How Let's Encrypt and Sectigo differ on deployment, pricing, openness and what each is actually built for.
| Let's Encrypt | Sectigo | |
|---|---|---|
| Type | Public CA (free) | Public CA + CLM |
| Deployment | SaaS (ACME) | SaaS |
| How it works | Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder. | Formerly Comodo CA. Issues public TLS, code-signing and S/MIME at volume through a large reseller channel. Sectigo Certificate Manager handles discovery, renewal and private PKI alongside the public roots. |
| Pricing* | Free | From $110/yr (1-yr DV) |
| Free tier | Yes | No |
| Open source | Boulder (MPL-2.0) | — |
| Compliance | WebTrust, CA/B Forum | WebTrust, CA/B Forum |
| Best for | Public web TLS on anything you can automate | Cost-sensitive estates that still want a CLM |
Choose Let's Encrypt for public web tls on anything you can automate. Choose Sectigo for cost-sensitive estates that still want a clm.
* Indicative list pricing (vendor documentation and public pricing pages, August 2026).