Earlier quoted context omitted.
Just so people don't get an oversimplified view of what it takes to start a CA from this comment, you will have much bigger challenges than access to application software. Your first issue will be securing millions of dollars per year for the staff that it takes to run the CA responsibly. Your next issue will be getting trusted by browsers. Also, the open source Let's Encrypt CA software is tailored for how we do thi…
What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000. Also, timeline. It took Let’s Encrypt a couple years to get in root pr…
It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share.
It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (starting at about $40K... KPMG don't come cheap), hardware (HSM, servers for validation, OCSP, CT, etc) and people (needs to be trusted people, and often are paid top dollars).
It's easy to _buy_ a CA than creating one. You can get your new root certificates included later easily now that you have a root already, from which you can cross-sign until they are included. CAs are sold out more often than many of us think.