We Analyzed 8.7B SSL Certificates: RSA Retook the Lead From ECDSA in July 2026 (August 2026 Update)
RSA retook the public-web lead from ECDSA in July 2026 (50.3% vs 49.7%). Correcting the record too: Cloudflare's revised data moves the crossover from May to June.
Published •Updated •56 min read

Updated August 1, 2026 with July data, and with a correction. Two things happened since the Q2 close, and the second one is on us. First, RSA retook the lead in July: 50.3% of issuance against ECDSA's 49.7%. Second, Cloudflare has revised its certificate transparency series since we published on July 2, and the revision lands squarely on the month this report built its headline around. On today's numbers May reads 48.5% ECDSA, not the 50.21% we published, which means the crossover we reported in May did not happen in May. The only month ECDSA has ever held a clear majority is June 2026, at 52.2%, and it gave the lead back four weeks later.
So the honest version of the story this report has tracked all year is narrower, later, and shorter-lived than the version we told in July. I've rewritten the title and the sections that carried the May claim, and I explain below exactly what changed and how I verified it. The Q2 quarterly picture itself still holds: ECDSA was the majority for the quarter as a whole, and the year-over-year move from 26.5% remains the real structural story. The CA/Browser Forum's 200-day cap also did exactly what we said it would, with 200-plus-day certificates falling from 10.8% of issuance a year ago to 0.10%. The full Q1 report, the original monthly layers, and every deep dive are preserved beneath the new section.
Previously — updated July 2, 2026 for the Q2 close. Q2 has closed, and it settles the three June calls in this report. ECDSA held the majority for the entire quarter (50.3% of issuance), and June alone reached 52.4%. A year ago it was just 26.5%, so elliptic-curve certificates went from a 27% minority to the outright majority in twelve months. Two of my three June predictions landed and one missed; I grade all three below. (The May-crossover element of this note is superseded by the August correction above; the quarterly and year-over-year figures still stand.)
The internet issued 10,940,896,117 SSL/TLS certificates in Q1 2026 — January through March. That's roughly 1,407 certificates every second. As CTO of TechnologyChecker.io, I lead the engineering team that processes approximately 80% of all global certificate transparency log data — about 8.7 billion certificate records in Q1 2026 alone — as part of our technology detection pipeline. We've mapped those certificate records to 64.3 million unique domains in our technology-detection graph, which gives us direct visibility into the infrastructure decisions behind every HTTPS connection on the web. It's the most technically demanding part of our entire technology lookup stack.
Key findings, newest first — the August 2026 and June 2026 updates, then the original Q1 2026 analysis:
- August 2026 update — RSA retook the public-web lead in July 2026 (50.3% versus ECDSA's 49.7%). Cloudflare has also revised the May figures this report originally built its crossover on: May now reads 48.5% ECDSA, below the line, so the only month elliptic-curve certificates have held a clear majority is June 2026, at 52.2%. We verified the correction two independent ways before publishing it.
- June 2026 update — ⚠️ the crossover claim in this bullet is superseded by the August update above; preserved as originally published. ECDSA overtook RSA on the public web for the first time in May 2026 (50.21% vs 49.79%), landing the crossover exactly when our April analysis predicted. Let's Encrypt held mid-50s share (55.65%), Sectigo/ZeroSSL pulled into a dead heat with Google Trust Services for #2 (14.02% vs 14.07%), and 17.10% of all CT entries now flow through static/tiled logs rather than classic RFC 6962 logs.
- 10.94 billion certificates logged in Q1 2026, down 8.3% from Q4 2025 (11.94B), according to Cloudflare Radar Certificate Transparency
- Let's Encrypt controls 54.4% of all issuance, down sharply from 63.0% in Q4 2025, while Sectigo/ZeroSSL surged 41.2%
- ECDSA now accounts for 42.9% of all certificates, up from 34.5% in Q4 2025 — gaining 8.4 percentage points in a single quarter
- 86.6% of certificates have 47-100 day lifetimes (the 90-day standard)
- 96.8% are Domain Validated (DV), and only 188,610 used Extended Validation
- Microsoft Corporation certificates grew 500% quarter-over-quarter, signaling explosive Azure adoption
- Microsoft Azure now leads .net with 39.1M certificates, overtaking ZeroSSL on the enterprise TLD
July 2026: RSA retook the lead, and a correction to the May crossover
July closed with RSA back in front at 50.3% of issuance against ECDSA's 49.7%. That alone would be worth an update. What makes this one different is that re-pulling the monthly series to add July also showed that the series itself has changed underneath us, and the change lands on the exact month this report built its headline around.
Here is the corrected monthly series, with what we published in July shown beside it so you can see precisely what moved.
| Month | RSA share | ECDSA share | ECDSA as we published it in July |
|---|---|---|---|
| April 2026 | 51.66% | 48.34% | 47.35% |
| May 2026 | 51.47% | 48.53% | 50.21% (the "crossover") |
| June 2026 | 47.81% | 52.19% | 52.4% |
| July 2026 | 50.30% | 49.70% | not yet published |
Source: Cloudflare Radar — radar/ct/summary/public_key_algorithm, calendar-month windows, pulled 2026-08-01. Shares computed from raw counts (RAW_VALUES).
Read down the ECDSA column and the story this report told all year changes shape. We reported that elliptic-curve certificates crossed 50% in May and kept climbing. On the current data they didn't cross in May at all: May now reads 48.53%, roughly 1.7 points below what we published and clearly on the RSA side of the line. The only month ECDSA has ever held a clear majority of new issuance is June 2026, at 52.19%. Four weeks later RSA had it back.
How I verified the correction before publishing it
I'm not willing to retract a headline on a single query, so I checked the months two independent ways.
The first is the summary endpoint, one call per calendar month. The second is the daily time series for the same month, summed by hand. These are different code paths on Cloudflare's side, and they agree: May comes back at 48.53% and 49.40%, both below 50%. June comes back at 52.19% on both methods, matching to the decimal. July comes back at 49.70% and 49.77%. Wherever the two methods disagree slightly they still land on the same side of the 50% line, and on the one month that decides the story they agree exactly.
There's one wrinkle worth publishing rather than hiding, because it's the same trap this report flagged back in the April update. Cloudflare's weekly aggregation tells a different story from its daily and monthly aggregation: ask for weekly buckets and every week in May comes back above 50% ECDSA. Two of the three views agree with each other and one doesn't, so I've anchored everything here to calendar months cross-checked against daily sums, and said so rather than quietly picking the view that flatters the original call. When we wrote in May that mixing window types is "exactly what turns into a phantom reversal," that was the right instinct. It just turned out to apply to our own headline.
The underlying cause is ordinary and worth understanding if you work with CT data: certificate transparency logs are backfilled. Entries arrive late, logs get re-scanned, and a month that looked settled keeps moving for weeks afterward. We already saw a smaller version of this at the Q2 close, when Q1 volume was revised from 10.94 billion up to 11.4 billion. If you are citing a certificate-share figure for a month that closed less than about eight weeks ago, treat it as provisional. That now includes ours.
What this does and does not change
The quarter-level and year-over-year findings hold. ECDSA was still the majority across Q2 2026 as a whole, and the structural move is still the real story: a year ago RSA led better than 73/27, and today the two algorithms are inside a point of each other. A decade-long RSA default has become a coin flip. That's a far more durable observation than which side of 50% either one sat on in any single month, and it's the sentence I should have led with in July instead of the crossover date.
What changes is the certainty. The crossover wasn't a line the web crossed once and left behind. On the current data it's a boundary the web is oscillating across, month to month, with June the only clear ECDSA month so far. The next genuinely informative reading is whether August confirms July's reversal or swings back again. I'll report it either way.
Why I am not publishing July's certificate-authority numbers yet
Re-pulling July also showed large moves in certificate-authority share, including Let's Encrypt reading close to 69% for the month against 59.5% in June. I'm holding those back for now.
July's total logged volume came in roughly 10% below June's, and the daily series for July returned 30 days rather than 31, both of which point to ingestion that has not finished settling. A near-ten-point single-month swing in the largest CA on the web is exactly the kind of number a backfill can create and then erase. Having just corrected a headline that a backfill moved, publishing a second dramatic claim from a window with the same weakness would be a poor trade. The algorithm figures above survive the two-method check. The CA figures don't yet earn the same confidence, so they wait for the Q3 close. The Q2 certificate-authority table below remains the most reliable published view.
SSL certificates at the Q2 2026 close, with the year-over-year picture
This report tracked the RSA-to-ECDSA crossover month by month through May. Now that Q2 has closed, I re-pulled every Cloudflare Radar Certificate Transparency dimension for the full quarter (April 1 to June 30, 2026) and, for the first time in this report, for the same quarter a year earlier (April 1 to June 30, 2025). A note on the numbers: Radar returns these as raw certificate counts (RAW_VALUES), so every share below is computed against that window's own total, and the quarterly figures are the honest full-quarter aggregate rather than a single-month snapshot.
