Summary
- An Internet Society Pulse guest article reports that Let’s Encrypt issued 99.21% of certificates observed in a 72-hour Certstream sample in July 2026. That is a bounded sample, not a full-year market census.
- The same project’s 2025 corpus put ZeroSSL first by certificate count and unique IP coverage. Repeated certificates for the same address, address allocation, current routing and live service use are different units.
- A concentration claim should publish a measurement receipt: window, collection channel, counted object, exclusions and attribution method. The percentage can then inform policy without pretending to decide more than it observed.
For three days in July, one certificate authority was almost the whole visible stream. Researchers following Certstream collected about 372,000 certificates containing 296,000 IP Subject Alternative Names. Let’s Encrypt accounted for 99.21% of those certificates; ZeroSSL for 0.76%.
Read alone, the figure sounds like a settled market structure. Read beside the project’s full-year 2025 data, it becomes a more interesting warning about measurement. In that earlier corpus ZeroSSL led with 312,816 certificates, while Let’s Encrypt had 186,390. Together they represented 96.44% of the observed certificate count.
Both observations can be correct. They do not count the same interval, and their apparent meaning changes again when the counted object changes.
One certificate is not one deployment
The researchers collected 517,619 unique IP certificates in 2025, but those certificates covered about 228,000 unique addresses. Let’s Encrypt’s 186,000-plus certificates collapsed to roughly 4,600 unique IPs. Around 176,000 certificates covered just two Cloudflare addresses.
That cluster does not establish that Cloudflare operated 176,000 independent services. The Pulse article offers a possible explanation—customer-rented infrastructure—but explicitly says there is no evidence confirming it. A short-lived certificate can be renewed many times. Several certificates can name the same address. One certificate can contain more than one address. An address can front many tenants or uses.
The count is therefore evidence about issuance objects first. Dividing it by a total produces an issuance share, not automatically a share of hosts, services, customers, traffic, reliance or bargaining power.
The study makes this visible rather than hiding it. It recomputes the picture by unique SAN IP and then follows addresses into ownership and routing datasets. About 218,000 addresses were associated with 2,137 owner entities and routed by 1,635 organizations across more than 120 countries. Its cleanest example is 1.1.1.1: allocated to APNIC Labs, routed by Cloudflare.
The holder in a registry, the network announcing a route, the operator answering a certificate challenge and the customer benefiting from a service may be different parties. A join across those tables is useful. It is not an identity function.
Validation proves a narrow, timed control
Let’s Encrypt issued its first IP-address certificate in July 2025 and made IP and six-day certificates generally available in January 2026. Its IP certificates last 160 hours. The operator’s explanation is direct: addresses are more transient than domain names, so validation should recur more frequently.
RFC 8738 defines what ACME can establish. For an IP identifier, the certificate applicant answers an http-01 or tls-alpn-01 challenge at the address; dns-01 is not permitted. The standard describes control at the time of validation and allows a CA to impose additional restrictions. Let’s Encrypt’s current challenge documentation also warns that multiple vantage points and anycast can produce different observations.
That proof is operationally valuable and deliberately bounded. It does not certify perpetual ownership. It does not say which organization holds the address in a registry, which autonomous system will route it tomorrow, which tenant caused issuance or which product eventually presented the certificate.
The CA/Browser Forum Baseline Requirements similarly speak of control or a granted right to use. RFC 5280 supplies the iPAddress form in the Subject Alternative Name. Neither turns the field into a title deed or a live network sensor.
A public log is not a service census
Certificate Transparency makes the study possible at scale. CT logs are append-only and publicly auditable; Chrome requires qualifying publicly trusted TLS certificates to carry evidence that satisfies its CT policy. Researchers can inspect issuance without asking each authority for a private ledger.
The project’s public repository also states its population: certificates from authorities trusted by Chrome. Self-signed IP certificates are out of scope. That boundary is not a flaw. It is what makes the result intelligible and reproducible.
But log inclusion and endpoint use remain separate events. A logged certificate may never be served. An active service may present a different certificate. A private PKI or self-signed deployment may work outside the observed population. Other clients can have different trust settings.
The project therefore added an active measurement: it probed selected ports and found about 38,000 hosts serving trusted IP TLS certificates across 21 ports. Ports 443 and 8443 supplied 91.1% of observations; port 853 supplied 0.16%. This result is closer to deployment, but it has its own port list, observation time and reachability limits. It cannot retroactively convert every logged object into a live service.
The result is strongest when its borders remain visible
The Pulse article does not simply announce a winner. It shows that issuer rank, unique-address coverage, ownership concentration, routed-network concentration and live serving observations answer different questions. Its code, notebooks and dataset path are public, allowing others to inspect and repeat the work.
The governance failure would begin after publication if a policymaker, buyer or platform copied only “99.21%”. A procurement decision might care about renewal dependence. A competition inquiry would need a defined market and evidence of power or harm. A network operator might care about client trust, issuance failure and replacement paths. A researcher tracking adoption might care about unique reachable services. One percentage cannot serve all four.
The current finding is a rapid-shift signal in a declared three-day window. The honest next question is whether repeated windows, using stable units and disclosed exclusions, reproduce it.
Sources
- https://pulse.internetsociety.org/en/blog/2026/09/lets-encrypt-ips-tracking-the-evolution-of-ip-x509-certificates/
- https://github.com/yevheniya-nosyk/ip_certificates_isoc
- https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate
- https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
- https://letsencrypt.org/docs/challenge-types/
- https://www.rfc-editor.org/rfc/rfc8738.html
- https://www.rfc-editor.org/rfc/rfc5280.html
- https://cabforum.org/working-groups/server/baseline-requirements/requirements/
- https://certificate.transparency.dev/logs/
- https://github.com/GoogleChrome/CertificateTransparency
- https://heng.lu/the-policy-mirror/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

