetSSL | Latvia | <0.1% | Reseller-turned-brand issuing from partner roots. |
| LevelBlue (Trustwave) | United States | <0.1% | Legacy Trustwave roots, largely wound down. |
| Camerfirma | Spain | <0.1% | Distrusted by Mozilla and Chrome in 2021; listed for completeness. |
| StartCom | Israel / China | <0.1% | Distrusted in 2016–2018 and no longer operating publicly. |
Shares below 0.1% are rounded down by the survey; a CA appearing there can still be issuing millions of certificates into environments the crawler never sees (internal networks, load balancers, mobile backends).
A few names here — Certum and SSL.com in particular — do more business in signing than in TLS, and that market runs on its own rules about key storage and validity. If that is what brought you to this list, our code signing certificate options cover which of those CAs we issue from.
Who owns which certificate authority?
Twenty years of acquisitions left the market with far more brands than operators. If you are comparing two "different" CAs, check this first — you may be comparing two price tiers from the same issuing infrastructure, which also means they share a trust fate if that operator has an incident.
DigiCert Group
DigiCert, Inc. (Clearlake Capital / TA Associates)
One issuing platform behind seven brand names. GeoTrust and RapidSSL are the budget tiers of the same infrastructure that signs DigiCert EV.
Sectigo
Sectigo Ltd. (GI Partners)
Renamed from Comodo CA in 2018. Most cheap certificates sold by hosts and resellers trace back here.
GoDaddy Group
GoDaddy Inc.
Starfield is GoDaddy's second root; W3Techs counts them separately, which understates GoDaddy if you only read one row.
GlobalSign
GMO GlobalSign Holdings (GMO Internet Group, Japan)
AlphaSSL is the reseller-facing budget brand. GlobalSign's website share comes largely from hosting platforms bundling it.
Independent / non-profit
Various
No shared parent. Let's Encrypt is a US non-profit; the rest are independent operators or subsidiaries of hosting, telecom and IT groups.
Security Standards and Compliance
All major Certificate Authorities must adhere to strict industry standards and undergo regular audits to maintain their trusted status. Understanding these standards helps you evaluate the security posture of different CAs.
Industry Standards
- • CA/Browser Forum Guidelines: Baseline requirements for certificate issuance
- • WebTrust Audits: Annual security and compliance audits
- • ETSI Standards: European Telecommunications Standards Institute compliance
- • Common Criteria: International security evaluation standards
Root Programs
- • Mozilla Root Program: Firefox browser trust
- • Microsoft Root Program: Windows and IE/Edge trust
- • Apple Root Program: Safari and iOS trust
- • Google Root Program: Chrome browser trust
Future of Certificate Authorities (2026–2029)
The SSL certificate industry is entering a period of rapid transformation. The 199-day lifetime cap (March 2026) is just the beginning—47-day certificates by 2029 will make ACME automation non-negotiable. Post-quantum cryptography, stricter CA accountability, and cloud-native PKI are reshaping the competitive landscape.
What's Ahead
- • 47-Day Certificates (2029): SC-081v3 mandates 100-day certs in 2027, then 47-day in 2029—full automation is the only viable path
- • Post-Quantum Cryptography: CAs preparing for NIST-standardized PQC algorithms; DigiCert and GlobalSign are leading readiness efforts
- • Stricter CA Accountability: The Entrust distrust demonstrated that browsers will act decisively against non-compliant CAs
- • Certificate Lifecycle Management (CLM): Enterprise CLM platforms from Sectigo, DigiCert, and GlobalSign becoming essential infrastructure
- • IoT Device Identity: Growing demand for lightweight certificates in IoT, automotive, and embedded systems
- • Cloud-Native PKI: AWS ACM, Google Cloud, and Azure increasingly abstracting CA choice for cloud workloads
Get Started with SSL Today
Don't let security vulnerabilities put your business at risk
EV SSL Certificate
Starting at $149.99/year
- Extended validation
- Green address bar
- $1.75M warranty
- Maximum trust indicators