Public Key Infrastructure (PKI) and digital certificates are fundamental to secure web communication by ensuring website authenticity, data confidentiality, and information integrity. As Afghan government institutions increasingly rely on websites and webmail systems to deliver digital services, secure certificate deployment has become essential for protecting sensitive information and maintaining public trust. This study assesses the deployment characteristics and security of PKI and digital certificates across 41 Afghan public-sector websites and 26 publicly accessible webmail systems. A quantitative, non-intrusive assessment was conducted using publicly available certificate and Transport Layer Security (TLS) information. Certificate authorities, validation types, trust chains, cryptographic mechanisms, and deployment practices were evaluated against recognized international cybersecurity standards and best practices. The results show that most public-sector websites use trusted certificate authorities, with Let's Encrypt securing 75.6% of the assessed websites. Certum, Google Trust Services, GlobalSign, and GoDaddy were also identified, while Domain Validation certificates were the predominant certificate type. However, 10 webmail systems (38.5%) generated browser security warnings, indicating weaknesses in certificate deployment or management. Overall, Afghan public-sector organizations have adopted trusted PKI infrastructures, but improvements in certificate management, security monitoring, and compliance with cybersecurity standards are required. These findings provide practical evidence to support stronger cybersecurity governance and improve the security and reliability of government digital services in Afghanistan.