WebPKI Observatory
Quantitative analysis of the Certificate Authority ecosystem that underpins TLS on the public internet. Data updated daily from Certificate Transparency logs, CCADB, Mozilla Bugzilla, and CA/Browser Forum records. Last updated 2026-07-18.
CA Market Share
The WebPKI market shows moderate concentration with five CAs controlling 92% of issuance. Internet Security Research Group leads at 40%, followed by Google Trust Services at 19% and DigiCert at 14%. The HHI of 2347 indicates a moderately concentrated market, while 75 CAs operate in the long tail with minimal issuance share. Despite consolidation at the top, 89 trusted CAs remain active in trust stores.
- Internet Security Research Group: 39.8% of unexpired certificates
- Google Trust Services LLC: 18.9% of unexpired certificates
- DigiCert: 13.7% of unexpired certificates
- GoDaddy: 10.2% of unexpired certificates
- Sectigo: 9.6% of unexpired certificates
The top 3 CAs account for 72.4% of all certificate issuance. The top 5 account for 92.2%. HHI concentration index: 2,347 (above 2,500 is considered highly concentrated). 89 Certificate Authorities are currently trusted by at least one major root program.
CA Compliance Incidents
1,511 incidents have been recorded across 54 CAs, with misissuance accounting for 588 events and governance failures for 476. Only 24% of incidents are discovered through CA self-detection, while 19% come from external researchers and 17% from automated tools. Root programs themselves identify just 4% of issues despite their governance authority. Policy failures appear in 175 incidents, disclosure failures in 132, and audit findings in 107, revealing that required controls frequently fail to prevent or detect problems before they reach production systems.
1,511 compliance incidents across 54 Certificate Authorities have been publicly documented in Mozilla Bugzilla since 2014.
- Misissuance: 588 incidents (39%)
- Governance: 476 incidents (32%)
- Revocation: 325 incidents (22%)
- Validation: 122 incidents (8%)
Of these incidents: 175 involved CAs violating their own documented policies, 132 involved failure to disclose issues on time, and 107 were discovered by auditors rather than by the CA itself.
Who discovers CA compliance incidents: root programs find 4%, automated tools (CT log monitors, linters) find 17%, and CAs' own monitoring accounts for only 24%.
CA Distrust Events
16 distrust events have occurred across the ecosystem, with 14 attributed to compliance or operational failures rather than malicious intent. Negligent noncompliance accounts for seven posture classifications, demonstrated incompetence for three, and willful circumvention for three. The median runway between distrust announcement and effective date is 1,185 days, though this extended timeline reflects browser programs balancing ecosystem disruption against security requirements. Pattern-of-issues findings appear in 10 distrust cases, indicating that single incidents rarely trigger removal but accumulated failures eventually exhaust root program patience.
16 Certificate Authorities have been removed from browser trust stores since 2011. 14 of these events involved compliance operations failures — inadequate incident response, concealment, or patterns of unresolved issues. 10 had documented recurring patterns of issues across multiple years.
Root Program Governance
Root program oversight coverage has collapsed from 68-78% in 2019 to just 18% for Chrome and 10% for Mozilla in 2025. Chrome commented substantively on 109 of 223 incident bugs in recent periods, while Mozilla engaged on 47 and Apple on 6. Microsoft provided zero substantive oversight comments despite maintaining the largest trust store with 142 exclusive roots. This governance gap means the majority of incidents now proceed without root program input, leaving CAs to self-interpret requirements. The declining oversight rate coincides with the surge in compliance obligations documented in BR readiness, creating a feedback loop where expanding requirements receive diminishing authoritative guidance.
Root program oversight coverage as a percentage of all CA compliance bugs: Chrome covered 67.8% in 2019 and 18.4% in 2025. Mozilla covered 78.0% in 2019 and 9.9% in 2025. Microsoft has made 0 governance comments on other CAs' compliance incidents across 1,787 total bugs.
CA/B Forum Ecosystem Participation
56 organizations hold CA/Browser Forum membership but only 21 contribute actively to standards development. 35 members maintain zero contribution records, effectively operating as observers rather than participants. Stephen Davidson leads ballot activity with 36 proposals, while Sectigo ranks as the most active organizational contributor. This participation gap means a small minority of CAs define requirements that bind the entire ecosystem, including the silent majority who implement but do not shape policy. The concentration of ballot leadership among high-volume CAs may explain why BR readiness obligations have grown 121-fold while streamlining efforts stall at zero ballots since 2022.
Of 56 CA/Browser Forum CA members, 21 have recorded community contributions and 35 have made no recorded public contribution to Bugzilla, ballot proposals, or bug filing.
Most active organizations: Sectigo, DigiCert, HARICA, Let's Encrypt, iSigma.
Geographic Distribution
US-based CAs issue 90% of all trusted certificates despite representing only 15 of 89 active CAs. European CAs account for 44 of the 89 trusted issuers but control just 10% of issuance, while Asia-Pacific's 17 CAs produce only 0.07% of certificates. This geographic concentration means a single regulatory or legal event in the United States could affect nine in ten HTTPS connections worldwide. The disparity between CA count and issuance share highlights how trust store presence does not translate to market success, particularly outside North America.
- United States: 15 CAs, 90.0% of certificate issuance
- Europe: 44 CAs, 9.9% of certificate issuance
- Asia-Pacific: 17 CAs, 0.1% of certificate issuance
- Americas: 3 CAs, 0.0% of certificate issuance
- Middle East / Africa: 6 CAs, 0.0% of certificate issuance
Government-Operated Certificate Authorities
30 government-operated or state-owned CAs hold positions in major trust stores but collectively issue only 0.06% of public certificates. These entities appear primarily in Microsoft's trust store, which maintains the broadest and least selective inclusion policy. State-controlled CAs present unique risks as they operate under legal frameworks that may prioritize national security or surveillance over browser security requirements. Despite minimal issuance share, their trust store presence grants them the technical capability to issue for any domain, making them a persistent counter-party risk in the WebPKI.
30 government-operated or state-owned Certificate Authorities hold trust in major browser root stores, accounting for 0.1% of certificate issuance.
Machine-readable dataset (JSON, ~68K tokens, updated daily)