Two totals frame everything else. The CT logs recorded 13.75 billion certificates in Q2 2026, up from 10.33 billion in Q2 2025 (a 33% year-over-year increase). And the headline this report has chased all year is now settled at the quarter level: ECDSA is the majority public-key algorithm for the entire quarter (50.3%), up from 26.5% a year ago. Twelve months ago RSA led better than 73/27; today elliptic-curve certificates are the outright majority.
| Metric | Q2 2025 | Q1 2026 | Q2 2026 | YoY |
|---|---|---|---|---|
| ECDSA share | 26.5% | 43.1% | 50.3% | +23.8 pt |
| RSA share | 73.5% | 57.0% | 49.7% | −23.8 pt |
| Let's Encrypt (ISRG) CA share | 68.4% | 54.4% | 56.7% | −11.6 pt |
| Google Trust Services share | 13.6% | 16.7% | 13.4% | −0.3 pt |
| Sectigo / ZeroSSL share | 3.1% | 11.7% | 11.8% | +8.7 pt |
| Amazon Trust Services share | 1.3% | 3.8% | 6.5% | +5.2 pt |
| Microsoft Corporation share | ~0% | 0.2% | 1.3% | +1.3 pt |
| 200+ day certs | 10.8% | 3.8% | 0.10% | −10.7 pt |
| 100–200 day certs | 0.9% | 8.3% | 11.0% | +10.0 pt |
| 47–100 day certs (the 90-day norm) | 88.0% | 86.7% | 84.6% | −3.4 pt |
| Wildcard share | 22.3% | 29.6% | 27.4% | +5.1 pt |
| Pre-certificate share | 27.6% | 32.8% | 34.4% | +6.8 pt |
| IP-address certs | 0.01% | 0.34% | 0.88% | +0.9 pt |
| Static / tiled CT log share | 20.5% | 21.8% | 18.6% | −1.9 pt |
| DV share | 98.4% | 96.9% | 96.8% | −1.6 pt |
| EV share | 0.0023% | ~0.001% | 0.0010% | roughly halved |
Source: Cloudflare Radar — radar/ct/summary/{public_key_algorithm, signature_algorithm, ca_owner, duration, has_wildcards, entry_type, has_ips, log_api, validation_level}, quarterly windows 2025-04-01→2025-06-30, 2026-01-01→2026-03-31, and 2026-04-01→2026-06-30. Shares computed from raw counts.
The three June predictions, now settled
At the end of the May update I named three things to watch in June. Q2 answers all three, and I got two right and one wrong.
1. "How far ECDSA pulls ahead": it climbed, then gave it back. ⚠️ Revised August 1, 2026. At the Q2 close this read as a clean continuation: the quarter came in at 50.3% and June reached 52.4%, so I wrote that RSA was settling into the legacy tail rather than staging a defense. Two things have since undercut that. Cloudflare revised May down from 50.2% to 48.53%, which removes a step from the climb I described, and July came in at 49.70% ECDSA against 50.30% RSA, which is precisely the defense I said was not happening. The corrected April-to-July run is 48.34% → 48.53% → 52.19% → 49.70%: not a staircase, an oscillation around the 50% line. I got the direction of the year right and the durability of the crossover wrong.
2. "Whether ZeroSSL takes #2 outright": not yet; Google Trust Services held #2 for the quarter. May's 0.05-point single-month tie did not convert into a lead change across the full quarter. Google Trust Services finished Q2 at 13.4% to Sectigo/ZeroSSL's 11.8%, a 1.6-point margin. The honest mechanic is worth stating: that gap closed almost entirely because Google Trust Services fell (16.7% to 13.4% QoQ), not because ZeroSSL rose (it was flat, 11.7% to 11.8%). The #2 race narrowed hugely year over year (a 10.5-point Google lead a year ago is now 1.6 points), but ZeroSSL has not yet taken the slot.
3. "Whether static/tiled CT logs keep eating share": no, and this is the call I got wrong. I wrote that if static-log share climbed through 25% the classic RFC 6962 logs would start looking like the legacy tier. It didn't climb. Static-log share eased to 18.6% for Q2, down from 21.8% in Q1 and roughly flat against 20.5% a year ago. The tiled-log design is a durable, structural minority of the ecosystem, but it is range-bound in the high teens to low twenties, not on a march to majority. The RFC 6962 logs are not becoming legacy on this timeline. I would rather flag a missed call than quietly drop it.
What a full year changed that the monthly layers couldn't show
The month-to-month view is good at catching crossovers; it's poor at showing slow, structural change. Four year-over-year moves only become obvious at this range.
The 200-day policy cliff is nearly complete. The CA/Browser Forum's 200-day maximum took effect March 11, 2026. A year ago, 200-plus-day certificates were 10.8% of all issuance; this quarter they are 0.10%, an almost total elimination. The migration went two ways at once: issuance piled into the 100-to-200-day bucket (0.9% to 11.0% YoY), and the ultra-short-lived edge grew hard, with sub-7-day certificates rising from about 15.5 million a year ago to 455.6 million this quarter as CDN and ephemeral-instance rotation scaled. Certificate lifetimes are compressing from both ends.
Amazon Trust Services is the CA growth story of the year. Its share went 1.3% → 3.8% → 6.5% across the three windows, roughly a five-fold YoY gain that lifts it to the #4 CA owner, now ahead of both GoDaddy and DigiCert. An Amazon Trust Services certificate maps cleanly to AWS-fronted infrastructure in our detection engine, so a jump this size is a direct read on AWS certificate automation spreading across its customer base. Microsoft Corporation, from a near-zero base a year ago to 1.3%, tells the same Azure-adoption story one tier down.
IP-address certificates went from rounding error to real signal. Certificates issued for a bare IP rather than a hostname rose from 0.01% of issuance a year ago to 0.88% this quarter, which at Q2 volume is roughly 121 million certificates (up from 1.4 million). For detection this is high-value: an IP-address certificate almost always means infrastructure addressed directly rather than through DNS, exactly the API-gateway and device-fleet layer that frontend-only scanners never see.
Extended Validation is now shrinking in absolute terms. EV was already vestigial; the year-over-year data shows it going backwards even as the market grew. Total issuance rose 33% YoY, yet the raw count of EV certificates fell from 237,064 to 142,230. A product category that loses volume in absolute numbers during a 33% market expansion isn't dying slowly anymore. Pre-certificates, meanwhile, kept rising (27.6% to 34.4% YoY), a quiet sign of an ecosystem where more CAs submit to logs before issuance, which is a health signal for everyone who monitors CT.
Is ECDSA or RSA more common in 2026?
They are close enough that the answer changes month to month. In July 2026 RSA leads at 50.3% against ECDSA's 49.7%, per Cloudflare Radar Certificate Transparency data. Across Q2 2026 as a whole ECDSA held a narrow majority, and June is the one month with a clear ECDSA lead at 52.2%. The durable point is the year-over-year move: RSA led 73.5% to 26.5% a year ago and the two are now within a point of each other.
When did ECDSA actually overtake RSA?
On Cloudflare's current data, June 2026 is the only month ECDSA has held a clear majority (52.2%), and RSA retook the lead in July at 50.3%. An earlier version of this report placed the crossover in May 2026; Cloudflare has since revised that month down to 48.5% ECDSA, below the 50% line. We corrected it above and explain how we verified the change.
Why do certificate transparency numbers change after publication?
CT logs are backfilled. Entries arrive late and logs are re-scanned, so a recently closed month keeps moving for weeks. Cloudflare revised May 2026 ECDSA share from 50.21% to 48.53% and earlier revised Q1 volume from 10.94 billion to 11.4 billion. Treat any certificate-share figure for a month that closed less than roughly eight weeks ago as provisional.
Which certificate authority is the largest in 2026?
Let's Encrypt (ISRG) remains by far the largest, issuing 56.7% of all certificates in Q2 2026 per Cloudflare Radar. Google Trust Services holds #2 at 13.4%, with Sectigo/ZeroSSL close behind at 11.8% and Amazon Trust Services the fastest riser at 6.5% (up from 1.3% a year ago). One organization still issues more than half the web's certificates, a concentration worth tracking for infrastructure resilience.
Did Extended Validation (EV) certificates make a comeback in 2026?
No. EV certificates fell to 0.0010% of Q2 2026 issuance, and the raw count actually declined year over year (237,064 to 142,230) even as total issuance grew 33%, per Cloudflare Radar. Browsers removed the EV address-bar treatment in 2019-2020, and without that visual distinction the category has no remaining value proposition. Domain Validated certificates account for 96.8% of the market.
How Did SSL Certificate Issuance Evolve Through May 2026?
The sections from here down are preserved as the earlier record: the May crossover layer, the April waypoint, the Q1 2026 baseline, and every deep dive. The July 2026 update and the Q2 close above are the current snapshot; the layers below show how the year got there.
⚠️ Correction notice for everything below this line. These preserved layers were written when Cloudflare's data showed ECDSA reaching 50.21% in May 2026, and they report that crossover as a confirmed event. Cloudflare has since revised May down to 48.53%, below the 50% line. On current data the crossover did not happen in May, June is the only month with a clear ECDSA majority, and RSA retook the lead in July. We have left these sections as originally published rather than editing the record retroactively, but every "May crossover" claim below is superseded by the corrected series near the top of this report. Figures other than the algorithm shares in these layers were accurate to their pull date and have not been re-verified against later revisions.
