← Back to Articles
Data Report2026-08-14•7 min read

2026 SSL/TLS Adoption Report

· CSR.plus Team

2026 SSL/TLS Adoption Report
  • •80% of the top 1 million websites now support TLS 1.3 — up from 47% five years ago.
  • •Let's Encrypt issued roughly three out of every four new certificates in 2026.
  • •89% of new certificates are valid for 90 days or less; 99.6% of them are signed with SHA-256.
80%
TLS 1.3 adoption
of top sites support TLS 1.3
74%
Let's Encrypt share
of newly issued certificates
89%
Certs ≤ 90 days
of new certificates
99.6%
SHA-256 signatures
of scanned certificates

TLS 1.3 adoption among top sites, 2021–2026 (%)

TLS 1.3 adoption among top sites, 2021–2026 (%)022446688475865717680202120222023202420252026Share of the top 1M domains supporting TLS 1.3.

Share of the top 1M domains supporting TLS 1.3.

Newly issued certificate market share by CA, 2026

Newly issued certificate market share by CA, 2026100100%Let's Encrypt — 74%DigiCert — 7%Sectigo — 6%GoDaddy — 4%Google Trust Services — 3%Other — 6%Share of certificates with issuance dates in 2026.

Share of certificates with issuance dates in 2026.

How this report was produced

Between 1 and 7 August 2026 we scanned the top 1 million registered domains (by traffic) with a handshake-based TLS probe. For each domain we recorded the negotiated protocol version, the certificate chain, the issuing CA, the validity period and the signature algorithm. Only aggregate figures are published; no domain-level data leaves the scan.

TLS 1.3 has become the default

TLS 1.3 adoption climbed from 47% in 2021 to 80% today. Apple, Google, Mozilla and Microsoft have all raised their default minimum protocol versions, and the shorter 90-day certificate lifecycle has made upgrades easier: operators now touch their TLS configuration several times a year anyway. TLS 1.3 also removed legacy ciphers and cut the handshake to a single round trip, which shows up directly in faster page loads.

One CA issues three out of four certificates

Let's Encrypt accounted for 74% of newly issued certificates in our scan, with DigiCert (7%) and Sectigo (6%) following. The rise of free, automated issuance through ACME has permanently changed the market: automation and integration, not price, are now the main differentiators, and even commercial CAs are competing on convenience.

The 90-day certificate is the new normal

89% of new certificates have a validity of 90 days or less, driven by the browser vendors' proposal to cap public trust at 90 days. Short lifetimes shrink the window for misuse after key compromise and force operators to automate renewal — which is exactly what ACME clients like certbot and Caddy now do out of the box.

Signatures and key strength

99.6% of scanned certificates use SHA-256 or a stronger hash; SHA-1 certificates have effectively disappeared. RSA-2048 remains the most common key type (about 60%), while ECDSA P-256 keeps growing thanks to smaller handshakes. A small but rising share of sites publish ECDSA alongside RSA to keep old clients happy.

What this means for your website

If your site still negotiates TLS 1.2 or older, you are part of a shrinking minority — and browser defaults are about to make it worse. Use our free tools to check: the SSL Checker shows negotiated protocols and the certificate chain, the Certificate Inspector analyzes the full chain in detail, and the SSL/TLS Tracer walks you through the handshake step by step.

FAQ

What percentage of websites use TLS 1.3 in 2026?

About 80% of the top 1 million domains support TLS 1.3. Roughly 90% still support TLS 1.2 as a fallback, and about 8% of sites still default to TLS 1.2.

Which certificate authority has the largest market share?

Let's Encrypt issues about 74% of new certificates, followed by DigiCert (7%), Sectigo (6%) and GoDaddy (4%).

Are 90-day certificates really the standard now?

Yes — 89% of newly issued certificates have a lifetime of 90 days or less. The 90-day cap proposal from the browser vendors is now in effect for publicly trusted certificates.

Why does TLS 1.3 matter?

TLS 1.3 removes legacy ciphers, reduces the handshake to a single round trip and enables forward secrecy by default. Sites on TLS 1.3 load faster and are more resistant to downgrade attacks.

How can I check my own site’s TLS configuration?

Use the free SSL Checker on csr.plus: enter your domain and you will see the negotiated protocol, certificate chain, issuer and validity, plus concrete recommendations.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles