If you have ever wondered who actually issues the certificates behind the padlock in Chrome, you are asking about certificate authorities (CAs) — the organizations browsers and operating systems trust to vouch for domains. This guide maps the major CAs worldwide, how market share is usually measured, and what that means if you are choosing SSL/TLS for a small business site.
How CA market share is usually measured
Public “market share” charts rarely mean the same thing. Researchers typically count valid certificates observed across large certificate transparency (CT) logs, or certificates seen on popular websites (Tranco/Alexa-style lists), sometimes filtered to DV-only or excluding free short-lived certs. Numbers move weekly. Treat any percentage as directional, not a purchase decision by itself.
- CT-log volume — favors high-volume free CAs (especially Let's Encrypt) because every issuance is logged.
- Top-site share — can look different because enterprises still buy DigiCert, Sectigo, GlobalSign, and others for OV/EV and fleets.
- Reseller channels — GoDaddy Group and hosting brands often sell another CA’s certificates under their own storefront.
The big players you will see in 2026
Let's Encrypt (ISRG)
The nonprofit Internet Security Research Group runs Let's Encrypt — the dominant issuer by raw certificate count for years. It issues free domain-validated (DV) certificates, typically short-lived (commonly 90 days, with shorter options evolving). docstoc’s automated SSL/TLS feature issues real Let's Encrypt certificates.
DigiCert Group
DigiCert is the enterprise heavyweight: OV/EV, warranties, and broader PKI (devices, code signing, S/MIME). It shows strongly on large corporate and regulated sites even when Let's Encrypt leads CT volume.
Sectigo (formerly Comodo CA)
A major commercial CA sold heavily through resellers — DV through EV, wildcards, and multi-domain products. Common when a host or IT reseller bundles “SSL” as a paid SKU.
GlobalSign, Entrust, and other commercial CAs
GlobalSign leans enterprise/PKI and IoT. Entrust and similar vendors appear in government and large-org PKI. Share varies by region and vertical more than by blog-chart rank.
Google Trust Services, Amazon, Microsoft
Cloud providers operate CAs used heavily inside their own clouds and for customer workloads. You may never “buy Google SSL” as a freestanding product, yet their trust roots matter at internet scale.
Regional and specialist CAs
Examples include Actalis (often via European host/reseller channels), Certum, Secom Trust (Japan-oriented commercial trust), and national/government CAs. They can dominate locally without topping global CT charts.
Free / ACME-oriented brands
ZeroSSL, SSL.com’s free ACME tier, and host-integrated free SSL (for example Hostinger or Cloudflare Universal SSL) compete on convenience more than on “who owns the root.” Always ask which CA actually signs the leaf certificate.
What market share means for a small business
For a freelancer or SMB marketing site, the browser padlock from a DV Let's Encrypt certificate is the same class of trust users see on millions of other sites. You do not need DigiCert-level share to be “secure enough” for HTTPS. You do need reliable issuance and renewal — which is why automation beats brand prestige for most small teams.
Choose a commercial CA when you have a real requirement for OV/EV, a contractual warranty, code signing, or an enterprise PKI program — not because a pie chart said they are #2.
Practical next steps
- Compare automation vs dashboards: docstoc vs Let's Encrypt DIY, vs ZeroSSL, vs DigiCert.
- If you are leaving a paid CA or free-SSL site, use a switch-from guide from the SSL hub.
- Check expiry math with the SSL expiry calculator.
FAQ
Is Let's Encrypt “less trusted” because it is free?
No. Browsers trust Let's Encrypt’s roots like other public CAs for DV HTTPS. Free means automated domain validation at scale, not a weaker padlock for normal websites.
Why do enterprise sites still buy DigiCert or Sectigo?
OV/EV policies, warranties, procurement lists, wildcards at scale, and broader PKI — not because DV Let's Encrypt fails to encrypt traffic.
Does docstoc run its own CA?
No. docstoc automates issuance of real Let's Encrypt DV certificates for your domain inside the same workspace as invoices and documents.