# lets-encrypt

Source: https://startwithidentity.com/vendors/pki/lets-encrypt/
Last updated: 2026-07-03
License: content by Start with Identity. Cite the source URL.

---

## Overview
Let's Encrypt is a free, automated, and open certificate authority run by the nonprofit Internet Security Research Group (ISRG). It issues the TLS certificates that secure a large share of the public web, entirely through the ACME protocol.

## What it is good at
It made HTTPS free and automatic. Certificates are issued and renewed via ACME with no cost and no manual steps, which is why it underpins so much of the web and integrates with virtually every server, CDN, and hosting platform. Its transparency and nonprofit governance are a public good.

## Where it falls short
It issues only domain-validated, short-lived public TLS certificates. It is not a private CA and does not cover device, workload, code-signing, or enterprise identity certificates, and there is no commercial support.

## Pricing
Free, funded by sponsors and donations to ISRG.

## Best for, and who should look elsewhere
Choose Let's Encrypt for free, automated public TLS. Look elsewhere for private-CA, device, or enterprise certificate needs (see [EJBCA](https://startwithidentity.com/vendors/pki/ejbca/) or [DigiCert](https://startwithidentity.com/vendors/pki/digicert/)).

## Bottom line
The free, automated CA that made HTTPS universal, ideal for public TLS and ACME-based automation.
