Let’s Encrypt
Let's Encrypt is a nonprofit Certificate Authority that provides free, automated TLS certificates to more than 700 million websites worldwide through the ACME protocol API, funded entirely by corporate sponsorships and donations.
- Company typePrivate
- Founded2015
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
Let’s Encrypt firmographics
Firmographics- Name
- Let’s Encrypt
- Legal name
- Internet Security Research Group (ISRG)
- Website
- https://letsencrypt.org
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Let's Encrypt is a nonprofit Certificate Authority that provides free, automated TLS certificates to more than 700 million websites worldwide through the ACME protocol API, funded entirely by corporate sponsorships and donations.
- Ownership category
- akta.pro rank
Let’s Encrypt industry classification
Industry- Product category
- Certificate Authority Services
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Device Identity & Certificate-Based Authentication (PKI) (BPAMAEAL)
Keywords
Where Let’s Encrypt is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Let’s Encrypt business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations
Revenue model
- Free Certificate Issuance (Primary Service): Let's Encrypt provides free TLS/SSL certificates to all websites as a nonprofit public benefit service. There is no revenue generated from certificate issuance. The service is funded entirely through sponsorships, donations, and grants.
- Sponsorships and Donations: Revenue is generated through corporate sponsorships (Diamond, Platinum, Gold, Silver tiers) and individual donations. Major sponsors include Google Chrome, Amazon Web Services, Microsoft, Mozilla, EFF, Shopify, and many others.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free TLS Certificates - No pricing tiers |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Let’s Encrypt product offering
Product offeringCore offering
Let's Encrypt is a nonprofit Certificate Authority operated by the Internet Security Research Group (ISRG) that provides free, automated TLS/SSL certificates to websites worldwide through the ACME (Automated Certificate Management Environment) protocol. The service enables fully automated issuance, domain validation, renewal, and revocation of digital certificates at no cost, and has expanded beyond domain names to issue certificates for IP addresses and support both RSA and ECDSA cryptography.
Product overview
Let's Encrypt is a nonprofit Certificate Authority operated by the Internet Security Research Group (ISRG) that provides free, automated TLS certificates. The core offering is the ACME (Automated Certificate Management Environment) protocol API, which enables automated certificate issuance, renewal, and management. Let's Encrypt issues domain-validated TLS certificates (with standard 90-day validity) for traditional domain names and expanded in July 2025 to issue IP address certificates (with short 6-day validity). The service integrates with numerous ACME clients including Certbot (the recommended client), Lego, acme.sh, Caddy, Traefik, and cert-manager for Kubernetes. Certificate lifecycle management is facilitated through ACME Renewal Information (ARI), which provides optimal renewal timing and exempts coordinated renewals from rate limits. Let's Encrypt operates Certificate Transparency logs and maintains multiple root and intermediate CA hierarchies for issuing end-entity certificates.
Differentiator
Problem solved
Functional benefit
Products and services
- Certificate Transparency (CT) Logs Public Certificate Transparency logs that record all certificates issued by publicly trusted CAs, enabling detection of mis-issued certificates. Operated as infrastructure available to all CAs in the Web PKI ecosystem.
Quantifiable outcome
- Enabled HTTPS for over 700 million websites globally
- +2 more outcomes
Companies that use Let’s Encrypt
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
Let’s Encrypt technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration27 records
Feature6 records
Let’s Encrypt partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered recommended and core.
- Red SiftrecommendedLet's Encrypt endorsed Red Sift as its recommended certificate monitoring service for Let's Encrypt subscribers. Red Sift provides certificate monitoring, expiration alerts, and management tools that complement Let's Encrypt's free certificate issuance.
- Princeton UniversitycorePartnered with Let's Encrypt on ACME Renewal Information (ARI) development, with support from the Open Technology Fund.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Let’s Encrypt competitors and assessment
Company assessmentBroad incumbents
- DigiCert: DigiCert is the largest commercial certificate authority and TLS/SSL market leader. It competes directly with Let's Encrypt as a publicly trusted CA, though it focuses on paid OV/EV certificates and enterprise PKI where Let's Encrypt does not operate. Directly comparable for the certificate issuance business.
- Sectigo: Sectigo (formerly Comodo CA) is one of the world's largest commercial certificate authorities and a direct competitor in the TLS certificate market. It issues DV, OV, and EV certificates and runs both free and paid CA offerings, overlapping with Let's Encrypt's DV certificate business at the free tier.