According to Cloudflare Radar Certificate Transparency, ECDSA overtook RSA on the public web for the first time in May 2026 — 50.21% of all certificates to RSA's 49.79%. In April we wrote that crossover would land "inside Q2, likely May 2026." It did, almost to the figure. Let's Encrypt settled at 55.65% CA-owner share, Sectigo/ZeroSSL kept climbing into a near-tie with Google Trust Services for the #2 spot (14.02% vs 14.07%), the 200+ day duration cliff held at 0.12%, and a structural change in the logging layer itself surfaced: 17.10% of all CT entries now flow through static/tiled logs. We re-pulled every Cloudflare Radar Certificate Transparency dimension for the full calendar month of May 2026. Updated June 1, 2026.
From the engineering side, the crossover isn't an abstract milestone — it's a load-bearing change in our pipeline. For 20 years RSA was the certificate algorithm you fingerprinted by default and ECDSA was the exception you special-cased; from May 2026 that's inverted, and our matching logic has to assume elliptic-curve first. I called the timing in April because the leading indicators were unambiguous: every Let's Encrypt RSA issuer (R12, R13) was shrinking while its ECDSA issuers (E7, E8) grew, and the ZeroSSL ECC issuer — which defaults to ECDSA — was the fastest-growing major CA on the board. When the issuance defaults move, the whole web follows within a quarter. What I did not fully predict was how flat the move would look month to month once you strip out the rolling-window noise (see the month-by-month breakdown) — the crossover was a steady grind, not a jump.
Which Cloudflare Radar Metrics Changed Most Through May 2026?
A note on windows: the May 2026 column below is a clean per-calendar-month pull (May 1–31). The April column carries the rolling-window figures we published in our May 2 update — a ~28-day window that ran into early May and therefore reads slightly hotter than a clean calendar April would. Where May looks lower than April (the 47–100 day bucket, for instance), that's the window correcting, not a reversal. Treat the May column as the canonical monthly figure and the April column as the snapshot we reported at the time.
| Metric | Q1 2026 | April 2026 (rolling) | May 2026 (clean month) | Direction |
|---|---|---|---|---|
| ECDSA share | 42.9% | 49.0% | 50.21% | Crossed — now the majority algorithm |
| RSA share | 57.1% | 51.0% | 49.79% | Crossed — now the minority algorithm |
| ISRG (Let's Encrypt) CA-owner share | 54.4% | 56.8% | 55.65% | Settled in the mid-50s |
| Sectigo (ZeroSSL) CA-owner share | 11.7% | 12.9% | 14.02% | Pulled into a tie for #2 |
| Google Trust Services share | 16.7% | 16.2% | 14.07% | Slipping — barely holds #2 |
| Amazon Trust Services share | 3.8% | 2.8% | 5.13% | Rebounded above Q1 |
| GoDaddy share | 5.9% | 4.0% | 4.73% | Roughly flat |
| DigiCert share | 6.6% | 5.5% | 4.12% | Declining |
| Microsoft Corp share | 0.2% | 0.81% | 1.32% | Compounding — ~56M certs in May |
| ECDSA SHA-384 (signature algo) | 26.8% | 23.9% | 25.28% | Back to co-leading |
| ECDSA SHA-256 | 15.7% | 24.6% | 24.47% | Plateaued in a tie |
| RSA SHA-256 | 54.9% | 49.1% | 47.90% | Tracks the RSA decline |
| 47-100 day certs | 86.6% | 89.4% | 86.42% | Flat (April was window-high) |
| 100-200 day certs | 8.2% | 8.6% | 10.41% | Growing — the real migration |
| 200+ day certs | 4.0% | 0.14% | 0.12% | Policy cliff holds |
| DV share | 96.83% | 96.83% | 97.07% | Status quo |
| OV share | 3.16% | 3.16% | 2.92% | Status quo |
| EV share | 0.002% | ~0.0014% | 0.0010% | Vestigial |
| Wildcard share | 29.6% | 29.2% | 26.72% | Edging toward a quarter |
| Pre-certificate share | 33.5% | — | 33.72% | Stable |
| Static/tiled CT log share | — | — | 17.10% | New logging layer |
| IP-address certificates | — | — | 0.92% | Niche, emerging |
| Monthly CT volume | — | 3.55B | 4.28B | Highest single month on record |
Which Q1 2026 and April Narratives Did May Confirm, Reverse, or Extend?
1. The ECDSA crossover happened on schedule — a prediction confirmed. ⚠️ This claim is superseded; see the correction above. On Cloudflare's revised data May reads 48.53%, so the call landed a month later than we scored it here, and the majority did not hold. Q1 said ECDSA would "surpass RSA before the end of 2026." April tightened that to "inside Q2, likely May." May appeared to deliver: ECDSA 50.21%, RSA 49.79%. This is the kind of falsifiable call we want on record, because we named the quarter, the likely month, and the mechanism (managed-platform issuance defaults). Scored against the corrected series, the quarter was right and the month was wrong.
2. Let's Encrypt settled, and the real story moved to the #2 fight. Q1's "ISRG is collapsing" read was wrong — we said so in April, and May confirms it: Let's Encrypt is parked in the mid-50s (54.4% → 56.8% → 55.65%), not retreating. The genuine drama is now behind it. Sectigo/ZeroSSL has closed a 5-point gap to a dead heat — Google Trust Services 14.07%, Sectigo 14.02%, a 0.05-point margin for the #2 slot. Two quarters ago that gap was 16.7% vs 11.7%. We break this race out below.
3. Two April calls partly reversed on clean data — and that's worth saying plainly. In April we wrote that the 47–100 day "90-day standard" bucket tightened to 89.4%. On a clean May pull it sits at 86.42% — essentially identical to Q1's 86.6%. The April 89.4% was inflated by the rolling window; the bucket didn't tighten, it held. The genuine policy migration shows up one bucket over: 100–200 day certs grew from 8.2% (Q1) to 10.41% (May) as issuance shifted down out of the now-dead 200+ day bracket (still cratered at 0.12%). Separately, April's "ECDSA SHA-256 dethroned SHA-384" call reversed: on clean May data the two ECDSA signature variants are co-leading at ~25% each (SHA-384 25.28%, SHA-256 24.47%). The ECDSA family won; neither hash variant ran away with it.
Which Q1 2026 Certificate Trends Held Through May?
Microsoft Corporation's surge is still compounding. Its CA-owner share went 0.2% (Q1) → 0.81% (April) → 1.32% (May). Applied to May's 4.28-billion-certificate total, that's roughly 56 million Microsoft-issued certificates in a single month — nearly double April's 28.8M. Azure's expansion into the certificate-issuance business is structural, not a one-quarter spike.
EV certificates kept decaying — 0.0010% of May issuance, down from 0.002% in Q1. EV is past dying; it's vestigial. DV held at 97.07% and OV at 2.92% — five months of near-identical share. Validation-level distribution remains one of the most stable metrics on the entire CT corpus.
Wildcard share slipped to 26.72%, down from 29.6% in Q1. The "nearly a third of the web runs multi-subdomain architectures" framing now wants softening to "just over a quarter" — though with no clean calendar-April wildcard pull to compare against, some of that 3-point Q1→May drop could still be window composition rather than a hard trend. We'll watch it.
What Should We Watch for in June 2026?
How far ECDSA pulls ahead. Crossing 50% is the headline; the question now is whether ECDSA keeps grinding up toward 55%+ or whether RSA stabilizes as a long legacy tail (older enterprise PKI, embedded devices, and CAs whose defaults haven't moved). The Jan→May slope says up.
Whether ZeroSSL takes #2 outright. A 0.05-point margin is a coin flip. If Sectigo edges past Google Trust Services in June, that's the first time in years the #2 CA owner isn't a hyperscaler's trust service — a meaningful signal about where free, panel-integrated issuance is heading.
Whether static/tiled CT logs keep eating share. 17.10% of entries on the new static-CT-API logs is already a structural slice of the ecosystem. If that climbs through 25%, the classic RFC 6962 logs start looking like the legacy tier — which changes how everyone who ingests CT data (us included) has to architect their pipelines.
Month-by-month: how the RSA-ECDSA crossover actually happened
⚠️ Corrected August 1, 2026. This section originally presented the monthly series as "a tidy five-step climb" that crossed 50% in May. Cloudflare has since revised several of these months, and the revision removes the May crossover. The table below now shows the current figures alongside what we originally published. The narrative underneath has been corrected to match.
