The certificate economy.
Beyond the browser.
Nine markets. Different buyers, economics and trust models. A source-linked view of where certificate demand is growing, who competes, and what a CA can do next.
Explore the nine certificate pillars
A purpose-based market map. Select a pillar for economics, competitors, demand drivers and a 2030 outlook.
Public TLS
Protect the installed base. Monetize reliable automation, not the renewal counter.
Machine identity
The recurring opportunity is the management layer across heterogeneous trust systems.
IoT & devices
Win design-in and lifecycle responsibility, not only factory certificate volume.
Person & workforce
Compete on assurance, enrollment and integration, not the whole identity market.
Email / S/MIME
The opportunity is managed rollout and key lifecycle, not a generic email-security TAM.
Code & firmware
Sell controlled signing as a service, not only a publisher credential.
Documents & seals
The addressable business is a trust-service workflow, not every electronic signature.
Brand / VMC & CMC
A focused certificate adjacency with a mailbox-provider acceptance dependency.
Content / C2PA
Treat provenance as an option on ecosystem adoption, not a revenue forecast based on AI image counts.
Three shifts the board should watch
Strategic interpretation of the sourced evidence, not three separate market-size forecasts.
From issuance to operations
TLS automation, private PKI and multi-CA management create recurring service opportunities. Revenue per managed identity is more useful than the renewal counter. [S10][S16][S39]
From browsers to machines
Cloud workloads and connected devices widen the trust boundary. Certificate adoption, credential roles and churn matter more than raw device headlines. [S06][S18][S31]
From a credential to a service
Code, document and content signing create demand for protected keys and workflow integration. Signing transactions are not new certificates. [S12][S20][S40]
The competitive picture is not one pie chart
Public web visibility is measurable. Private trust, signing and device PKIs need different evidence.
Public TLS: observed website usage
Share among websites with a known CA, using W3Techs classifications.
Not 2025 data, certificate-unit share or revenue share. Sites may use multiple CAs; shares need not total 100%. [S09]
One issuer can play several roles
Separate public trust, private infrastructure, specialist assurance and platform distribution. The competitive matrix identifies documented participation without turning product catalogs into invented market shares.
Portfolio evidence and transaction disclosure, not a complete vendor census. [S21][S16][S17][S34]
Build the management layer before chasing volume.
Our strategic starting point: automate the core TLS estate, expand into private PKI and signing workflows, and enter specialist device or provenance markets through validated use cases.