Dear CA Colleagues,
The structural changes in the global SSL/TLS certificate market have likely already been reflected in your revenue figures, and the outlook is probably not optimistic. Q1 2026 data show that Let's Encrypt issued approximately 54.4% of all publicly trusted SSL/TLS certificates, with Google Trust Services ranking second at around 16.7%. Add to that platform CAs such as Amazon, Microsoft, and Cloudflare, and free and cloud-platform-related certificates now account for over 90% of global issuance. The declining market share of traditional commercial CAs is an industry-wide reality.
At the same time, the S/MIME certificate market remains largely untapped. The S/MIME standard has existed for nearly three decades, yet an academic study covering 27 years and over 81 million emails found that only 5.46% of users had ever used S/MIME or PGP, with actual encrypted emails accounting for just 0.06%.
This is not a question of technical feasibility; major email clients have long supported S/MIME. The real barrier is usability: manually applying for certificates, manually configuring them in the email client, manually renewing certificates — these steps are enough to deter most users.
This is precisely where the opportunity lies for the CA industry.
On July 2, 2025, the CA/Browser Forum S/MIME Certificate Working Group officially passed Ballot SMC012, incorporating RFC 8823 (ACME for S/MIME) into the S/MIME Baseline Requirements. This means automated S/MIME certificate issuance is now an industry-standard option. The standards are in place. The market is waiting for a truly usable implementation.
The potential market for S/MIME certificates is far larger than that for SSL certificates. SSL certificates correspond to approximately 200 million websites worldwide, while S/MIME corresponds to over 5 billion internet users and their multiple email accounts. This is an order-of-magnitude larger incremental opportunity.
ZTmail is built precisely to seize this opportunity. It is an email client centered on automatic S/MIME certificate management, enabling users to complete certificate application and configuration with one click, with encryption and digital signing enabled by default. Private keys are generated and securely stored on the user's local device.
To ensure this innovative product benefits all CAs and enables more email users to adopt encryption sooner, ZoTrus Technology has made an even more far-sighted decision: to build an AutoCert Marketplace open to all global CAs. This marketplace will not only bring S/MIME certificate orders to CAs but also allow email users to compare prices and services across CA websites, all in one place, without having to visit each CA’s website individually.
For CAs, this means:
The first CAs to join will receive the most favorable support terms, with flexible partnership models and case-by-case commercial terms.
ZTmail has the necessary technical foundation in place. But only with the participation of CAs worldwide can this ecosystem truly flourish. This is not a solo performance by a single vendor, but an industry infrastructure project that requires the collective participation of certificate authorities.
Protecting the email privacy and communication security of global internet users is becoming a new historical mission for the CA industry. Previously, CAs secured the connection between websites and users through SSL/TLS certificates. Today, we could further protect users' most daily and most sensitive communication — email. This is both a business opportunity and a shared industry responsibility.
The ZTmail Ecosystem Partnership platform is committed to neutral operation and open access: the platform does not favor any CA, all access criteria are open and transparent, and any qualified CA can join under the same rules. Mailbox validation, identity vetting, and certificate issuance control always remain with the CA; ZoTrus does not intervene in any CA's certificate issuance decisions.
I have personally attended multiple CA/Browser Forum face-to-face meetings and witnessed the global CA industry's journey from the peak of the SSL market to its current adjustment. It is based on this understanding of the industry that ZoTrus has launched this open cooperation platform for S/MIME certificate automation for CAs worldwide.
The S/MIME certificate automation market has just begun. Early participants will have the opportunity to co-define the user experience and cooperation rules, and secure advantageous early positions.
I and the entire development team sincerely invite CAs worldwide to join the ZTmail Ecosystem Partnership platform, to jointly promote the realization of encryption by default for email, and to jointly fulfill the industry's responsibility to protect users' email communication privacy.
Visit the AutoCert Marketplace (https://ztmail.ai/marketplace) to see how end users can purchase certificates, or visit the Ecosystem Partnership page (https://ztmail.ai/partnership) for cooperation details. For further inquiries, please contact: partner@ztmail.ai.
Richard Wang
ZTmail Chief Architect
Founder & CEO, ZoTrus Technology
August 20, 2026