History

A Decade of HTTPS Adoption Statistics: 2015 to Today

In the mid-2010s, plain HTTP still accounted for a substantial share of overall web traffic and page loads across major browsers' own telemetry. Within about a decade — driven by Let's Encrypt's free certificates, Chrome's escalating "Not Secure" warnings, Google's ranking signal, and broader industry hardening efforts — HTTPS became the overwhelming majority of web traffic loaded by modern browsers.

What drove the curve

No single factor explains the shift entirely — it's the combined, roughly simultaneous effect of removing the cost barrier (Let's Encrypt), removing the technical friction (automation via ACME and AutoSSL), and adding visible pressure (browser warnings, search ranking) that together moved HTTPS from a deliberate, often costly choice to the unremarkable default.

What's left

The remaining pockets of plain HTTP today tend to be abandoned or unmaintained sites, very old internal/legacy systems not exposed to broader adoption pressure, or specific technical constraints (extremely resource-limited embedded devices) — rather than any large, actively maintained segment of the modern web choosing to skip HTTPS deliberately.

How adoption differed meaningfully by region and site type during the transition

HTTPS adoption didn't progress uniformly — commercial and e-commerce sites, along with sites in regions with stronger data-protection regulation, the EU notably following GDPR, tended to adopt earlier and more completely than personal sites or older sites maintained with minimal ongoing investment, producing a genuinely uneven adoption curve beneath the smooth aggregate statistics usually cited.

What current browser telemetry actually shows about remaining plain HTTP traffic

Browser vendors' own published telemetry consistently show the overwhelming majority of page loads happening over HTTPS today, with the remaining plain HTTP share concentrated heavily in specific, identifiable categories — internal or local network addresses, older cached content, and a long tail of infrequently-updated smaller sites — rather than any broad, actively growing category of the web still resisting HTTPS.

What role Content Delivery Networks played in accelerating adoption

Major CDNs offering free, automatically managed SSL as a standard included feature (Cloudflare notably) played a significant, sometimes underappreciated role in HTTPS adoption statistics, since a site owner could gain HTTPS coverage simply by routing traffic through such a service without needing to manage certificates on their own origin infrastructure at all.

How this history is likely to be remembered in retrospect

Looking back, the 2014-2020 period is likely to be remembered as the specific window during which HTTPS transitioned from a notable, deliberate security choice to simply an assumed, unremarkable baseline characteristic of any legitimate website — a transition that took the combined effect of cost removal, automation, and escalating browser pressure to actually complete, none of which alone would likely have been sufficient.

Where to find current, up-to-date adoption statistics yourself

Both Chrome's and Firefox's transparency reports publish regularly updated HTTPS usage statistics drawn directly from their own user telemetry, offering a more current and authoritative picture than any single point-in-time historical summary, including this one, can fully capture on its own.

What the remaining adoption gap suggests about internet infrastructure's long tail generally

The specific, persistent categories of remaining plain-HTTP traffic, abandoned sites, ancient embedded devices, deeply legacy internal systems, illustrate a broader pattern common across internet infrastructure generally: aggregate statistics can show something as functionally universal while a genuinely difficult-to-eliminate long tail of edge cases persists indefinitely, a pattern worth keeping in mind whenever any technology's adoption is described using round, seemingly complete percentages.

A closing reflection on how far the baseline has shifted

Perhaps the clearest measure of how completely this history's overall arc has played out is that a plain HTTP website today reads as a specific, noticeable anomaly requiring explanation, a complete inversion of the situation three decades ago when encryption was the unusual exception rather than the assumed default.

A plain HTTP site today reads as a specific anomaly requiring explanation, the complete inversion of where this history started.