The quarterly and rolling-window views compress the most important certificate-algorithm shift of the decade into a handful of data points. Pulled as clean per-calendar-month snapshots, here is the full run, with July added and every month re-pulled on 2026-08-01:
| Month | RSA share | ECDSA share | Gap | ECDSA as originally published |
|---|---|---|---|---|
| January 2026 | 61.12% | 38.88% | RSA +22.2 pt | 38.42% |
| February 2026 | 54.56% | 45.44% | RSA +9.1 pt | 45.44% (unchanged) |
| March 2026 | 55.25% | 44.75% | RSA +10.5 pt | 45.65% |
| April 2026 | 51.66% | 48.34% | RSA +3.3 pt | 47.35% |
| May 2026 | 51.47% | 48.53% | RSA +2.9 pt | 50.21% (the "crossover") |
| June 2026 | 47.81% | 52.19% | ECDSA +4.4 pt | 52.4% |
| July 2026 | 50.30% | 49.70% | RSA +0.6 pt | not yet published |
Source: Cloudflare Radar — radar/ct/summary/public_key_algorithm, calendar-month windows, all re-pulled 2026-08-01. Shares computed from raw counts.
Three things stand out at monthly resolution, and the first one is not what this section used to say:
The climb was real, but it never became a settled crossover. ECDSA gained 6.6 points between January and February (38.88% → 45.44%) as the year-end RSA provisioning bulge cleared and issuers' ECDSA defaults took over the steady-state flow. From there it drifted up rather than marching: 44.75%, 48.34%, 48.53%, then a genuine June majority at 52.19%, then back under the line in July. February is the decisive month, not May. What follows February is a slow convergence toward parity, and parity is where the two algorithms still sit.
The older a month gets, the more you can trust it. February re-pulled at exactly the figure we published. January moved by less than half a point. March, April and May all moved by roughly one to two points, and May moved enough to erase a headline. That is the shape of CT backfill: recent months keep absorbing late entries, older months settle. It is the practical reason we now treat any month that closed inside the last eight weeks as provisional, including July's own figures above.
This is a clean monthly series; our April figure was a rolling window. Our April update reported ECDSA at 49.0%, but that came from a ~28-day window that ran into early May, catching the fastest part of the climb. The clean calendar-April pull now reads 48.34%. Both are honest, because they measure different windows. We flagged at the time that mixing window types is exactly what turns into a phantom "reversal," and we would rather show the seam than quietly paper over it. That warning aged into something more pointed than we intended: the reversal that eventually needed flagging was in our own May headline, and it came from backfill rather than window-mixing. The discipline was right even though we were the ones who needed it.
RSA isn't disappearing — it's becoming the legacy tail. Falling below 50% doesn't make RSA rare; it makes it the minority default. Half the public web's new certificates are still RSA, concentrated in older enterprise PKI, embedded and IoT fleets, and hosting panels whose defaults nobody has touched. For technology detection that inversion matters more than the headline: an RSA certificate is now a mild legacy signal where two years ago it was the null hypothesis. Of the 64.3 million domains we've mapped from CT logs, the ones still defaulting to RSA are increasingly a tell about the age and management maturity of the stack behind them.
The #2 fight: Google Trust Services and ZeroSSL are now a dead heat
While everyone watched the RSA-ECDSA line, the closer race was for second place among CA owners. In Q1 it wasn't close — Google Trust Services held 16.7% to ZeroSSL's 11.7%. By May the gap had all but vanished:
| CA owner | Q1 2026 | April 2026 | May 2026 |
|---|---|---|---|
| Google Trust Services | 16.7% | 16.2% | 14.07% |
| Sectigo (ZeroSSL) | 11.7% | 12.9% | 14.02% |
| Gap | 5.0 pt | 3.3 pt | 0.05 pt |
A 5-point lead narrowed to a 0.05-point margin — statistically a tie. ZeroSSL's rise is the clearest "free, panel-integrated, ECDSA-by-default" story in the data: its growth tracks Cloudflare's Universal SSL integration and one-click hosting-panel defaults, and its ECC issuer was the single fastest-growing major CA across the whole period (+51.1% QoQ). Google Trust Services isn't shrinking in absolute terms so much as growing slower than the total, so its share erodes while ZeroSSL's compounds.
For detection this matters because the two CAs map to opposite ends of the hosting market. A Google Trust Services certificate skews toward GCP-fronted and enterprise infrastructure; a ZeroSSL ECC certificate skews toward Cloudflare-integrated and budget or shared hosting. As their volumes converge, the base rate we assign each signal shifts — and getting that base rate right is the difference between a confident stack prediction and a coin flip.
Two new signals in the May data: static CT logs and IP-address certificates
Refreshing every dimension surfaced two breakdowns the original report didn't track, both of which say something about where the certificate ecosystem is heading.
17.10% of CT entries now flow through static (tiled) logs. The classic certificate transparency log defined by RFC 6962 is a dynamic, Merkle-tree-backed service that every monitor has to poll and reconcile. The newer static-CT-API design — Google's tiled-log specification, implemented by logs like Sunlight — serves the same auditable data as flat, cacheable, CDN-frontable tiles. As of May 2026, 82.90% of entries are still on RFC 6962 logs and 17.10% are on static logs. That is already a structural minority, not an experiment.
David Thomson, CTO, on what the static-log migration costs the people who ingest CT: Most readers will never notice this line item. We notice it acutely. Ingesting roughly 80% of global CT data means running a fleet that polls dozens of logs continuously, and the RFC 6962 logs and the new static logs are different ingestion problems — different consistency guarantees, different fetch patterns, different failure modes. Watching static logs jump to 17% of entries means a sizeable share of the 64.3 million domains in our detection graph is now arriving through a pipeline we had to stand up in parallel with the old one. Everything I learned building crawl and indexing infrastructure at Google Search transfers cleanly here: when the substrate underneath a data source changes, the teams who treated ingestion as a solved problem are the ones who quietly go blind. We re-architected for tiled logs early. The 17% figure is why that was the right call.
0.92% of May certificates were issued for bare IP addresses. That reads like rounding error until you apply it to volume: roughly 39 million certificates in a single month, issued not for a domain name but for an IP. This is new behavior — Let's Encrypt and a handful of other CAs began issuing short-lived IP-address certificates in 2025, and it is now a measurable, persistent slice. For us it is a high-value signal: an IP-address certificate almost always means infrastructure addressed directly rather than through DNS — API gateways, IoT device fleets, ephemeral cloud instances, and self-hosted services that never sit behind a conventional hostname. It is a window into exactly the backend, never-renders-HTML layer that frontend-only scanners cannot see.
This report breaks down the full SSL certificate transparency data for Q1 2026: who issues these certificates, which cryptographic algorithms dominate, what durations are standard, and why these shifts matter for website operators, security teams, and anyone selling into the infrastructure layer. I've spent 15 years building large-scale data systems — including five years on Google's Search team working on crawling and indexing infrastructure — and after architecting TechnologyChecker.io's detection pipeline that scans the 29.9 million active domains we crawl monthly, I can say with confidence that certificate transparency logs are among the richest and most underused signals in technology intelligence. Our competitors, as we've documented in our BuiltWith alternatives analysis, still rely primarily on frontend signals. They're missing the infrastructure layer entirely.
How many SSL certificates are issued per quarter in 2026?

In Q1 2026 (January 1 through March 31), certificate transparency logs recorded 10,940,896,117 new SSL/TLS certificates. The previous quarter (Q4 2025, October through December) logged 11,936,202,619, an 8.3% quarter-over-quarter decrease. That still translates to over 121.6 million certificates per day, or roughly 3.65 billion per month.
Certificate transparency has been mandatory for all publicly trusted certificates in Chrome since April 2018. Every certificate issued by a public CA gets recorded in append-only logs that anyone can audit. Our team at TechnologyChecker.io uses CT logs to identify hosting infrastructure and CDN providers across the 29.9 million active domains we scan monthly. It's one of our most reliable data sources.
Why does this matter beyond security? Certificate metadata tells you things that JavaScript fingerprinting can't. Which CA a company picked. Which algorithm. Whether they use wildcards. How often they rotate. These choices map directly to cloud providers and automation maturity.
According to Mordor Intelligence, the global Certificate Authority market is valued at $232.27 million in 2026 and projected to reach $396.58 million by 2031, growing at 11.32% CAGR. The sheer volume of certificate issuance we're tracking confirms this isn't slowing down.
Who are the largest Certificate Authorities in 2026?

