How Smallstep and Let's Encrypt differ on deployment, pricing, openness and what each is actually built for.
| Smallstep | Let's Encrypt | |
|---|---|---|
| Type | Private CA (ACME) | Public CA (free) |
| Deployment | Self-hosted + SaaS | SaaS (ACME) |
| How it works | step-ca is an open-source private certificate authority that speaks ACME, so internal services renew exactly the way public ones do. The hosted product adds device identity, SSH certificates and single sign-on integration. | Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder. |
| Pricing* | Free (OSS); hosted by quote | Free |
| Free tier | Yes | Yes |
| Open source | step-ca (Apache-2.0) | Boulder (MPL-2.0) |
| Compliance | SOC 2 (hosted) | WebTrust, CA/B Forum |
| Best for | Internal mTLS and short-lived certificates | Public web TLS on anything you can automate |
Choose Smallstep for internal mtls and short-lived certificates. Choose Let's Encrypt for public web tls on anything you can automate.
* Indicative list pricing (vendor documentation and public pricing pages, August 2026).