2026 SSL/TLS Adoption Report
· CSR.plus Team

- •80% of the top 1 million websites now support TLS 1.3 — up from 47% five years ago.
- •Let's Encrypt issued roughly three out of every four new certificates in 2026.
- •89% of new certificates are valid for 90 days or less; 99.6% of them are signed with SHA-256.
TLS 1.3 adoption among top sites, 2021–2026 (%)
Share of the top 1M domains supporting TLS 1.3.
Newly issued certificate market share by CA, 2026
Share of certificates with issuance dates in 2026.
How this report was produced
Between 1 and 7 August 2026 we scanned the top 1 million registered domains (by traffic) with a handshake-based TLS probe. For each domain we recorded the negotiated protocol version, the certificate chain, the issuing CA, the validity period and the signature algorithm. Only aggregate figures are published; no domain-level data leaves the scan.
TLS 1.3 has become the default
TLS 1.3 adoption climbed from 47% in 2021 to 80% today. Apple, Google, Mozilla and Microsoft have all raised their default minimum protocol versions, and the shorter 90-day certificate lifecycle has made upgrades easier: operators now touch their TLS configuration several times a year anyway. TLS 1.3 also removed legacy ciphers and cut the handshake to a single round trip, which shows up directly in faster page loads.
One CA issues three out of four certificates
Let's Encrypt accounted for 74% of newly issued certificates in our scan, with DigiCert (7%) and Sectigo (6%) following. The rise of free, automated issuance through ACME has permanently changed the market: automation and integration, not price, are now the main differentiators, and even commercial CAs are competing on convenience.
The 90-day certificate is the new normal
89% of new certificates have a validity of 90 days or less, driven by the browser vendors' proposal to cap public trust at 90 days. Short lifetimes shrink the window for misuse after key compromise and force operators to automate renewal — which is exactly what ACME clients like certbot and Caddy now do out of the box.
Signatures and key strength
99.6% of scanned certificates use SHA-256 or a stronger hash; SHA-1 certificates have effectively disappeared. RSA-2048 remains the most common key type (about 60%), while ECDSA P-256 keeps growing thanks to smaller handshakes. A small but rising share of sites publish ECDSA alongside RSA to keep old clients happy.
What this means for your website
If your site still negotiates TLS 1.2 or older, you are part of a shrinking minority — and browser defaults are about to make it worse. Use our free tools to check: the SSL Checker shows negotiated protocols and the certificate chain, the Certificate Inspector analyzes the full chain in detail, and the SSL/TLS Tracer walks you through the handshake step by step.
FAQ
What percentage of websites use TLS 1.3 in 2026?
About 80% of the top 1 million domains support TLS 1.3. Roughly 90% still support TLS 1.2 as a fallback, and about 8% of sites still default to TLS 1.2.
Which certificate authority has the largest market share?
Let's Encrypt issues about 74% of new certificates, followed by DigiCert (7%), Sectigo (6%) and GoDaddy (4%).
Are 90-day certificates really the standard now?
Yes — 89% of newly issued certificates have a lifetime of 90 days or less. The 90-day cap proposal from the browser vendors is now in effect for publicly trusted certificates.
Why does TLS 1.3 matter?
TLS 1.3 removes legacy ciphers, reduces the handshake to a single round trip and enables forward secrecy by default. Sites on TLS 1.3 load faster and are more resistant to downgrade attacks.
How can I check my own site’s TLS configuration?
Use the free SSL Checker on csr.plus: enter your domain and you will see the negotiated protocol, certificate chain, issuer and validity, plus concrete recommendations.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.