Tony Wang6 min readHTTPS Got Democratized. The 27% Who Still Pay for a Certificate Look Exactly Like You'd Expect.
73.2% of reachable sites in our census use a free CA. The paid minority splits along the same top-heavy line as everything else here.
Free HTTPS was the plan all along — Let's Encrypt exists specifically to make certificate cost stop being a reason any site skips encryption. Split our census by certificate authority and the plan clearly worked: nearly three-quarters of the reachable web now runs on a free certificate. The interesting part isn't that majority. It's that the remaining quarter isn't random — it sorts by rank exactly like everything else in this census does.
Nearly three in four reachable sites run a free certificate
Let's Encrypt alone covers 339,096 reachable sites (40.0%); Google Trust Services — Google's own free CA, commonly auto-issued through Google Cloud, Firebase, and similar managed platforms — covers another 280,976 (33.2%). Combined, 620,072 sites, 73.2% of the reachable web, run on a certificate that cost nothing and required no manual renewal. This is the headline: paying for a certificate is now a minority behavior, and has been trending that way since Let's Encrypt's public launch in 2016.
The paying minority sorts by rank, same as everything else here
| Certificate authority | Top 10K | 10K-100K | 100K-1M |
|---|---|---|---|
| DigiCert3.17x top-heavy | 13.2% | 8.85% | 4.17% |
| Sectigo1.46x top-heavy | 4.72% | 4.28% | 3.23% |
| Google Trust Services1.22x tail-heavy | 23.28% | 26.61% | 28.3% |
| Let's Encrypt2.07x tail-heavy | 17.03% | 23.14% | 35.17% |
| CA | Top 10K | 10K–100K | 100K–1M | Direction |
|---|---|---|---|---|
| DigiCert | 13.20% | 8.85% | 4.17% | 3.17× top-heavy |
| Sectigo | 4.72% | 4.28% | 3.23% | 1.46× top-heavy |
| Google Trust Services | 23.28% | 26.61% | 28.30% | 1.22× tail-heavy |
| Let's Encrypt | 17.03% | 23.14% | 35.17% | 2.07× tail-heavy |
This is the same shape this census keeps finding in category after category: a paid, deliberately-chosen option concentrates toward the top of the web, while a free, default option climbs toward the tail. DigiCert's gradient is the sharpest of the four — sites in the top 10,000 run it more than three times as often as sites in the 100K–1M tail. A spot-check of real domains behind the top-tier DigiCert number reads exactly like what that gradient would predict: adobe.net, gs.com (Goldman Sachs), sony.net, uber.com, salesforce-sites.com, and bradesco.com.br (one of Brazil's largest banks) all appear in the top 10,000. Let's Encrypt runs the cleanest version of the opposite pattern — climbing at every single rank band, from 17.03% at the top to 35.17% in the tail.
Google Trust Services is the one entry that doesn't fit either camp cleanly, and worth noting rather than smoothing over: it's a free CA, but its gradient (1.22×) is far gentler than Let's Encrypt's (2.07×), and it actually leans slightly tail-heavy rather than perfectly flat. The likely explanation is that GTS gets auto-issued by Google's own managed platforms (Cloud Run, Firebase Hosting, App Engine) — services used across the whole size spectrum, including plenty of well-resourced companies that chose Google Cloud for reasons that have nothing to do with certificate cost. It's free like Let's Encrypt, but its distribution follows "who picked this cloud platform," not "who specifically needed a zero-cost certificate."
An honest gap: GlobalSign shows zero detections here
Limits, stated plainly
Certificate authority reflects a genuinely different kind of signal than most of this census: it's read from the TLS handshake, not from homepage HTML, so it's unaffected by JavaScript rendering, CAPTCHA challenges, or any of the usual reasons a fingerprint pass might miss something. But it inherits the same rank-band caution as every other cut in this series: the top-10,000 band is the smallest sample here too, so treat its exact percentages as directional. And as always, correlation isn't causation — a company doesn't get more traffic because it bought a DigiCert certificate; the more likely direction is that organizations large enough to have a dedicated security/IT budget are also more likely to already be operating at a scale that draws real traffic.
Query the full Tech Stack dataset
1,000,000 fingerprinted domains — CDN, CMS, ecommerce, SSL/TLS issuer and more — over one REST API, ranked by Tranco traffic rank.
Frequently asked questions
What percentage of websites use a free SSL certificate?
73.2% of reachable sites in Crawlora's 1,000,000-domain tech-stack census (620,072 of 847,491) use a free certificate authority - Let's Encrypt (339,096 sites, 40.0%) or Google Trust Services (280,976 sites, 33.2%).
Does using a paid SSL certificate correlate with website traffic rank?
Yes, sharply for the two paid CAs measured. DigiCert usage falls from 13.20% of the top 10,000 Tranco-ranked sites to 4.17% of the 100K-1M tail - a 3.17x top-heavy gradient. Sectigo shows the same direction more mildly (4.72% to 3.23%, 1.46x).
Does using Let's Encrypt correlate with website traffic rank?
Yes, in the opposite direction from paid CAs. Let's Encrypt usage climbs from 17.03% of the top 10,000 sites to 35.17% of the 100K-1M tail - a 2.07x tail-heavy gradient, the free default becoming more common further down the list.
Which companies use DigiCert certificates?
A spot-check of the top 10,000 Tranco-ranked sites carrying a DigiCert certificate in this census turned up adobe.net, gs.com (Goldman Sachs), sony.net, uber.com, salesforce-sites.com, and bradesco.com.br (one of Brazil's largest banks) - consistent with DigiCert's 3.17x top-heavy gradient.
Why does GlobalSign show zero usage in this census?
Not because no site uses GlobalSign - it's a real, commonly used paid certificate authority. This census's signature set simply doesn't yet include a marker for it, a stated detector coverage gap rather than a claim about real-world usage.