Blog

CLM Vendor Comparison 2026: Keyfactor vs Venafi vs DigiCert, Pricing and Licensing

Independent comparison of Keyfactor, Venafi, DigiCert, Sectigo, Entrust and Certdog. Seven licensing models, pricing ranges and total cost of ownership.

Selecting a certificate lifecycle management (CLM) platform is one of the most consequential infrastructure decisions an organisation will make. The platform will underpin your ability to maintain digital trust, prevent certificate-related outages, meet regulatory requirements, and prepare for the cryptographic transitions ahead.

The CLM market is evolving rapidly. CyberArk's $1.54 billion acquisition of Venafi in 2024 reshaped the competitive landscape. Keyfactor strengthened its position through two acquisitions in 2025. The CA/Browser Forum's decision to reduce public TLS certificate lifetimes to 47 days by 2029 has made automated certificate lifecycle management a strategic imperative rather than an operational nice-to-have.

This guide maps the major CLM vendors, their products, and their capabilities. It then breaks down the seven licensing models in the market and provides practical guidance on evaluating total cost of ownership. For the fundamentals of what CLM is and why it matters, see our companion guide: What is Certificate Lifecycle Management?.

Defining Your Requirements Before You Evaluate

Before comparing vendors, you need to understand your own environment. The following questions should shape your evaluation:

Certificate estate size and growth: how many certificates are under management today? What is the projected growth over one, three, and five years? Environments with 5,000 certificates have fundamentally different requirements from those with 500,000.

Certificate types: do you need to manage public TLS certificates, internal PKI certificates, device certificates, code signing certificates, S/MIME, or machine identities? Not every platform handles all types equally.

CA landscape: which Certificate Authorities do you use today? Do you operate Microsoft AD CS, EJBCA, or another private CA? Do you use multiple public CAs? A platform that only integrates with its own CA creates vendor lock-in.

Deployment model: do you need on-premises, SaaS, hybrid, or air-gapped deployment? Defence and government environments often require on-premises or air-gapped capability.

Integration requirements: what systems does the CLM platform need to connect with? Consider SIEM, ITSM (ServiceNow), PAM, HSMs, DevOps pipelines, Kubernetes, and cloud providers.

Protocol support: which certificate management protocols does your environment require? ACME for web automation, EST for device enrolment, CMP for telecom/government, SCEP for Microsoft/MDM?

PQC readiness: does the platform support post-quantum cryptography algorithms and provide cryptographic discovery capabilities for migration planning?

Vendor Product Map: Who Provides What

The following section maps the major CLM vendors, their core products, and their key strengths and limitations.

Venafi (CyberArk Certificate Manager)

The dominant enterprise CLM platform, acquired by CyberArk for $1.54 billion in 2024. The product is being rebranded as CyberArk Certificate Manager and integrated into CyberArk's identity security portfolio. Venafi offers TLS Protect (on-premises), TLS Protect Cloud (SaaS), and TLS Protect for Kubernetes (built on Jetstack's cert-manager).

Strengths: 200+ out-of-the-box integrations; proven at over one million certificates; FedRAMP authorised; the broadest discovery and automation ecosystem in the market; SSH key management and code signing governance.

Limitations: does not act as a CA itself; integration complexity is high with 3 to 6 months typical implementation; pricing is opaque and has increased since the CyberArk acquisition; product roadmap now driven by CyberArk's IAM strategy rather than pure PKI.

Keyfactor Command

The primary mid-market alternative to Venafi, with a dedicated CLM platform distinct from EJBCA (its CA software). Keyfactor acquired InfoSec Global and CipherInsights in 2025 for cryptographic discovery and PQC capabilities. Unsung is a Keyfactor partner and works extensively with Keyfactor Command.

Strengths: native EJBCA integration allowing certificate profile management directly within the Command UI; leading PQC readiness with ML-DSA and SLH-DSA support; advanced RBAC; customisable dashboards; ServiceNow integration included; on-premises, SaaS, Azure Marketplace, and air-gap deployment options.

Limitations: not a CA itself (requires EJBCA or a third-party CA); not yet FedRAMP authorised; proven scale ceiling around 500K certificates versus Venafi's 1M+; narrower integration ecosystem (50 to 80 native connectors versus 200+); implementation requires 2 to 4 months.

DigiCert Trust Lifecycle Manager

Built on the DigiCert ONE platform, this integrates CA-agnostic CLM with DigiCert's public trust CA issuance and private PKI services. DigiCert moved to a new unified seat-based licensing model in October 2025.

Strengths: CA-agnostic management (DigiCert CA, Microsoft CA, AWS Private CA, Google CAS); public and private trust from a single platform; UEM integration (Intune, JAMF); quantum-safe certificate support; strong for organisations standardising on DigiCert.