- GlobalSign: GlobalSign is a longstanding commercial certificate authority and one of the top global CAs alongside Let's Encrypt. It offers a mix of public TLS and private enterprise PKI services, comparable to Let's Encrypt in the public trust CA category but with a focus on paid enterprise offerings.
- Entrust: Entrust is a top global commercial certificate authority offering TLS, S/MIME, and identity-based certificates. Comparable to Let's Encrypt as a publicly trusted CA, though it primarily serves enterprise and government customers with paid OV/EV certificates rather than free automated DV.
Direct peers
- IdenTrust: IdenTrust is a top commercial certificate authority - and an existing Gold-level sponsor of Let's Encrypt - with deep roots in the trusted CA ecosystem (historically cross-signed ISRG Root X1). Directly comparable as a publicly trusted CA serving regulated and enterprise customers.
- ZeroSSL: ZeroSSL offers free 90-day ACME-compatible SSL certificates alongside paid plans, directly competing with Let's Encrypt on free automated DV certificates via the same ACME protocol. It is the closest direct free-tier alternative to Let's Encrypt for individual website operators.
Emerging players
- Google Trust Services: Google Trust Services operates Google's own certificate authority (formerly Google Internet Authority G2) and issues certificates transparently for Google Cloud and other services. Comparable as a publicly trusted CA, though issuance is largely tied to Google products and not aimed at the general public the way Let's Encrypt is.
- AWS Certificate Manager: AWS Certificate Manager issues and manages free TLS certificates for AWS workloads (and charged for external use). It is a functionally analogous free-CA service but tightly coupled to AWS workloads, partly overlapping with the addressable market for Let's Encrypt's cloud/SaaS use cases.
Others
- Venafi (CyberArk): Venafi is a leading certificate lifecycle management (CLM) and machine identity management platform. It does not issue certificates itself but sits adjacent to Let's Encrypt by managing certificates (including Let's Encrypt-issued ones) across enterprise estates - a complementary service layer.
- Keyfactor: Keyfactor is a certificate and PKI lifecycle management platform serving enterprises. Like Venafi, it does not issue TLS certificates itself but competes in the certificate management space adjacent to Let's Encrypt, especially for organizations running private CAs and managing Let's Encrypt-issued public certificates at scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat7 records
Key risks7 records
Key highlights7 records
Customer concentration
Let’s Encrypt social profiles
Digital presenceLet’s Encrypt financial estimates
Financial estimateRevenue estimate
Valuation estimate
Let’s Encrypt leadership team
Management profileNumber of profiles
Profiles1 record
Let’s Encrypt funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Let’s Encrypt M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Let’s Encrypt
What does Let’s Encrypt do?
Let's Encrypt is a nonprofit Certificate Authority operated by the Internet Security Research Group (ISRG) that provides free, automated TLS/SSL certificates to websites worldwide through the ACME (Automated Certificate Management Environment) protocol. The service enables fully automated issuance, domain validation, renewal, and revocation of digital certificates at no cost, and has expanded beyond domain names to issue certificates for IP addresses and support both RSA and ECDSA cryptography.
Is Let’s Encrypt a public or private company?
Let’s Encrypt is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Let’s Encrypt founded?
Let’s Encrypt was founded in 2015. It employs 1 to 10 people.
Where is Let’s Encrypt based?
Let’s Encrypt is headquartered in San Francisco, United States, in the North America region.
How does Let’s Encrypt make money?
Two revenue lines are on record. Free Certificate Issuance (Primary Service) is the primary driver. The others are sponsorships and Donations.
Who are Let’s Encrypt's main competitors?
Broad incumbents on record are DigiCert, Sectigo, GlobalSign and Entrust. Direct peers are IdenTrust and ZeroSSL. Emerging players are Google Trust Services and AWS Certificate Manager. Others are Venafi (CyberArk) and Keyfactor.
Does Let’s Encrypt have an API?
Yes. Let's Encrypt provides the ACME (Automated Certificate Management Environment) protocol API for automated TLS certificate issuance and management. The ACME v2 API (RFC 8555) enables clients to automatically obtain, renew, and revoke SSL/TLS certificates. The production ACME directory endpoint and staging environment at https://acme-staging-v02.api.letsencrypt.org/directory are available. The API supports certificate issuance for domain names and IP addresses, with HTTP-01, DNS-01, and TLS-ALPN-01 challenge types. Developer documentation is at letsencrypt.org/docs.
What industry is Let’s Encrypt in?
Let’s Encrypt's product category is Certificate Authority Services. Its primary akta.pro industry code is BPAMAEAL, Device Identity & Certificate-Based Authentication (PKI). Its NAICS code is 5182 and its SIC code is 7370.