BOARD EDITION / 2026Board brief
CA BOARD INTELLIGENCE / 2025–2030

The certificate economy.
Beyond the browser.

Nine markets. Different buyers, economics and trust models. A source-linked view of where certificate demand is growing, who competes, and what a CA can do next.

Research snapshot: 14 September 2026 · Global scope

The broader PKI opportunity

Two overlapping analyst estimates · USD bn

$14.9–19.7billion forecast for 2030
2025–2030 calculated endpoint trajectories05101520202520262027202820292030USD bn
ABI ResearchGrand View Research

Published endpoints; annual paths calculated. Different market definitions, not an additive total or confidence interval. [S02][S03]

2025 broad PKI estimates
$5.4–7.6bn
Alternative analyst baselines. Includes more than certificate issuance.
Analyst estimates[S02][S03]
Broad PKI revenue by 2030
2.6–2.8×
Endpoint growth multiples within each source’s own market definition.
Calculated[S02][S03]
Connected IoT devices in 2030
39bn
Demand proxy, not the number of certificates or paid identities.
Device forecast[S06]
Public TLS maximum from 2029
47 days
Shorter lifetimes increase renewal workload, not automatically revenue.
Adopted standard[S10]
Four different growth measures: protected identities, active certificates, annual issuance and revenue. This site keeps them separate. Numerical CA share is shown only where the denominator is defensible. [S01]
01 / MARKET MAP

Explore the nine certificate pillars

A purpose-based market map. Select a pillar for economics, competitors, demand drivers and a 2030 outlook.

Compare all pillars
02 / STRATEGIC SIGNALS

Three shifts the board should watch

Strategic interpretation of the sourced evidence, not three separate market-size forecasts.

BOARD SIGNAL

From issuance to operations

TLS automation, private PKI and multi-CA management create recurring service opportunities. Revenue per managed identity is more useful than the renewal counter. [S10][S16][S39]

BOARD SIGNAL

From browsers to machines

Cloud workloads and connected devices widen the trust boundary. Certificate adoption, credential roles and churn matter more than raw device headlines. [S06][S18][S31]

BOARD SIGNAL

From a credential to a service

Code, document and content signing create demand for protected keys and workflow integration. Signing transactions are not new certificates. [S12][S20][S40]

03 / COMPETITION

The competitive picture is not one pie chart

Public web visibility is measurable. Private trust, signing and device PKIs need different evidence.

Open the landscape
Measured website sample13 Sep 2026

Public TLS: observed website usage

Share among websites with a known CA, using W3Techs classifications.

Not 2025 data, certificate-unit share or revenue share. Sites may use multiple CAs; shares need not total 100%. [S09]

17 provider profiles9-pillar matrix

One issuer can play several roles

Separate public trust, private infrastructure, specialist assurance and platform distribution. The competitive matrix identifies documented participation without turning product catalogs into invented market shares.

Sectigo includes Entrust’s transferred public-certificate business.
Entrust private CA services remain a distinct competitor.
Cloud providers and CA-software vendors have different economic roles.

Portfolio evidence and transaction disclosure, not a complete vendor census. [S21][S16][S17][S34]

Build the management layer before chasing volume.

Our strategic starting point: automate the core TLS estate, expand into private PKI and signing workflows, and enter specialist device or provenance markets through validated use cases.

Test the priorities