ISO-27001 or SOC2 external certification?

I would like to know if LetsEncrypt is planning to become certified by an external party.

Or failing that, does the LetsEncrypt API undergo any security review or periodic penetration test?

Let’s Encrypt (and therefore it’s API as well as issuance systems) undergo a pretty extensive audit (WebTrust) as part of being a publically trusted CA. The audits are available here:

As I’m not affiliated with LE I can’t say anthing about ISO-27001 and SOC2

WebTrust audits are apparently SOC-3 audits.

The scope of a WebTrust audit would absolutely encompass the ACME service provided by Let’s Encrypt, much as it would the web frontend and bespoke APIs of your typical commercial CA.

all this information is available in the document repository

go to town :smiley:

as a side note most of these conversations ended up going in circles

to save you time - let’s encrypt complies with the security and audit requirements set by the industry just like any other paid Public Certificate Authority

And back on topic, I remember finding this recently while looking for something else:

“Auditing costs include the required annual WebTrust audits as well as third party expert security review and testing. The third party security audits include code review, infrastructure review, penetration testing, and ACME protocol analysis. We are not required to do third party auditing beyond the WebTrust audits, but it would be irresponsible of us not to.”


