WebPKI Observatory — Jurisdiction Risk
Five jurisdictions carry high legal risk for compelled certificate misuse through national security frameworks, signals intelligence mandates, or weak rule-of-law protections: China, Russia, the United Kingdom, Australia, and Hong Kong. India and Turkey occupy a moderate-risk tier with expanding surveillance regimes and periodic government interference in technical operations. These classifications examine legal authorities that could compel CAs to issue unauthorized certificates or disclose private keys, distinct from the geographic incorporation patterns that show US dominance in the market tab.