SSLCloakBuy short-lived cert

Let's Encrypt vs ZeroSSL

A genuinely neutral comparison — SSLCloak sells certificates through both, per order, so there's no reason for this page to favor either one.

The short answer

For almost every order, it doesn't matter which you pick — both are Domain Validation (DV)-only certificate authorities trusted by essentially every browser, both support the same ACME automation and wildcard certificates via DNS validation, and both are free to issue through. The real difference is underneath: Let's Encrypt is a nonprofit operating its own independent root; ZeroSSL is a commercial company (owned by HID Global since 2024) whose certificates chain to Sectigo's root. That's why having both available is real redundancy — just not the strongest theoretical version of it. See “If they're not fully independent root programs, what's the point?” below.

Side by side

 Let's EncryptZeroSSL
OperatorInternet Security Research Group (ISRG), a 501(c)(3) nonprofitA commercial company, acquired by HID Global in January 2024
Founded2015 (ISRG itself: 2013)2016
Root certificateISRG Root X1 / X2 — Let's Encrypt's own root, self-signed and directly trustedIntermediate CAs that chain to Sectigo's USERTrust RSA root, not a separate root program
CostAlways free, no paid tierFree tier (3 certs via the dashboard, unlimited via ACME), or paid plans from $14.99/mo for more annual/wildcard certs
Validation levelsDomain Validation (DV) onlyDomain Validation (DV) only
ACME supportCreated the ACME protocol (RFC 8555); ACME-only, no web dashboardFull ACME support, plus its own web dashboard and REST API
External Account Binding (EAB)Not requiredRequired for ACME issuance
Wildcard certificatesYes, via DNS-01 validationYes, via DNS-01 validation
Scale~10 million certificates issued per day (late 2025)1M+ certificates issued monthly; 2.4M+ user accounts
Browser trust~99.9% of browsers~99.9% of browsers

The technical difference that actually matters

Both CAs issue certificates that chain up to a root trusted by browsers and operating systems — that's a baseline requirement for public trust, not a differentiator. The real difference is which root, and who operates it.

Let's Encrypt issues from ISRG Root X1 / X2 — a root Let's Encrypt's own nonprofit operates itself. It used to also chain through a cross-signed IdenTrust root for compatibility with older devices that didn't yet trust ISRG's root directly; that cross-sign expired in September 2024, and Let's Encrypt has run on its own self-signed root exclusively since.

ZeroSSL issues through intermediate CAs (“ZeroSSL RSA/ECC Domain Secure Site CA”) that chain to Sectigo's USERTrust RSA root — the same root program used by Sectigo's own certificates and several other resellers. This isn't a knock on ZeroSSL's certificates (they're equally trusted by every browser), but it does mean ZeroSSL and Let's Encrypt aren't two fully separate root trust chains the way, say, Let's Encrypt and DigiCert are.

What this means in practice: choosing between them for redundancy still protects you against a company-specific outage, rate limit, or policy change at either CA — that part is real. It wouldn't protect you against the specific, unlikely scenario of Sectigo's root itself being distrusted, since that could affect ZeroSSL without touching Let's Encrypt.

Why SSLCloak offers both

Redundancy you don't have to build yourself, with the honest caveat above. If Let's Encrypt has an outage, or you hit a rate limit, or a network you're deploying to flags Let's Encrypt specifically by issuer name, having ZeroSSL as a genuinely separate company and infrastructure means you're not stuck waiting on one provider. You pick per order, right up until you submit it, and can switch any time without creating a second account or losing your order history.

FAQ

Is ZeroSSL as trusted as Let's Encrypt?
In the way that matters to a visitor's browser, yes — both chain to roots trusted by essentially every modern browser and OS, so a certificate from either shows the same padlock with no warnings. Where they genuinely differ is corporate structure and root program: Let's Encrypt is run by a nonprofit and operates its own independent root; ZeroSSL is a commercial company (owned by HID Global) whose certificates chain to Sectigo's root rather than a separate one it operates itself.
If they're not fully independent root programs, what's the point of offering both?
Real, practical redundancy, just not the strongest possible version of it. Let's Encrypt and ZeroSSL are still operationally separate companies with separate infrastructure and separate issuing intermediates — an outage, policy change, or incident specific to one doesn't touch the other. What they're not is two completely unrelated root trust chains, since ZeroSSL's intermediate ultimately chains to Sectigo's root. For most practical purposes (an outage, a rate limit, a business decision by one company) that distinction doesn't matter; it would matter in the specific, rare scenario of Sectigo's own root being distrusted, since that could affect ZeroSSL without affecting Let's Encrypt's independent root.
Which one should I pick?
For most orders it genuinely doesn't matter — pick whichever, or let redundancy be the reason you'd ever need the other. Reach for ZeroSSL specifically if a network you're deploying to has flagged Let's Encrypt by issuer name, or if you're mid-outage on Let's Encrypt and need to issue right now.
Can I use both across different orders?
Yes — SSLCloak lets you choose per order, right up until you submit it, without creating a second account or losing your order history.

Ready to order?

Pick your CA on the Options step of checkout — right up until you place the order.

See pricing →

Sources