WebPKI Observatory
Quantitative analysis of the Certificate Authority ecosystem that underpins TLS on the public internet. Data updated daily from Certificate Transparency logs, CCADB, Mozilla Bugzilla, and CA/Browser Forum records. Last updated 2026-08-02.
CA Market Share
Five CAs control 91.8% of all trusted certificate issuance, led by Internet Security Research Group at 39.2% and Google Trust Services at 19.9%. The top three CAs hold 72.93% market share, producing an HHI of 2325 that signals moderate concentration. Despite 89 trusted CAs operating globally, 75 sit in the long tail with minimal issuance volume but full trust store inclusion.
- Internet Security Research Group: 39.2% of unexpired certificates
- Google Trust Services LLC: 19.9% of unexpired certificates
- DigiCert: 13.9% of unexpired certificates
- GoDaddy: 9.7% of unexpired certificates
- Sectigo: 9.1% of unexpired certificates
The top 3 CAs account for 72.9% of all certificate issuance. The top 5 account for 91.8%. HHI concentration index: 2,325 (above 2,500 is considered highly concentrated). 89 Certificate Authorities are currently trusted by at least one major root program.
CA Compliance Incidents
CAs have reported 1,531 incidents across 54 organizations, with misissuance representing 596 cases and governance failures accounting for 488. Only 25% of incidents emerged through CA self-detection, while external researchers discovered 19% and automated tools found 17%, revealing gaps in internal controls. Policy failures affected 183 incidents and disclosure failures 136, with just 107 audit findings despite mandatory annual examinations, foreshadowing the audit intelligence finding that oversight mechanisms miss operational realities.
1,531 compliance incidents across 54 Certificate Authorities have been publicly documented in Mozilla Bugzilla since 2014.
- Misissuance: 596 incidents (39%)
- Governance: 488 incidents (32%)
- Revocation: 325 incidents (21%)
- Validation: 122 incidents (8%)
Of these incidents: 183 involved CAs violating their own documented policies, 136 involved failure to disclose issues on time, and 107 were discovered by auditors rather than by the CA itself.
Who discovers CA compliance incidents: root programs find 4%, automated tools (CT log monitors, linters) find 17%, and CAs' own monitoring accounts for only 25%.
CA Distrust Events
Browsers have issued 16 distrust actions against CAs, with 14 stemming from compliance operations failures and 10 following patterns of repeated issues rather than isolated incidents. Negligent noncompliance characterizes 7 cases, willful circumvention 3, and demonstrated incompetence 3, while CAs receive a median 1,185-day runway between distrust announcement and root removal. These posture classifications show most distrusted CAs failed operational discipline rather than deliberately subverting rules, connecting to the governance tab's finding that oversight coverage has declined even as incidents accumulate.
16 Certificate Authorities have been removed from browser trust stores since 2011. 14 of these events involved compliance operations failures — inadequate incident response, concealment, or patterns of unresolved issues. 10 had documented recurring patterns of issues across multiple years.
Root Program Governance
Chrome participated substantively in only 18.4% of 2025's 223 reported CA incidents, down from 67.8% coverage in 2019, while Mozilla dropped from 78.0% to 9.9% and Apple engaged in 5.4% despite growing to 16.4% browser share. Microsoft provided zero substantive oversight across all 1,812 bugs in the corpus despite maintaining 142 roots not trusted by other programs. This declining engagement leaves most incidents unreviewed by root programs even as their trust decisions affect billions of users, connecting to the operational risk finding that only 25% of incidents emerge through CA self-detection.
Root program oversight coverage as a percentage of all CA compliance bugs: Chrome covered 67.8% in 2019 and 18.4% in 2025. Mozilla covered 78.0% in 2019 and 9.9% in 2025. Microsoft has made 0 governance comments on other CAs' compliance incidents across 1,812 total bugs.
CA/B Forum Ecosystem Participation
56 organizations hold CA/B Forum membership but only 21 contribute actively, leaving 35 with zero ballot or discussion participation while still benefiting from industry standards. Stephen Davidson of Sectigo leads individual engagement with 36 proposed ballots, while Sectigo as an organization dominates overall contribution metrics. This silent majority pattern concentrates policy development among a handful of active CAs while decisions bind all 89 trusted entities, amplifying the governance gap where oversight coverage continues declining.
Of 56 CA/Browser Forum CA members, 21 have recorded community contributions and 35 have made no recorded public contribution to Bugzilla, ballot proposals, or bug filing.
Most active organizations: Sectigo, DigiCert, HARICA, Let's Encrypt, iSigma.
Geographic Distribution
US-incorporated CAs issue 90.46% of trusted certificates despite representing only 15 of 89 trusted entities, while 44 European CAs collectively hold just 9.46% issuance share. Asia-Pacific's 17 CAs contribute 0.08% of volume, revealing geographic concentration that mirrors market share dynamics. This incorporation-based distribution differs from legal jurisdiction risk, which considers where CAs operate infrastructure and face compelled disclosure regimes regardless of formal headquarters location.
- United States: 15 CAs, 90.5% of certificate issuance
- Europe: 44 CAs, 9.5% of certificate issuance
- Asia-Pacific: 17 CAs, 0.1% of certificate issuance
- Americas: 3 CAs, 0.0% of certificate issuance
- Middle East / Africa: 6 CAs, 0.0% of certificate issuance
Government-Operated Certificate Authorities
30 government-operated or state-owned CAs hold trust store inclusion but account for only 0.07% of issuance, operating primarily for domestic infrastructure rather than public web traffic. These entities face heightened scrutiny over their trust store presence given state access to private keys and potential compelled misuse scenarios. Their minimal issuance share suggests browsers have largely contained exposure while maintaining diplomatic inclusion of sovereign operators.
30 government-operated or state-owned Certificate Authorities hold trust in major browser root stores, accounting for 0.1% of certificate issuance.
Machine-readable dataset (JSON, ~68K tokens, updated daily)