← Back to Articles
Report2026-08-15•6 min read

Let's Encrypt Market Share and E5/E6 Transition Report 2026

· CSR.plus Team

Let's Encrypt Market Share and E5/E6 Transition Report 2026
  • •Let’s Encrypt remains the largest public CA by volume, with hundreds of millions of active certificates and the clear majority of new issuance.
  • •The E5/E6 root transition is the defining chain story of 2025-2026: new chains cross-signed by ISRG Root X1, with legacy cross-signed chains on a defined retirement path.
  • •Operators should verify chain trust both on modern clients and on the legacy cross-signed path, especially for embedded devices.
300M+
Active certs
issued by Let’s Encrypt
Majority
New issuance share
of all new DV certs
Both paths
Root X1 cross-sign
E5/E6 + legacy chains
90 days
Renewal cadence
automated by default

Market position

Let’s Encrypt accounts for the large majority of new domain-validated certificates issued each month and operates one of the largest active certificate inventories in the world. Its 90-day lifetime and free ACME issuance have pushed commercial DV prices toward the floor, reshaping the reseller market that this site’s price comparison tracks.

The E5/E6 chain transition

The newer E5/E6 intermediates are cross-signed by ISRG Root X1, and the classic cross-signed chains remain available to support older clients during the transition. The transition changes which chain your client receives depending on the ACME configuration and CDN settings, so certificate chain inspection is now part of standard certificate hygiene.

What operators must check

Verify your served chain on both the modern and legacy paths — use this site’s chain-compatibility tool or openssl verify against both roots. Confirm that your ACME client is not pinning a retired chain, and that CDN edge configurations serve the intended intermediate. Old devices that only trust the legacy cross-signed root are the main group that still depends on the legacy chain.

FAQ

Is the legacy chain being retired?

The older cross-signed chains are on a defined retirement schedule. Site operators who must support old clients should track the announced dates and test the legacy path before it disappears.

Do I need to change anything?

For most automated deployments, no. If you pin certificate chains, serve certificates through a CDN, or support old devices, verify both chain paths.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles