The banker asks for a "premium SSL certificate" for the brochure site. The developer says Let's Encrypt is free and auto-renewed. Both are right about encryption — nobody is wrong about the padlock. The useful debate is what you buy beyond TLS.
Let's Encrypt issues free DV (Domain Validation) certificates, valid for 90 days, renewable via the ACME protocol. Paid certificate authorities sell DV, OV (Organization Validation), and EV (Extended Validation), sometimes limited financial warranty, and phone support for issuance or revocation. Understanding this distinction avoids paying for administrative comfort that automation already solves.
Comparison beyond the padlock
The table below compares what each option actually delivers — not what the CA salesperson highlights on a brochure.
| Element | Let's Encrypt (DV) | Paid certificate |
|---|---|---|
| TLS 1.2/1.3 encryption | Yes | Yes (DV) |
| Legal identity validation | Domain only | OV/EV verifies entity |
| Cost | Free | From a few euros to several hundred per year |
| Duration | 90 days (auto renewal) | 1–398 days depending on CA |
| Issuer support | Community | CA ticket or phone |
| Liability warranty | No | Sometimes limited |
| Audit perception | Widely accepted | Sometimes required in legacy banking |
Paying for pure DV in 2026 often means paying for a renewal email and CA logo — not stronger cryptography.
The difference is therefore not technical for DV: it is organisational, contractual, and sometimes political within your company or with your auditor.
Let's Encrypt: enough for whom?
For most websites, APIs, and standard e-commerce, Let's Encrypt meets regulatory requirements. GDPR and PCI-DSS require strong encryption in transit — not a specific CA brand for a DV certificate.
The automation ecosystem is mature: Caddy renews natively, Traefik integrates ACME, certbot runs on millions of servers, and host panels like OVH, Infomaniak, or Plesk offer Let's Encrypt in one click. Wildcard via DNS-01 (Cloudflare, OVH API, etc.) is free and well documented.
Watch points remain operational: monitor expiry with a D-14 alert, test renewal on staging, and document who manages the ACME account when someone leaves. Rate limits (five duplicate certificates per week per domain) mostly appear with misconfigured renewal loops.
Paid certificate: when it justifies itself
Some enterprise policies mandate a commercial issuer — banks, regulated industry, large groups with an approved CA catalogue. In that case, an OV or EV certificate provides documented organisation verification, useful for compliance files requiring a printable attestation.
Legacy environments, increasingly rare, may reject Let's Encrypt's ISRG root. Test before migration rather than assuming. Urgent revocation support with CA SLA remains a niche for critical infrastructure without a 24/7 team.
Watch multi-year certificates: industry maximum duration has been reduced, and a forgotten two-year cert costs more than well-monitored Let's Encrypt automation. EV no longer delivers "trusted site" UX in modern Chrome, Safari, or Firefox — the green bar is gone.
For cipher suites and a maintainable TLS profile, see Configure TLS. ACME automation is covered in ACME: monitor renewal.
Shared good practices for both options
Whether you choose Let's Encrypt or a paid CA, fundamentals stay the same. Serve TLS 1.2 minimum and TLS 1.3 preferred, with a Mozilla Intermediate profile rather than a cipher list copied from a forum. Verify the full chain includes the intermediate certificate — a common error that breaks some clients.
Enable HSTS only once HTTPS works everywhere, including concerned subdomains. OCSP stapling improves handshake performance if your server supports it. For web server automation, compare Nginx or Caddy for your stack.
The peak: you pay for paperwork, not the padlock
Before renewing a paid certificate, ask for written proof that your audit forbids Let's Encrypt. If nobody knows, you probably pay out of habit.
Decide and move forward without blind spots
Start by checking whether your audit or specification mandates a named issuer or OV/EV level. If not, deploy Let's Encrypt with a D-14 expiry alert and document renewal in your runbook. If yes, shortlist CAs with enterprise validation proof and test legacy client compatibility before switching. In both cases, apply a maintainable TLS profile and plan an annual review. Compare hosts that ease automation via our compare tool and directory.
Frequently asked questions
Is Let's Encrypt less secure than a paid certificate?
Not for standard DV: TLS encryption is equivalent. The difference is OV/EV validation, issuer support, and sometimes compatibility with older clients — not base cryptographic strength.
Do I need EV for user trust?
Green EV bars disappeared from modern browsers. EV remains useful for internal policies or regulated sectors requiring strengthened legal identity proof — not to reassure the general public.
When should I pay for a wildcard certificate?
If your stack cannot automate Let's Encrypt DNS-01, or an auditor requires a specific commercial issuer. Otherwise, a Let's Encrypt wildcard via DNS API remains free.
Let's Encrypt renewal: outage risk?
Yes if certbot cron is missing or HTTP-01 is blocked. Automate renewal and monitor expiry at D-14 minimum to avoid a weekend outage.
Before renewing paid DV, ask: does our audit forbid Let's Encrypt? If nobody knows, you probably pay out of habit.