Ten organizations control most of the global certificate issuance. We pulled this from Cloudflare Radar certificate transparency data for Q1 2026 (January 1 through March 31):
| CA Owner | Q1 2026 Volume | Market Share | Q4 2025 Volume | QoQ Change |
|---|---|---|---|---|
| ISRG (Let's Encrypt) | 5,950,304,369 | 54.4% | 7,522,440,330 | -20.9% |
| Google Trust Services | 1,822,660,520 | 16.7% | 1,789,579,382 | +1.8% |
| Sectigo (ZeroSSL) | 1,282,502,173 | 11.7% | 908,374,971 | +41.2% |
| DigiCert | 720,653,324 | 6.6% | 557,862,457 | +29.2% |
| GoDaddy | 643,592,385 | 5.9% | 630,672,950 | +2.0% |
| Amazon Trust Services | 417,009,827 | 3.8% | 325,676,379 | +28.1% |
| IdenTrust Services | 28,566,186 | 0.3% | 44,309,999 | -35.5% |
| SSL.com | 28,464,106 | 0.3% | 129,257,108 | -78.0% |
| Microsoft Corporation | 20,647,114 | 0.2% | 3,439,582 | +500.3% |
| GlobalSign | 12,049,799 | 0.1% | 11,905,002 | +1.2% |
SSL Certificate Authority Market Share Q1 2026: Let's Encrypt at 54.4%
ISRG (Let's Encrypt) issued 54.4% of all public SSL/TLS certificates in Q1 2026 — down sharply from 63.0% in Q4 2025. Google Trust Services holds 16.7%, Sectigo (ZeroSSL) surged to 11.7% (+41.2% QoQ), DigiCert 6.6%, GoDaddy 5.9%, and Amazon Trust Services 3.8%. The remaining 0.9% includes IdenTrust, SSL.com, Microsoft Corporation, and GlobalSign.
Source: Cloudflare Radar Certificate Transparency · Q1 2026
| Label | Value |
|---|---|
| ISRG (Let's Encrypt) | 54.4% |
| Google Trust Services | 16.7% |
| Sectigo (ZeroSSL) | 11.7% |
| DigiCert | 6.6% |
| GoDaddy | 5.9% |
| Amazon Trust Services | 3.8% |
| Other (IdenTrust, SSL.com, Microsoft, GlobalSign) | 0.9% |
- Let's Encrypt's share fell 8.6 percentage points in one quarter (63.0% → 54.4%) — the sharpest quarterly drop on record
- Sectigo/ZeroSSL grew 41.2% QoQ to 11.7%, driven by Cloudflare Universal SSL and free-tier expansion
- The top 3 CAs (ISRG, Google, Sectigo) control 82.8% of all global SSL issuance
- Microsoft Corporation grew 500% QoQ — small base, but the fastest-growing CA in absolute terms
May 2026 update — the #2 race tightened to a tie: On a clean full-month pull, Let's Encrypt settled at 55.65% of issuance — mid-50s, not collapsing (the Q1 "collapse" read was a Q4 2025 calendar artifact, as we said in April). The real movement is below it: Sectigo/ZeroSSL reached 14.02%, drawing level with Google Trust Services at 14.07% — a 0.05-point margin for second place, down from a 5-point Q1 gap. Microsoft Corporation kept compounding to 1.32% share — roughly 56M certificates in May, nearly double April's 28.8M. Amazon Trust Services rebounded to 5.13%, while DigiCert (4.12%) and GoDaddy (4.73%) eased.
Four trends stand out:
Let's Encrypt is losing market share fast. Down from 63.0% in Q4 2025 to 54.4% in Q1 2026 — an 8.6 percentage point drop in a single quarter. In absolute terms, ISRG issued 1.57 billion fewer certificates than the prior quarter. That said, renewal timing and short-lived certificate rotation cause natural quarter-to-quarter swings, and Q4 historically sees elevated issuance due to year-end infrastructure provisioning. Still, a 20.9% volume decline is the sharpest quarterly drop we've tracked.
Sectigo/ZeroSSL is surging. Up 41.2% quarter-over-quarter to nearly 1.28 billion certificates. They've firmly established themselves as the third-largest CA owner, now closer to Google Trust Services than ever. ZeroSSL has been pushing hard on free tier expansion and hosting panel integrations, and it's paying off.
Microsoft grew 500%. From 3.4 million to 20.6 million certificates — a six-fold increase in one quarter. That tracks with Microsoft Azure's accelerating cloud adoption. When we see a Microsoft Corporation CA on a domain, it almost always means ASP.NET infrastructure behind it.
Microsoft Azure SSL Certificate Growth 2025-2026: 500% QoQ Surge
Microsoft Corporation issued just 3.44 million SSL/TLS certificates in Q4 2025. In Q1 2026 that figure jumped to 20.65 million — a 500.3% quarter-over-quarter increase, the largest of any Certificate Authority. The per-month pace kept compounding: April 2026 alone produced 28.8 million Microsoft-issued certificates, and May reached roughly 56.5 million (1.32% of all issuance) — nearly double April. Azure's expansion into the certificate-issuance business is structural, not a one-quarter anomaly.
Source: Cloudflare Radar Certificate Transparency · Q4 2025 – May 2026
| Period | Certificates issued (millions) |
|---|---|
| Q4 2025 (3 mo) | 3.44M |
| Q1 2026 (3 mo) | 20.65M |
| Apr 2026 (1 mo) | 28.8M |
| May 2026 (1 mo) | 56.5M |
- Microsoft Corp grew 500.3% quarter-over-quarter into Q1 2026 — the largest QoQ surge of any major CA
- Single-month volume kept doubling: 28.8M in April, ~56.5M in May (1.32% CA-owner share)
- Microsoft Azure RSA TLS CA 04 leads .net with 39.1M certs and entered .io at 9.8M
- A Microsoft Corporation CA on a domain correlates with ASP.NET infrastructure at 85%+ probability
SSL.com collapsed 78%. From 129 million to 28 million certificates. The sharpest decline of any CA in our dataset. This likely reflects a shift in hosting panel defaults or a large customer migration away from SSL.com-issued certificates.
We feed CA distribution directly into our detection engine. Amazon Trust Services certificates mean AWS. Google Trust means GCP. Microsoft Azure CAs mean Azure. It's not a guess. Competitors focused on frontend JavaScript detection can't do this.
What are the top issuing Certificate Authorities by volume?

Parent CA owners operate multiple issuing CAs. Looking at the issuing level reveals the RSA-to-ECDSA shift happening in real time:
| Issuing CA | Parent | Q1 2026 Volume | Q4 2025 Volume | QoQ Change |
|---|---|---|---|---|
| R13 (RSA) | Let's Encrypt | 1,960,588,084 | 2,905,069,879 | -32.5% |
| R12 (RSA) | Let's Encrypt | 1,960,257,397 | 2,905,245,239 | -32.5% |
| WE1 | Google Trust | 1,424,115,916 | 1,423,591,197 | +0.04% |
| E7 (ECDSA) | Let's Encrypt | 993,860,966 | 855,590,883 | +16.2% |
| E8 (ECDSA) | Let's Encrypt | 993,801,264 | 855,528,023 | +16.2% |
| ZeroSSL ECC Domain Secure | Sectigo | 914,291,444 | 605,099,820 | +51.1% |
| Go Daddy Secure CA - G2 | GoDaddy | 507,520,723 | 623,930,701 | -18.7% |
| Encryption Everywhere DV TLS CA - G2 | DigiCert | 394,932,862 | 304,795,907 | +29.6% |
| WR1 | Google Trust | 287,764,146 | 271,986,877 | +5.8% |
| Sectigo Public Server Auth CA DV E36 | Sectigo | 250,466,591 | 196,006,151 | +27.8% |
The pattern is dramatic. Let's Encrypt's RSA issuers (R12 and R13) each dropped over 32% while their ECDSA issuers (E7 and E8) grew 16.2%. ZeroSSL's ECC (ECDSA) issuer surged 51.1%, the fastest growth of any major issuing CA. The migration from RSA to elliptic curve cryptography is accelerating faster than ever, and Q1 2026 data makes that undeniable.
Why should you care about which issuing CA shows up on a domain? Because it tells you more than "this site has HTTPS." An R13 certificate means Let's Encrypt RSA, and that correlates heavily with WordPress on shared hosting. A ZeroSSL ECC Domain Secure certificate usually means Cloudflare-integrated hosting. The issuing CA narrows the backend down before we even look at HTTP headers.
What is the single point of failure risk for Let's Encrypt?

ISRG (the parent of Let's Encrypt) issues 54.4% of all SSL/TLS certificates on the internet. One organization controls certificate issuance for more than half the web. That concentration creates real risk — though notably, it's trending in the right direction, down from 63.0% in Q4 2025.
Let's Encrypt certificates have 90-day lifetimes, which means millions need to be renewed every single day. The renewal process is automated through ACME clients like Certbot, and that automation works well. Until it doesn't.
Here's the problem: most ACME client configurations don't include automatic failover to an alternative CA. If Let's Encrypt experiences an extended outage, or a policy change forces revocation at scale (as happened with their CAA rechecking bug in March 2020, which affected 3 million certificates), millions of sites would face certificate expiry with no automated backup plan.
For security teams and site reliability engineers, this is worth tracking. At TechnologyChecker.io, we monitor CA distribution across domains as part of our infrastructure resilience assessment. A client running 100% of their properties on a single CA has a different risk profile than one distributing across two or three providers. We surface this data as part of our technology detection data intelligence.
I'm not saying Let's Encrypt is unreliable. They've built impressive infrastructure. But 54.4% market concentration in any system deserves attention. The good news is that the Q1 data shows the ecosystem is naturally diversifying — Sectigo, DigiCert, and Amazon are all gaining ground. Diversification isn't paranoia. It's engineering.
Which Certificate Authorities dominate which TLDs?

