HTTPS Adoption and TLS Deployment Report 2026
· CSR.plus Team

- •The default-protocol HTTPS share now exceeds 95% of pages measured across the top of the web, with HSTS following close behind.
- •TLS 1.3 has become the dominant protocol version, while TLS 1.0 and 1.1 have dropped to effectively zero in public usage.
- •The remaining HTTPS gap concentrates in low-traffic and legacy segments; adoption follows traffic, not domain counts.
Methodology and headline numbers
This report aggregates publicly measurable signals — default-protocol statistics from usage-measurement trackers, TLS-version distribution from CDN telemetry, and HSTS preload list membership. Together they show a web that has crossed the HTTPS tipping point: the majority of user traffic is encrypted end-to-end, and plain-HTTP fallbacks have become a compatibility choice rather than the default.
TLS version migration status
TLS 1.3 is now the most negotiated version on major CDNs, driven by default-on 1.3 in browsers and servers. TLS 1.2 remains the compatibility floor and is still required for older enterprise clients. TLS 1.0/1.1 have been disabled in every major browser and OS since 2020-2021; public traffic using them is effectively zero, and the remaining deployments exist only on legacy embedded systems.
What the gaps mean
The small HTTPS gap is heavily skewed: low-traffic hobby sites, legacy government and education portals, and some embedded devices. HSTS adoption is strong among large sites but patchy for smaller domains, and preload-list membership remains the most reliable hardening signal. For site owners the practical takeaway is unchanged: serve HTTPS-only, enable HSTS, and migrate any remaining plain-HTTP endpoints behind the TLS edge.
FAQ
Is HTTPS adoption measured by domains or traffic?
Most published statistics weight by traffic or page views, which overstates adoption among large sites. By raw domain count the HTTPS share is lower but still a clear majority.
Do I still need to support TLS 1.2?
Yes — TLS 1.3-only servers break some enterprise and embedded clients. Enable both 1.2 and 1.3, disable everything older.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.