Sectigo Limited

United States · owned by Independent (United States) · sectigo.com · 16 vendors

Sectigo is a leading Certificate Authority and provider of SSL/TLS certificates and automated certificate lifecycle management (CLM) solutions. The company offers a cloud-native platform that enables organizations to discover, manage, and automate digital certificates across their entire enterprise, securing humans, devices, and workloads. Trusted by over 700,000 global customers for more than 20 years, Sectigo also provides website security tools and quantum-ready PKI solutions.

Resilience scores

Disruption prediction

Sectigo Limited has an estimated 27% probability of disruption in the next 6 months.

10 of Sectigo Limited's 16 vendors monitored for disruptions.

Technology vendors

Services catalogue

5 services in catalogue across 3 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-05-04 · revision 5

16 direct vendors, 225 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Sectigo Limited exhibits a medium level of migration readiness, primarily due to a mix of foundational strengths and significant unknowns or complexities. A key opportunity for migration is the implied existing experience with cloud environments, as the company provides 'cloud-based certificate lifecycle management services'. Its strong security posture, evidenced by ISO 27001 certification and established data privacy frameworks (GDPR, EU-U.S. Data Privacy Framework), provides a solid base for secure migration. However, several factors pose significant challenges. The regulatory environment is complex, with 'Assessment Required' statuses for NIS2, SOC2, and ISAE 3000. Addressing these during a migration would require substantial effort and could introduce delays and increased costs. Global data residency requirements, while managed through existing frameworks, add complexity to data placement and transfer strategies, potentially necessitating specific contractual terms for customers. A major impediment to a higher readiness score is the complete lack of detailed information on the internal tech stack (e.g., cloud-native architecture, containerization, microservices adoption), which makes it difficult to assess the architectural flexibility and effort required for migration. Financial stability to fund a major migration is also unknown due to missing revenue and growth data. Lastly, while there is some vendor geographic diversity, the 'Vendor Lock-in Risk' is unknown, and the 'Total Vendors: 0' data point is ambiguous, making a precise assessment of vendor-related migration complexity difficult.

Compliance

5 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Sectigo processes personal data of EU/EEA residents through their certificate issuance services and has global operations including EU offices (France). While they have comprehensive privacy policies and data protection measures in place, the medium risk reflects the complexity of cross-border data transfers and the substantial fines (up to 4% of global turnover) for non-compliance. Their privacy policy demonstrates GDPR compliance awareness with detailed data processing descriptions, retention periods, and individual rights provisions.

Evidence: https://www.sectigo.com/privacy-policy, https://www.sectigo.com/legal, https://www.sectigo.com/uploads/files/C2120-ISMS759-10-83-cert.pdf

NIS2 (source) — Assessment Required

NIS2 applicability is uncertain as Sectigo operates in cybersecurity/digital infrastructure which could qualify as 'digital providers' under Important Entities, and they have EU operations (France office). However, their exact classification under NIS2 sectors and whether they meet the size thresholds (50+ employees or €10M+ turnover) requires further assessment. The medium risk reflects potential applicability given their digital infrastructure role and EU presence, with significant compliance obligations if applicable.

Evidence: https://www.sectigo.com/about, https://www.sectigo.com/uploads/files/C2120-ISMS759-10-83-cert.pdf

ISO 27001 (source) — Compliant

Sectigo has achieved ISO 27001 certification, demonstrating compliance with international information security management standards. The low risk reflects their certified status and the strong security framework this provides for their certificate authority operations.

Evidence: https://www.sectigo.com/uploads/files/C2120-ISMS759-10-83-cert.pdf, https://www.sectigo.com/legal

Financials

Three-year financials

Financial Resilience Score: 6/10

Sectigo demonstrates a structurally sound business model anchored in recurring, subscription-based certificate renewals across a base of over 700,000 customers and 2,700+ active partners. The renewal-driven nature of SSL/TLS certificates provides high revenue predictability, and the CA/Browser Forum's move toward 47-day certificate lifespans dramatically increases renewal frequency — from roughly once per year to approximately eight times per year — acting as a powerful structural revenue and volume accelerant for Sectigo's automation platform. The company's position as the world's largest commercial Certificate Authority by volume (over 1 billion certificates issued) creates meaningful scale advantages and switching cost moats, particularly as enterprises migrate to CLM SaaS platforms with higher average selling prices and superior retention economics. The strategic pivot from commodity certificate sales toward the enterprise Sectigo Certificate Manager (SCM) platform represents a margin-accretive upsell opportunity across the existing customer base, and is supported by consistent G2 CLM Leader recognition for 12 consecutive quarters and a Forrester TEI study citing 243% ROI for enterprise customers. Francisco Partners' PE backing provides capital for M&A and product investment without short-term public market pressures. Emerging growth catalysts — post-quantum cryptography readiness, IoT identity, and eIDAS-compliant qualified certificates — further diversify the long-term revenue opportunity. However, the score is tempered by significant transparency limitations: no audited revenue, EBIT, equity, or balance sheet data is publicly available, making it impossible to assess leverage, debt covenants, cash burn, or true profitability. The PE ownership overhang is notable — Francisco Partners has held Sectigo for approximately eight years, exceeding typical 4–7 year hold periods, meaning an exit event (IPO or trade sale) may be imminent and could introduce strategic uncertainty. Competitive pressure from free certificate providers (Let's Encrypt) and cloud-native bundled certificates (AWS, Google) continues to erode the low end of the market, and any CA compliance failure under WebTrust or CA/Browser Forum rules could trigger browser distrust — an existential operational risk as demonstrated by the Symantec CA precedent in 2017–2018. The overall resilience score of 6 reflects a genuinely strong and defensible business model with compelling structural tailwinds, offset by the opacity inherent in private PE-backed ownership, meaningful competitive and regulatory risks, and the inability to verify financial health through any public primary source.

Key strengths: Recurring subscription/renewal-based revenue model with high predictability, World's largest commercial Certificate Authority by volume — over 1 billion certificates issued, 700,000+ customers and 2,700+ active channel partners providing distribution leverage, 47-day SSL/TLS certificate lifespan mandate (effective 2026) dramatically increases renewal frequency and automation platform demand, Strategic pivot to higher-margin enterprise CLM SaaS (SCM platform) — 12 consecutive G2 Leader quarters, Diversified product portfolio: TLS/SSL, S/MIME, code signing, IoT identity, private PKI, eIDAS, web security, Post-quantum cryptography (PQC) investment positions Sectigo ahead of anticipated algorithm migration, Francisco Partners PE backing provides capital for M&A and product investment, Forrester TEI study citing 243% ROI for enterprise customers supports strong product-market fit, Global presence across 8 offices and 150+ countries

Risk factors: No public financial reporting — revenue, EBIT, equity, and leverage are entirely undisclosed and unverifiable, PE ownership overhang: Francisco Partners has held Sectigo ~8 years, exceeding typical hold period; exit event may be approaching, CA compliance risk: any mis-issuance or WebTrust audit failure could result in browser distrust — an existential risk (cf. Symantec CA 2017–2018), Intense competition from DigiCert, GlobalSign, Entrust, Let's Encrypt (free DV), and cloud-native free/bundled certificates (AWS, Google), Commoditization of DV certificates creating structural price compression at the low end of the market, Regulatory and CA/Browser Forum risk across multiple jurisdictions (eIDAS, WebTrust, national frameworks), Acquisition integration risk from multiple acquired products (Icon Labs, CodeGuard, SiteLock), Customer concentration at enterprise CLM level unknown, Geopolitical and regulatory risk as a global CA operating under diverse and evolving regulatory frameworks

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report