// Engineering Log

Free Let's Encrypt Alternatives in 2026: ZeroSSL, Google Trust Services, Cloudflare — Compared

Published on 2026-09-22

// Fast route

This article belongs to the topic Security and protection.

Let’s Encrypt has made free HTTPS certificates the norm: they are issued automatically via the ACME protocol, and the client on the server renews them before expiration. But Let’s Encrypt is not the only free certificate authority. An alternative is needed when you want a backup CA in case of outages or limits, a different validity policy, a web interface, or cloud integration. Below is what is realistically available in 2026 and what has changed at Let’s Encrypt itself.

What changed at Let’s Encrypt

  • OCSP disabled. Since 7 May 2025 OCSP URLs are no longer included in certificates, and on 6 August 2025 Let’s Encrypt’s OCSP servers were turned off. Revocation checking now goes through certificate revocation lists (CRL). If your server was configured for OCSP stapling or clients required OCSP Must-Staple, you needed to reconfigure that.

  • Validity periods shortened. Instead of a single 90-day term, Let’s Encrypt introduced ACME profiles:

    • tlsserver — since 13 May 2026 issues certificates for 45 days;
    • classic (default profile) — will switch to 64 days on 10 February 2027 and to 45 days on 16 February 2028;
    • shortlived — 6-day certificates for those who deliberately choose a very short lifetime.

    At the same time, the period during which domain validation can be reused is reduced: to 10 days in 2027 and to 7 hours in 2028.

Practical takeaway: manual renewal is no longer an option. The ACME client must renew, and do so with a margin — not in the last day, but roughly a third into the certificate’s lifetime. The client chooses the profile; check your client’s documentation for support for selecting profiles.

Which free CAs are available

ZeroSSL

ZeroSSL is the second most well-known free CA with ACME support. According to ZeroSSL documentation, via ACME you can obtain an unlimited number of free 90-day certificates, including multi-domain and wildcard (*.example.com) certificates. The ACME directory is https://acme.zerossl.com/v2/DV90.

ACME requires External Account Binding (EAB) credentials: they are created in the ZeroSSL dashboard. In addition to ACME, ZeroSSL has a web interface for manual issuance and paid plans with annual certificates.

Google Trust Services

Google issues publicly trusted certificates for free via its own ACME service (Public CA). The directory is https://dv.acme-v02.api.pki.goog/directory. A Google Cloud project is required to use it: create an EAB key with gcloud publicca external-account-keys create. The certificate issuance itself is free. For Russian companies this option is usually unavailable: Google Cloud has not registered new customers from Russia since 2022.

Buypass — closed

The Norwegian Buypass was long a popular free alternative with ACME support. As of 16 October 2025 the Go SSL service was shut down: certificates cannot be ordered, renewed, or replaced. Already issued certificates remain valid until their expiration. If Buypass is configured as your primary or backup CA — replace it.

Alternatives that do not directly replace Let’s Encrypt

SSL.com

SSL.com supports ACME, but it is a paid service: according to SSL.com documentation, certificates issued via ACME are annual, priced by certificate type, and EAB credentials from the dashboard are required. Suitable if you need an annual certificate or OV/EV with organization validation, but not as a free replacement.

AWS Certificate Manager

ACM issues free certificates only for services integrated with AWS: load balancers, CloudFront, API Gateway. Certificates that can be exported and installed on your own server are paid: $7 for issuance or renewal for a regular domain and $79 for wildcard. ACM is unavailable for Russian companies due to payment restrictions.

Cloudflare Universal SSL

If your site is served through Cloudflare’s proxy, Cloudflare issues a certificate for the connection between the visitor and Cloudflare. Encryption between Cloudflare and your server is configured separately: the Full (strict) mode verifies a valid certificate on the server, while Flexible leaves that segment unencrypted — avoid using Flexible. For an audience in Russia note that since 9 June 2025 Russian operators have been limiting connections to Cloudflare, which Cloudflare itself confirmed.

ZeroSSL or Let’s Encrypt

CriteriaLet’s EncryptZeroSSL
Cost via ACMEfreefree, unlimited
Certificate lifetime90 days, moving to 45 (profiles)90 days
Wildcardyes, via DNS validationyes
RegistrationnoneEAB from the dashboard
Web interface for manual issuancenoyes
Rate limits on issuanceyes, publishedno limits on number of certificates via ACME

For most servers the difference is small: both CAs work via ACME, and the client switches between them with one setting. A sensible scheme is Let’s Encrypt as the primary CA and ZeroSSL as a fallback. Caddy does this by default: according to its documentation, if obtaining a certificate from Let’s Encrypt fails it tries ZeroSSL.

ACME clients instead of certbot

Certbot is the best-known client, but not the only one. The choice of client is often more important than the choice of CA.

  • acme.sh — a shell script with no dependencies, supports DNS validation via APIs of many providers. Since version 3.0 (August 2021) it defaults to issuing certificates from ZeroSSL; to switch back to Let’s Encrypt use acme.sh --set-default-ca --server letsencrypt.
  • lego — a client and library in Go, a single binary, supports over 200 DNS providers. Convenient for wildcard certificates and scripting.
  • Caddy — a web server that obtains and renews certificates itself, without a separate client. More details — in the article “What is Caddy”.
  • Traefik — a reverse proxy for containers with built-in ACME: certificates are issued for services based on their labels.
  • certbot — still a good choice for a classic server with Nginx or Apache, especially if you are already using it.

Common mistakes

  • Manual renewal or an old cron without checks. With a 45-day validity period an error in renewal is noticed quickly and painfully. Set up monitoring for certificate expiration.
  • Buypass in configuration. Renewal with a closed CA will not work — check which ACME server is configured in your client.
  • Cloudflare Flexible mode. The visitor sees a lock in the browser, but traffic to your server is sent in plaintext.
  • Wildcard without DNS validation. A *.example.com certificate is issued only via a DNS record; the client needs access to the DNS provider’s API for that.
  • Dependence on OCSP. OCSP stapling and Must-Staple settings for Let’s Encrypt certificates no longer make sense.

How ACME issuance works, what domain validations exist, and what CAA and Certificate Transparency are — in the article “Let’s Encrypt certificates: ACME, domain validation, CAA and Certificate Transparency”.

Need an SSL certificate or HTTPS setup?

I can help choose a solution and set up automatic renewal. Write to me — we'll figure it out together.

Написать в Telegram →

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Security and protection

SSL, hardening, access control, service protection, and secure configurations.

Typical tasks behind this topic

  • Set up SSL, certificates, and secure connections
  • Restrict access and close unnecessary entry points
  • Harden server and service configuration

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply