Let's Encrypt
Capability scores
Methodology →- Authentication
- 2.5
- SSO & Federation
- 2.0
- Authorization
- 2.0
- Lifecycle & Provisioning
- 4.0
- MFA & Passwordless
- 2.0
- Governance & Audit
- 3.0
- Developer Experience
- 4.5
- Deployment Flexibility
- 4.0
- Pricing Transparency
- 5.0
- Support & Ecosystem
- 4.0
Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.
Overview
Let's Encrypt is a free, automated, and open certificate authority run by the nonprofit Internet Security Research Group (ISRG). It issues the TLS certificates that secure a large share of the public web, entirely through the ACME protocol.
What it is good at
It made HTTPS free and automatic. Certificates are issued and renewed via ACME with no cost and no manual steps, which is why it underpins so much of the web and integrates with virtually every server, CDN, and hosting platform. Its transparency and nonprofit governance are a public good.
Where it falls short
It issues only domain-validated, short-lived public TLS certificates. It is not a private CA and does not cover device, workload, code-signing, or enterprise identity certificates, and there is no commercial support.
Pricing
Free, funded by sponsors and donations to ISRG.
Best for, and who should look elsewhere
Choose Let's Encrypt for free, automated public TLS. Look elsewhere for private-CA, device, or enterprise certificate needs (see EJBCA or DigiCert).
Bottom line
The free, automated CA that made HTTPS universal, ideal for public TLS and ACME-based automation.
Related on Start with Identity
- CVESMB Server Kerberos reflection via Ghost SPNs
October 2025 follow-on to CVE-2025-33073. SMB Server elevation of privilege by combining Kerberos reflection with Ghost SPNs and DNS self-registration.
- CVEWindows SMB Client improper authentication (tampering)
Windows SMB Client improper authentication (CWE-287) that allows tampering. Not an Entra token bug, but it sits in the same Microsoft identity-adjacent patch tr
- CVEWindows SMB Kerberos reflection elevation of privilege
Kerberos authentication reflection on SMB, still abusable via Ghost SPNs after the first fix. High-severity elevation of privilege on Windows.
- Comparisondigicert-vs-sectigo
Two commercial certificate authorities with lifecycle management attached. DigiCert is the premium option, Sectigo the value one, and shrinking certificate life
- Comparisonkeyfactor-vs-venafi
Both automate certificate lifecycle at enterprise scale. The live question in 2026 is ownership: Keyfactor is independent, while Venafi sits inside CyberArk, no
- BlogA CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later r
By SWI Community Team · Last evaluated 2026-07-03
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to community@startwithidentity.com.