TLD-level CA distribution doesn't get much attention, but it should. We queried TLD-specific certificate transparency data for Q1 2026 and the results reveal some major shifts:
| TLD | #1 CA | Volume | #2 CA | Volume | Key Insight |
|---|---|---|---|---|---|
| .com | ZeroSSL ECC Domain Secure | 250.4M | R13 (Let's Encrypt) | 180.8M | ZeroSSL leads the most popular TLD by 1.4:1 |
| .org | R13 (Let's Encrypt) | 17.1M | R12 (Let's Encrypt) | 17.1M | ZeroSSL (17.1M) now virtually tied with LE |
| .io | R13 (Let's Encrypt) | 18.0M | R12 (Let's Encrypt) | 18.0M | Microsoft Azure emerges at #3 with 9.8M |
| .net | Microsoft Azure RSA TLS CA 04 | 39.1M | ZeroSSL ECC Domain Secure | 34.3M | Microsoft Azure now leads .net |
| .dev | WE1 (Google Trust) | 65.3M | Amazon RSA 2048 M04 | 32.4M | Amazon combined (64.7M) nearly matches Google |
Several things jumped out compared to our previous analysis:
ZeroSSL still dominates .com with 250.4 million certificates, about 1.4x Let's Encrypt's 180.8 million on the same TLD. The gap has narrowed from the 2:1 ratio we reported earlier, suggesting Let's Encrypt is making gains on .com specifically even as it loses overall market share. This dynamic is partly driven by Cloudflare's integration with Sectigo/ZeroSSL for their universal SSL product.
Microsoft Azure now leads .net. This is the biggest TLD-level shift in our Q1 data. Microsoft Azure RSA TLS CA 04 alone issued 39.1 million certificates on .net, taking the #1 position from ZeroSSL (34.3 million). When we detect a Microsoft Azure CA on a .net domain, the probability of an ASP.NET backend exceeds 85%. We've validated that number by cross-referencing with HTTP header analysis.
Microsoft Azure has arrived on .io. The developer/startup TLD that was previously almost entirely Let's Encrypt now shows Microsoft Azure RSA TLS CA 04 at #3 with 9.8 million certificates. This signals a meaningful shift in the startup and SaaS ecosystem toward Azure hosting, a trend our detection pipeline has been picking up since late 2025.
Google and Amazon are neck-and-neck on .dev. Google Trust's WE1 issuer leads with 65.3 million certificates, while Amazon RSA issuers combine for 64.7 million. The .dev TLD (operated by Google) was once clearly Google territory, but Amazon's near-equal presence confirms it's a fully multi-cloud TLD.
The .org TLD is now a three-way tie. Let's Encrypt R13 (17.1M), R12 (17.1M), and ZeroSSL ECC Domain Secure (17.1M) are virtually tied. The non-profit/open-source TLD that was once exclusively Let's Encrypt territory is diversifying fast.
These TLD-CA correlations feed directly into our tech stack predictions. You can't get this from scanning HTML source code.
What percentage of certificates use RSA versus ECDSA in 2026?

The shift from RSA to ECDSA accelerated dramatically in Q1 2026:
| Algorithm | Q1 2026 Volume | Q1 Share | Q4 2025 Share |
|---|---|---|---|
| RSA | 6,243,519,896 | 57.1% | 65.5% |
| ECDSA | 4,697,372,632 | 42.9% | 34.5% |
ECDSA Crossed 50% of New Certificates in June 2026, Then Fell Back
Six months earlier RSA outnumbered ECDSA nearly two to one: 65.6% to 34.5% in Q4 2025, a 31-point lead. ECDSA closed almost all of that through 2026, but it has not converted the climb into a settled crossover. June 2026 is the only month elliptic-curve certificates have held a clear majority, at 52.2%, and RSA retook the lead in July at 50.3%. An earlier version of this chart placed the crossover in May 2026; Cloudflare has since revised that month down to 48.5% ECDSA, below the 50% line, and the figures here reflect the corrected series.
Source: Cloudflare Radar Certificate Transparency · Q4 2025 – July 2026
| Period | ECDSA share of certificates (%) |
|---|---|
| Q4 2025 | 34.45% |
| Jan 2026 | 38.88% |
| Feb 2026 | 45.44% |
| Mar 2026 | 44.75% |
| Apr 2026 | 48.34% |
| May 2026 | 48.53% |
| Jun 2026 | 52.19% |
| Jul 2026 | 49.7% |
- June 2026 is the only month ECDSA has held a clear majority (52.2%); RSA retook the lead in July at 50.3%
- RSA fell from a 31-point lead in Q4 2025 to within a point of parity in seven months, then stabilised there
- The decisive move was January to February (+6.6 pts ECDSA) as the year-end RSA provisioning bulge cleared; what followed was convergence toward parity rather than a continued climb
- An earlier version placed the crossover in May 2026; Cloudflare revised that month to 48.5% ECDSA, so the corrected series shows the crossover arriving in June and lasting one month
May 2026 update — ECDSA crossed RSA, on schedule: It happened on the timeline we called in April. ECDSA reached 50.21% of all May issuance to RSA's 49.79% — the first month elliptic-curve certificates are the majority on the public web. The clean monthly climb: ECDSA 38.42% (Jan) → 45.44% (Feb) → 45.65% (Mar) → 47.35% (Apr) → 50.21% (May). One April call corrected on clean data: the two ECDSA signature variants didn't split the way we read them — they're co-leading at roughly 25% each (ECDSA SHA-384 25.28%, ECDSA SHA-256 24.47%), rather than SHA-256 running away with it. RSA SHA-256 fell to 47.90%. The ECDSA family won the web; no single hash variant did.
ECDSA gained 8.4 percentage points in a single quarter — the fastest adoption acceleration we'd ever measured. At the time we wrote that ECDSA would surpass RSA before the end of 2026; in the event it crossed far sooner, reaching 50.21% in May 2026 (see the update above). The Q1 signature algorithm breakdown that set up that call:
| Signature Algorithm | Volume | Share |
|---|---|---|
| RSA SHA-256 | 6,003,644,343 | 54.9% |
| ECDSA SHA-384 | 2,932,695,042 | 26.8% |
| ECDSA SHA-256 | 1,713,070,602 | 15.7% |
| RSA SHA-384 | 291,179,995 | 2.7% |
| RSA SHA-512 | 302,495 | ~0% |
| RSA SHA-1 | 51 | ~0% |
Only 51 certificates used SHA-1 in the entire quarter. SHA-1 is effectively dead for TLS.
The technical advantages of ECDSA are measurable. A 256-bit ECDSA key provides equivalent security to a 3,072-bit RSA key, with much smaller certificate sizes. According to SSL.com's ECDSA vs RSA comparison, ECDSA delivers 5-10x faster TLS handshakes and lower bandwidth consumption. That speed difference (100-300 milliseconds per handshake) matters for Largest Contentful Paint. Sites near the 2.5-second LCP threshold can pass or fail Core Web Vitals based on their certificate algorithm alone.
Algorithm choice tells us a lot about the infrastructure behind a domain. ECDSA with SHA-384 usually means modern cloud hosting and automated certificate management. RSA SHA-256 is more common on legacy hosting and shared environments where nobody changed the defaults.
I've been tracking this shift since we first started processing CT logs at scale, and Q1 2026 set up a call we got half right: ECDSA reached parity with RSA inside a single quarter rather than the two to three we initially hedged, though on Cloudflare's revised data the clear majority arrived in June rather than May and lasted one month (see the correction above). The ZeroSSL ECC issuer's 51.1% growth rate, and Let's Encrypt's E7/E8 ECDSA issuers growing while its R12/R13 RSA issuers declined, were the leading indicators that made the timing readable in advance.
How long do SSL certificates last in 2026?

Certificate lifetimes tell you how automated an organization's infrastructure is:
| Duration | Q1 2026 Volume | Share |
|---|---|---|
| 47-100 days | 9,477,167,467 | 86.6% |
| 100-200 days | 902,478,436 | 8.2% |
| 200+ days | 433,534,930 | 4.0% |
| 10-47 days | 46,196,184 | 0.4% |
| 3-7 days | 42,917,542 | 0.4% |
| 3 days or less | 38,321,360 | 0.4% |
| 7-10 days | 280,198 | ~0% |
SSL Certificates Over 200 Days Collapsed 97% After CA/B Forum Policy (March 2026)
The CA/Browser Forum's 200-day maximum certificate lifetime took effect on March 11, 2026. In Q1 2026, 4.0% of all certificates (433.5 million) had lifetimes exceeding 200 days. By April 2026 that bucket had collapsed to 0.14%, and a clean full-month May pull held it at 0.12% — the cliff is permanent, not a one-month shock. The genuine migration shows up one bucket over: the 100-200 day band grew from 8.2% (Q1) to 10.41% (May) as issuance shifted down out of the now-dead 200+ day bracket. This is the cleanest before-and-after observation in the entire CT dataset: regulatory deadlines on the public CA system are fast-acting, not symbolic.
