Let's Encrypt has issued 380M+ free TLS certificates on 129M unique domains in three years since launch, making it the largest certificate issuer in the world
Bon anniversaire, Let's Encrypt! — The free-to-use nonprofit was founded in 2014 in part by the Electronic Frontier Foundation …
Context & Ripple Effects
Three years after the EFF-Mozilla-Cisco project issued its first free HTTPS certificate in September 2015, Let's Encrypt has become the world's largest certificate authority on volume. The inflection points were structural rather than incremental: all major browsers trusting its root within weeks of launch (October 2015), and the March 2018 release of free wildcard certificates plus ACME v2 automation, which removed the last per-subdomain friction for operators.
The trajectory is steep and compounding — from 1M certificates in its first three months to 380M+ across 129M unique domains today — which is why this anniversary matters beyond a nonprofit's birthday: it marks the moment encryption stopped being a product you buy and became infrastructure you assume.
First-order effects
- Commercial certificate authorities lose the low-end web outright: with 129M unique domains now covered free, the price of a basic TLS certificate has collapsed toward zero, pushing paid CAs upmarket into validation-heavy enterprise offerings.
- Hosting platforms and CDNs can default every customer site to HTTPS at no marginal cost, since ACME v2 automates issuance and renewal without manual verification.
Second-order effects
- Certificate resellers and bundled-SSL hosting upsells become stranded revenue streams, forcing registrars and hosts to compete on other services while shipping encryption for free.
- Browser vendors gain leverage over the entire CA ecosystem: with one dominant free issuer setting automation norms via ACME, compliance with browser policy effectively means compliance with Let's Encrypt's operating model.
Third-order effects
- If issuance keeps scaling at this rate, plaintext HTTP becomes a legacy exception rather than a default, and the web's security baseline shifts from 'encrypted if you pay' to 'encrypted unless you opt out' — with regulators and browsers treating unencrypted traffic as a defect.
- The certificate market restructures around what money still buys: extended validation, warranties, and managed PKI for enterprises, while commodity domain-validation becomes a public good sustained by nonprofit funding.
The trend: Web encryption is completing its shift from a paid commercial product to free automated infrastructure, with a single nonprofit issuer setting the de facto standard for how the rest of the CA industry must operate.