WebPKI Observatory
Quantitative analysis of the Certificate Authority ecosystem that underpins TLS on the public internet. Data updated daily from Certificate Transparency logs, CCADB, Mozilla Bugzilla, and CA/Browser Forum records. Last updated 2026-09-16.
CA Market Share
Five certificate authorities control 91% of all publicly trusted issuance, with Let's Encrypt (ISRG) leading at 37.1% and Google Trust Services at 21.1%. The market HHI of 2254 indicates moderate concentration, with 75 CAs in the long tail serving the remaining 8.5% of the ecosystem. DigiCert, GoDaddy, and Sectigo round out the top five, collectively representing the operational backbone of the public web's cryptographic identity layer.
- Internet Security Research Group: 37.1% of unexpired certificates
- Google Trust Services LLC: 21.1% of unexpired certificates
- DigiCert: 16.3% of unexpired certificates
- GoDaddy: 9.7% of unexpired certificates
- Sectigo: 7.3% of unexpired certificates
The top 3 CAs account for 74.5% of all certificate issuance. The top 5 account for 91.5%. HHI concentration index: 2,254 (above 2,500 is considered highly concentrated). 89 Certificate Authorities are currently trusted by at least one major root program.
CA Compliance Incidents
1,572 compliance incidents have been recorded across 54 certificate authorities, led by misissuance (611 incidents), governance failures (505), and revocation problems (332). CAs self-detect only 26% of their own incidents, while external researchers, automated tools, and root programs collectively account for most discovery, indicating systemic surveillance and control gaps. Policy failures (195) and disclosure failures (139) outnumber audit findings (108), suggesting that third-party audits examined in the audit intelligence analysis miss or do not surface the operational lapses that ultimately appear in public incident reports.
1,572 compliance incidents across 54 Certificate Authorities have been publicly documented in Mozilla Bugzilla since 2014.
- Misissuance: 611 incidents (39%)
- Governance: 505 incidents (32%)
- Revocation: 332 incidents (21%)
- Validation: 124 incidents (8%)
Of these incidents: 195 involved CAs violating their own documented policies, 139 involved failure to disclose issues on time, and 108 were discovered by auditors rather than by the CA itself.
Who discovers CA compliance incidents: root programs find 4%, automated tools (CT log monitors, linters) find 17%, and CAs' own monitoring accounts for only 26%.
CA Distrust Events
16 distrust events have occurred across browser and operating system programs, with 14 attributed to compliance or operational failures rather than cryptographic compromise. Seven CAs exhibited negligent noncompliance posture, three demonstrated willful circumvention, and three showed demonstrated incompetence, revealing the behavioral patterns that lead root programs to remove trust. The median runway from distrust announcement to effective removal is 1,185 days, providing extended notice periods that balance ecosystem stability against the urgency of removing problematic actors identified through the 1,572 incidents in the operational risk data.
16 Certificate Authorities have been removed from browser trust stores since 2011. 14 of these events involved compliance operations failures — inadequate incident response, concealment, or patterns of unresolved issues. 10 had documented recurring patterns of issues across multiple years.
Root Program Governance
Chrome participated in 18.4% of the 223 incident discussions in 2025, down from 67.8% in 2019, while Mozilla declined from 78.0% to 9.9% and Apple contributed to just 5.4% of cases. Microsoft provided zero oversight participation in 2025 despite operating a trust store, leaving the majority of the 1,572 recorded incidents without formal root program engagement in their public disclosure threads. The declining coverage rate means CAs increasingly self-manage incident response without the forcing function of root program scrutiny, directly correlating with the operational finding that only 26% of incidents are self-detected.
Root program oversight coverage as a percentage of all CA compliance bugs: Chrome covered 67.8% in 2019 and 18.4% in 2025. Mozilla covered 78.0% in 2019 and 9.9% in 2025. Microsoft has made 0 governance comments on other CAs' compliance incidents across 1,858 total bugs.
CA/B Forum Ecosystem Participation
56 organizations hold CA/B Forum membership but only 21 contribute actively to ballot or discussion processes, leaving 35 members with zero recorded participation in policy development. Stephen Davidson of Sectigo leads individual ballot activity with 36 proposals, while Sectigo as an organization tops contribution metrics despite ranking fifth in market share at 7.3%. The participation gap means governance decisions affecting the entire 6,657-obligation compliance surface are shaped by a small subset of stakeholders, many operating in the long tail rather than the concentrated top five that serve 91% of issuance volume.
Of 56 CA/Browser Forum CA members, 21 have recorded community contributions and 35 have made no recorded public contribution to Bugzilla, ballot proposals, or bug filing.
Most active organizations: Sectigo, DigiCert, HARICA, Let's Encrypt, iSigma.
Geographic Distribution
United States-incorporated CAs issue 92.3% of all publicly trusted certificates, despite 44 European CAs and 17 Asia-Pacific authorities holding trust store positions. Europe accounts for just 7.6% of issuance volume and Asia-Pacific rounds to 0.09%, revealing a profound geographic concentration that mirrors but intensifies the market share findings. The dominance of US-based issuers creates jurisdictional exposure analyzed separately in the legal risk framework, but the incorporation pattern itself reflects where technical capability, capital, and audit infrastructure have historically concentrated.
- United States: 15 CAs, 92.3% of certificate issuance
- Europe: 44 CAs, 7.6% of certificate issuance
- Asia-Pacific: 17 CAs, 0.1% of certificate issuance
- Americas: 3 CAs, 0.0% of certificate issuance
- Middle East / Africa: 6 CAs, 0.0% of certificate issuance
Government-Operated Certificate Authorities
30 government-operated or state-owned certificate authorities hold trusted roots across the four major programs, though they collectively represent only 0.08% of observed issuance volume. These CAs span national PKI programs, military certificate services, and sovereign identity initiatives, maintaining trusted status primarily for domestic or specialized use cases rather than public web issuance. The presence of state-controlled CAs in global trust stores creates ongoing policy tension between technical interoperability requirements and geopolitical trust boundaries, particularly for governments identified in the high-risk jurisdiction framework.
30 government-operated or state-owned Certificate Authorities hold trust in major browser root stores, accounting for 0.1% of certificate issuance.
Machine-readable dataset (JSON, ~68K tokens, updated daily)