Source: Cloudflare Radar Certificate Transparency · Q1 2026 – May 2026
| Period | Share of certificates over 200 days (%) |
|---|---|
| Q1 2026 (pre-policy) | 4% |
| Apr 2026 (post-policy) | 0.14% |
| May 2026 (held) | 0.12% |
- 200+ day certificates fell from 4.0% to 0.14% in 30 days, then held at 0.12% in May — a permanent cliff
- 433.5 million long-lived certificates in Q1 vanished from new issuance by April and stayed gone
- The real migration is the 100-200 day band, which grew from 8.2% (Q1) to 10.41% (May)
- Next deadlines: 100-day max by 2027, 47-day max by 2029 — forcing every operator into ACME automation
May 2026 update — the cliff held, and the migration moved one bucket over: On clean full-month data the 200+ day bucket stayed cratered at 0.12% — the CA/Browser Forum's March 11 maximum is permanent, not a one-month shock. But our April read needs a correction: we reported the 47-100 day bucket tightening to 89.4%; that was rolling-window inflation. The clean May figure is 86.42%, essentially identical to Q1's 86.6% — that bucket held, it didn't tighten. The genuine migration shows up one bucket over: 100-200 day certificates grew to 10.41% (from 8.2% in Q1) as issuance shifted down out of the now-dead 200+ day bracket. The policy is still the cleanest before-and-after in the dataset; the precise shape just needed a clean window to read correctly.
The 90-day certificate (47-100 day bucket) dominates at 86.6%. This is the standard for Let's Encrypt, Google Trust Services, and ZeroSSL. These three CAs together represent over 82% of the market, so their 90-day default sets the industry norm.
The 38.3 million certificates with lifetimes of 3 days or less are primarily from CDN providers. Cloudflare, for example, rotates edge certificates very frequently as part of their security model. When we detect ultra-short-lived certificates on a domain, it's a reliable signal for CDN-fronted architecture.
The 433.5 million certificates lasting 200+ days (4.0% of total) represent a shrinking segment that will decline rapidly now that the CA/Browser Forum's new policy took effect. According to SSL.com, effective March 11, 2026, SSL/TLS certificate maximum durations reduced to 200 days under the new CA/Browser Forum ballot, with further reductions to 47 days planned by 2029. The 100-200 day bucket grew from 4.1% in Q4 2025 to 8.2% in Q1 2026, as CAs shift issuance from the 200+ day bracket down to comply with the new maximum.
Certificate duration tells us about automation maturity. 90-day certificates with ACME renewal? Modern deployment practices, almost guaranteed. 200+ day certificates? Manual renewal, or a hosting provider that bundles long-lived certs — and a segment that's about to be forced into modernization. The correlation is strong enough that we use it as a detection signal.
What validation levels do certificates use?

The validation level data confirms what many of us in the security industry have been saying for years: Extended Validation is effectively dead.
| Validation Level | Q1 2026 Volume | Share |
|---|---|---|
| Domain Validated (DV) | 10,594,309,303 | 96.83% |
| Organization Validated (OV) | 345,285,805 | 3.16% |
| Unknown | 1,112,399 | 0.01% |
| Extended Validated (EV) | 188,610 | 0.002% |
May 2026 update — DV ticked up, EV is now a rounding error: DV rose slightly to 97.07% and OV eased to 2.92% — five months of near-identical share, still the most stable metric on the entire CT corpus. April issued just 49,965 EV certificates; by May, EV had fallen to 0.0010% of all issuance (down from 0.002% in Q1). EV isn't merely dying anymore — it's vestigial.
Only 188,610 Extended Validation certificates were issued out of 10.94 billion total in Q1 2026. That's 0.002%. Chrome and Firefox removed the green address bar for EV certificates in 2019-2020, and usage has cratered since. Users can't visually distinguish DV from EV in modern browsers, which eliminates the primary value proposition EV certificates once offered.
From an SEO perspective, HTTPS is a confirmed Google ranking signal (since 2014), but there's no differentiation between DV, OV, and EV. A free Let's Encrypt DV certificate has the same ranking value as a $1,000 EV certificate. The Google Content Warehouse API leak revealed hasSecureUrl as a binary attribute. It's on or off. No bonus for spending more.
OV certificates at 3.16% serve a different purpose. They're used by organizations that need verified identity in their certificate metadata, often for compliance requirements in finance, healthcare, and government. This is one of our detection signals: an OV certificate on a financial services domain correlates with regulated industry infrastructure.
How do wildcard certificates factor into the market?

Nearly a third of all certificates are wildcards:
| Wildcard Status | Q1 2026 Volume | Share |
|---|---|---|
| Without wildcards | 7,705,305,886 | 70.4% |
| With wildcards | 3,235,590,231 | 29.6% |
May 2026 update — wildcards edged below a third toward a quarter: On a clean full-month pull, wildcard share slipped to 26.72% (from 29.6% in Q1). The "nearly a third" framing below was true when we wrote it; it now wants softening to "just over a quarter." One honest caveat: without a clean calendar-April wildcard pull to compare against, part of that ~3-point drop could be window composition rather than a hard trend — so we're calling it a drift to watch, not a confirmed structural decline.
A wildcard certificate (*.example.com) covers all subdomains under a single domain. 29.6% is a lot. It tells us that nearly a third of the web runs multi-subdomain architectures: enterprise SaaS platforms, CDN providers, organizations with multiple customer-facing services under one domain.
We use wildcards as a detection input. A wildcard from Amazon Trust Services using ECDSA? Almost always AWS-hosted SaaS on Application Load Balancers. A wildcard from Let's Encrypt using RSA? More likely WordPress multisite or shared hosting. The CA + algorithm + wildcard combination narrows the stack prediction fast.
The wildcard split also tells us about operational maturity. Managing dozens of subdomains with individual certificates is expensive. Wildcards mean centralized infrastructure management, which correlates with DevOps practices and infrastructure-as-code. When we see wildcards, we know the team has invested in automation.
What do certificate expiration patterns reveal?

As of early April 2026, the vast majority of Q1 2026 certificates remain valid:
| Status | Q1 2026 Volume | Share |
|---|---|---|
| Valid | 10,492,396,419 | 95.9% |
| Expired | 448,499,698 | 4.1% |
The 448.5 million certificates that have already expired include ultra-short-lived CDN certificates (38.3 million were 3 days or less at issuance) and early-January certificates approaching the end of their 90-day validity windows. That's roughly 5 million certificates expiring per day — every one a potential problem. Browser warnings scare visitors. API integrations break. Google Search Console flags the domain.
For us, expired certificates are useful in a different way. When a domain's certificates consistently lapse, it's a leading indicator of the domain going dark or changing ownership. We track that as part of our infrastructure health signals.
By contrast, Q4 2025 certificates show 91% already expired when viewed today — which is expected, since most 90-day certificates from October-December 2025 have naturally reached the end of their validity by April 2026. This confirms the rapid rotation cycle that defines modern certificate management.
What does certificate entry type data show?

Certificate transparency logs accept two types of entries: final certificates and pre-certificates.
| Entry Type | Q1 2026 Volume | Share |
|---|---|---|
| Certificate | 7,279,390,912 | 66.5% |
| Pre-certificate | 3,661,505,205 | 33.5% |
Pre-certificates get submitted to CT logs before the final certificate is issued, as defined in RFC 6962. The 33.5% pre-certificate rate increased from 30.5% in Q4 2025, indicating improving CT ecosystem health. CAs submitting pre-certificates let monitors catch misissued certificates before they go live.
Why do we care? Pre-certificates give us advance notice. New domains, new certificates being provisioned, often hours or days before anything goes live. That early signal feeds into our real-time detection pipeline.
Why certificate transparency data matters for technology detection

This is where we do something nobody else does. We processed about 8.7 billion certificate records in Q1 2026 from CT logs. That's roughly 80% of all global CT log data — nearly 2.9 billion per month. No competitor touches this data.
Here's what CT data actually tells our detection engine:
CA selection maps to hosting providers. Amazon Trust Services = AWS. Microsoft Azure CAs = Azure. Google Trust Services = GCP. We've validated these mappings across millions of domains by cross-referencing with DNS records and HTTP headers. It's deterministic, not probabilistic.
Algorithm choices reveal platform age. ECDSA with modern hash algorithms? Updated platform, automated certificate management. RSA SHA-256 on a long-lived certificate? Probably a legacy system nobody's touched in a while.
Certificate duration tells us about automation. 90-day certs with ACME renewal mean modern DevOps. 200+ day manually managed certs mean something very different — and with the new 200-day maximum taking effect, these legacy holdouts are being forced to modernize.
Wildcard patterns expose architecture. A wildcard paired with specific CA and algorithm metadata tells us if a domain runs microservices, a CDN-fronted monolith, or a multi-tenant SaaS platform.
TLD-CA correlations predict stacks. Microsoft Azure CA on a .net domain? Over 85% confidence it's an ASP.NET backend. Let's Encrypt on a .io domain with certain HTTP headers? We can narrow the stack to a handful of candidates. Microsoft Azure now appearing on .io domains at scale? That's a signal of Azure's expanding reach into the startup ecosystem.
