x509.systems

LLet's Encrypt

The nonprofit CA that made automated TLS the default — free, ACME-only, 90-day certificates.

Public CA (free)SaaS (ACME)By ISRGSince 2015Open source: Boulder (MPL-2.0)
Type
Public CA (free)
How it works
Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder.
Deployment
SaaS (ACME)
Pricing*
Free
Free tier
Yes
Open source
Boulder (MPL-2.0)
Compliance
WebTrust, CA/B Forum
Best for
Public web TLS on anything you can automate
Notable
Billions of certificates issued

* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.

Strengths

  • Free and genuinely unlimited in practice
  • ACME everywhere — client support is universal
  • Short lifetimes push good automation hygiene
  • Run by a nonprofit with public transparency

Trade-offs

  • Domain validation only — no OV or EV
  • No support contract to escalate to
  • Rate limits bite on very large estates
  • No code-signing or S/MIME

Visit Let's Encrypt → Documentation

Listed for comparison as of August 2026 — not an endorsement, and Let's Encrypt did not pay for placement. See disclosure.

Compare Let's Encrypt with…

Let's Encrypt vs DigiCertLet's Encrypt vs SectigoLet's Encrypt vs Venafi