How Google Trust Services and Let's Encrypt differ on deployment, pricing, openness and what each is actually built for.
| Google Trust Services | Let's Encrypt | |
|---|---|---|
| Type | Public CA (cloud) | Public CA (free) |
| Deployment | SaaS (ACME) | SaaS (ACME) |
| How it works | Google’s own publicly trusted CA, issuing DV certificates free through ACME and through Certificate Manager for Google Cloud load balancers. The certificates cost nothing; Certificate Manager itself is metered past the first 100 per month. Certificate Authority Service covers private CAs on the same platform. | Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder. |
| Pricing* | Certificates free; manager metered | Free |
| Free tier | Yes | Yes |
| Open source | — | Boulder (MPL-2.0) |
| Compliance | WebTrust, CA/B Forum | WebTrust, CA/B Forum |
| Best for | Workloads already inside Google Cloud | Public web TLS on anything you can automate |
Choose Google Trust Services for workloads already inside google cloud. Choose Let's Encrypt for public web tls on anything you can automate.
* Indicative list pricing (vendor documentation and public pricing pages, August 2026).