Most technology detection platforms check frontend signals: JavaScript libraries, HTML meta tags, cookies, and HTTP headers. Those are valid signals, and we use them too. But they miss the infrastructure layer entirely. You can't see from a page's HTML whether it's hosted on AWS or Azure. You can't tell from a JavaScript bundle whether the organization uses automated certificate management. Backend services like n8n — workflow automation tools that never expose a single line of client-side code — are completely invisible to frontend-only scanners. Our CT log pipeline, combined with DNS and header analysis, detects these backend technologies across thousands of domains. Certificate transparency data gives us that infrastructure visibility, and it's a major reason our technology detection covers 40,000+ technologies while competitors top out at a fraction of that depth.
I've led the engineering effort on this SSL certificate transparency data pipeline since we started building it over two years ago. Drawing on my experience designing crawling infrastructure at Google Search, we architected a distributed stream processing system that handles nearly 2.9 billion records per month. The engineering cost is significant, but the detection accuracy gains are worth it. This is original data and analysis that can't be replicated by scraping homepages.
How does HTTPS adoption affect SEO rankings?

HTTPS has been a confirmed Google ranking signal since 2014. But the relationship between certificates and search rankings is more specific than most guides acknowledge.
HTTPS is a baseline, not a differentiator. According to SSL Dragon, 88% of websites now use SSL/TLS certificates. With that level of adoption, having HTTPS doesn't give you a competitive edge. Not having it penalizes you. The Google Content Warehouse API leak revealed hasSecureUrl as a binary attribute. There's no gradient. It's simply present or absent.
Expired certificates actively hurt rankings. When a certificate expires, browsers display interstitial warnings. Visitors bounce. Those bounces register as badClicks in Google's NavBoost system, which directly demotes pages. An expired certificate doesn't just lose your HTTPS signal. It creates negative engagement signals that compound over time.
Mixed content degrades rankings. A page served over HTTPS that loads images, scripts, or stylesheets over HTTP triggers mixed content warnings. Modern browsers block some mixed content entirely, which can break page functionality and increase Core Web Vitals errors. Google's crawlers check for this.
CA choice doesn't affect rankings. A Let's Encrypt DV certificate and a DigiCert EV certificate have identical ranking value. Google doesn't differentiate between CAs or validation levels for search purposes.
TLS configuration affects Core Web Vitals indirectly. ECDSA certificates with TLS 1.3 produce faster handshakes than RSA with TLS 1.2. The difference is 100-300 milliseconds. For sites near the 2.5-second LCP threshold, that can mean passing or failing Core Web Vitals. We track this in our analytics detection pipeline because sites optimizing for performance tend to adopt modern TLS configurations alongside their frontend optimizations. With ECDSA adoption at 42.9% and accelerating, more sites are benefiting from these performance gains.
For B2B sales teams using technographic data, certificate configuration is a qualifying signal. An organization running ECDSA with automated renewal is more likely to be a mature technology buyer with real budget for developer tools.
Will SSL/TLS certificates last 47 days max by 2029?
Yes. The CA/Browser Forum has approved a phased reduction in maximum certificate lifetimes. According to SSL.com, certificates already dropped to a 200-day maximum as of March 11, 2026. The timeline moves to 100 days by 2027 and 47 days by 2029.
This will force every organization to adopt automated renewal. Manual certificate management can't handle 47-day rotations at scale. The 86.6% of certificates already at 90-day lifetimes won't feel much impact since they're already automated. The 12.2% at 100+ days will need to modernize. Our Q1 data already shows this transition in progress: the 100-200 day bracket doubled from 4.1% (Q4 2025) to 8.2% (Q1 2026) as CAs shift issuance away from 200+ day certificates.
For us, shorter lifetimes mean better data. A domain rotating certificates every 47 days gives us 8 data points per year instead of 1 (for annual certs). More data points mean we can detect technology stack changes, hosting migrations, and infrastructure upgrades faster.
What are certificate transparency logs?
Certificate transparency logs are append-only, cryptographically verifiable records of every SSL/TLS certificate issued by participating Certificate Authorities. Defined by RFC 6962, CT logs were designed to make certificate issuance auditable. If a CA issues a fraudulent or unauthorized certificate for your domain, CT logs provide a public record that monitoring tools can detect.
According to Secybers, there are over 40 active CT logs maintained by organizations including Google, Cloudflare, DigiCert, and others as of 2026. Major logs include Google's Argon, Xenon, and Icarus shards, Cloudflare's Nimbus, and DigiCert's Yeti and Nessie logs.
We ingest data from most of these logs. Processing nearly 2.9 billion records per month requires distributed stream processing, and we've built custom ingestion pipelines that parse certificate metadata in real time: CA information, algorithm details, domain names, validity periods. All of it gets cross-referenced with our DNS resolution, HTTP header analysis, and JavaScript fingerprinting systems.
What tools are available for certificate transparency monitoring?
Several tools provide certificate transparency search and monitoring capabilities, though at very different scales:
- Cloudflare Radar Certificate Transparency provides aggregate statistics and search across CT logs. It's the data source for much of the analysis in this report.
- crt.sh offers free certificate transparency search by domain, operated by Sectigo. Good for individual domain lookups.
- SSLMate Cert Spotter provides monitoring and alerting for certificate changes on domains you own.
- Google Certificate Transparency maintains the specification and operates several CT log shards.
These tools serve different purposes. For individual domain monitoring, crt.sh and Cert Spotter work well. For aggregate analysis at our scale (80% of global CT log data, 64.3 million domains tracked from those logs), there's nothing off-the-shelf. We built our pipeline from scratch.
According to CSC Global research, 60% of businesses use three or more SSL providers, and 72% of respondents didn't know the details of upcoming certificate lifetime changes. That gap between complexity and awareness is exactly where monitoring tools and technology intelligence platforms provide value.
Methodology
The data in this report comes from Cloudflare Radar Certificate Transparency monitoring, accessed on April 2, 2026. The primary analysis period covers Q1 2026 (January 1 through March 31, 2026), with quarter-over-quarter comparisons against Q4 2025 (October 1 through December 31, 2025).
June 2026 refresh. On June 1, 2026 we re-pulled every Cloudflare Radar Certificate Transparency dimension for the full calendar month of May 2026 (May 1–31), plus per-calendar-month pulls of the public-key-algorithm split for January through April to build the month-by-month crossover series. These are clean single-month windows, which is why the May figures differ slightly from the rolling ~28-day window we published in the May 2 (April) update — most visibly in the 47–100 day duration bucket, where the rolling window read 89.4% and the clean month reads 86.42%. We report both rather than silently restate. Two dimensions were added in this refresh that the original report did not track: log_api (the split between classic RFC 6962 logs and the newer static/tiled-log API) and has_ips (certificates issued for bare IP addresses). The same minor CT pipeline annotation around January 5–6, 2026 reappears on the clean January pull and does not materially affect the monthly algorithm shares. All May figures are share-normalized (PERCENTAGE) except total volume, which is a raw certificate count.
July 2026 refresh (Q2 close plus year-over-year). On July 2, 2026 we re-pulled every Cloudflare Radar Certificate Transparency dimension for the full second quarter (April 1 to June 30, 2026), for Q1 2026 (January 1 to March 31), and for the same quarter one year earlier (April 1 to June 30, 2025) to build the report's first year-over-year layer. These quarterly pulls return raw certificate counts (normalization: RAW_VALUES), so every share in the Q2-close section is computed against that window's own total rather than read off a pre-normalized figure. Two consequences of the aggregation window are worth naming: (1) a re-pull of the Q1 2026 window now totals ~11.4B certificates versus the 10.94B we reported on April 2, the difference being late-arriving CT entries backfilled since, so the Q2-close section compares like-for-like quarterly pulls and leads with the year-over-year delta rather than restating a QoQ volume that would argue with the published Q1 figure; (2) the log_api and has_ips dimensions both return data for the 2025 window, so their year-over-year comparisons are real rather than inferred.
Cloudflare Radar monitors major CT logs including Google's Argon, Xenon, and Icarus shards, Cloudflare's Nimbus logs, and DigiCert's Yeti and Nessie logs. TLD-specific data was queried separately through the same interface. A minor data pipeline interruption was noted on January 5-6, 2026 but does not materially affect quarterly totals.
TechnologyChecker.io's CT data processing ingests about 80% of global CT log data (roughly 8.7 billion certificate records in Q1 2026, or nearly 2.9 billion per month). Our CT pipeline has surfaced and mapped 64.3 million unique domains into technology detection; we cross-reference those certificate signals with DNS records, HTTP headers, JavaScript fingerprints, and HTML patterns across the 29.9 million active domains we crawl each month to detect 40,000+ technologies. All proprietary detection data in this report comes from our internal systems. Market share and volume figures come from Cloudflare Radar.
Certificate Authority market valuations are sourced from Mordor Intelligence (January 2026 report). SSL certificate adoption statistics are from SSL Dragon, sourcing data from January 2026. Enterprise SSL usage statistics are from CSC Global's published research.


