x509.systems

Smallstep vs Let's Encrypt

How Smallstep and Let's Encrypt differ on deployment, pricing, openness and what each is actually built for.

SmallstepLet's Encrypt
TypePrivate CA (ACME)Public CA (free)
DeploymentSelf-hosted + SaaSSaaS (ACME)
How it worksstep-ca is an open-source private certificate authority that speaks ACME, so internal services renew exactly the way public ones do. The hosted product adds device identity, SSH certificates and single sign-on integration.Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder.
Pricing*Free (OSS); hosted by quoteFree
Free tierYesYes
Open sourcestep-ca (Apache-2.0)Boulder (MPL-2.0)
ComplianceSOC 2 (hosted)WebTrust, CA/B Forum
Best forInternal mTLS and short-lived certificatesPublic web TLS on anything you can automate

Smallstep

  • Genuinely quick to stand up
  • ACME internally — same tooling as public TLS
  • Excellent short-lived certificate and SSH support
  • Not a public CA — internal trust only
  • Smaller company than the incumbents

Let's Encrypt

  • Free and genuinely unlimited in practice
  • ACME everywhere — client support is universal
  • Short lifetimes push good automation hygiene
  • Domain validation only — no OV or EV
  • No support contract to escalate to

Bottom line

Choose Smallstep for internal mtls and short-lived certificates. Choose Let's Encrypt for public web tls on anything you can automate.

* Indicative list pricing (vendor documentation and public pricing pages, August 2026).