Limitations: SaaS-only with no on-premises deployment option; no air-gap support; per-certificate costs at enterprise scale are prohibitively expensive without DigiCert CA bundling; ACME automation limited to DV certificates; performance degradation reported at peak volumes.

Sectigo Certificate Manager (SCM)

A cloud-native, CA-agnostic CLM platform from Sectigo (formerly Comodo CA). Available as full enterprise SCM and an SMB-focused SCM Pro tier.

Strengths: CA-agnostic; strong ACME support with DNS-based DCV automation; cloud-native and highly scalable; SCM Pro provides flat-rate per-domain pricing for smaller organisations; recognised as a G2 CLM leader.

Limitations: limited on-premises deployment compared to Venafi and Keyfactor; less depth in enterprise ITSM/SIEM integrations; SCM Pro limited to DV/OV certificates; no code signing governance or SSH key management; less suited to very large (200K+) certificate estates.

Entrust PKI Hub

Launched in January 2025, Entrust PKI Hub is an all-in-one container-based virtual appliance bundling a high-throughput CA, CLM (CertHub), enrolment services, OCSP, timestamping, and CA gateway into a single deployment.

Strengths: complete PKI stack in a single appliance; container-based for easy scaling; post-quantum-ready architecture; centralised management console; good for organisations wanting a simplified deployment.

Limitations: newer product with less mature ecosystem and third-party integrations; limited Kubernetes and SIEM/ITSM integration documentation; licensing tiers (X-Small, Small, Medium) may constrain flexibility for rapidly scaling environments.

Certdog (Krestfield)

A UK-developed CA and CLM platform targeting SME to mid-enterprise organisations, with particular strength in Microsoft AD CS environments. Available with a free tier (limited by certificate count) and paid commercial tiers.

Strengths: creates root and intermediate CAs with CRL/OCSP services; direct AD CS and EJBCA integration; REST API for DevOps automation; supports AWS CloudHSM, Azure Key Vault, Google KMS; Windows, Linux, and container deployment; lower cost of entry than tier-1 platforms.

Limitations: lacks large enterprise integrations (no native ServiceNow, Splunk, SIEM connectors); smaller integration ecosystem; no native Kubernetes CLM; less suited to estates exceeding 100K certificates at high concurrency; no publicly communicated PQC roadmap.

Other Notable Platforms

AppViewX CERT+: enterprise CLM automation platform positioning itself as a centralised control plane across hybrid-cloud, multi-cloud, legacy, containers, and IoT environments. Strong workflow automation and crypto-agility features.

GlobalSign Atlas / LifeCycleX: built on GlobalSign's Atlas platform with a unique SAN-based licensing model designed for the 47-day certificate era. LifeCycleX launched in September 2025.

Nexus Certificate Manager: a mature multi-tenant PKI platform deployed across approximately 100 large organisations hosting roughly one billion certificates. Specialises in national eID, citizen identity, and government PKI.

HashiCorp Vault PKI: treats certificates as ephemeral, short-lived tokens generated on-demand via API. Ideal for Kubernetes, microservices, and DevOps but not designed for traditional long-lived certificate management.

AWS Private CA: managed CA service for issuing private certificates within the AWS ecosystem. Not an enterprise-wide CLM solution, but useful for AWS-native workloads.

Microsoft AD CS: free Windows Server role providing basic private PKI. Widely deployed but increasingly limited for hybrid and cloud environments, with no built-in CLM, minimal automation, and no central dashboard.

Capability Comparison Matrix

The following table provides a high-level comparison of core CLM capabilities across the major platforms.

PKI CLM Comparison Matrix

CLM Vendor Comparison 2026 - Head to Head Comparisons

Head-to-Head: Keyfactor Command vs Venafi

This is the comparison most enterprise buyers end up making. Both are CA-agnostic control planes. Neither is a CA in its own right. The practical question is not which platform is more capable in the abstract — it is whether your estate is large and complex enough to justify what Venafi costs to buy, implement and run. For most organisations, it is not.

Choose Keyfactor Command if

  • You run EJBCA, or plan to. Native integration lets you manage certificate profiles directly within the Command interface rather than operating two systems and reconciling between them. No competitor offers this depth of CA integration.
  • Post-quantum readiness is a live programme. ML-DSA and SLH-DSA support is in the product now. The InfoSec Global and CipherInsights acquisitions in 2025 added cryptographic discovery capability that goes beyond certificate inventory to algorithm, key and protocol visibility. This is currently the strongest PQC position in the CLM market.
  • You need air-gapped or on-premises deployment. Supported alongside SaaS and Azure Marketplace. Several major competitors offer no on-premises option at all.
  • Implementation timescale matters. Two to four months against Venafi's three to six. On a programme with a regulatory or contractual deadline, that gap is the difference between delivering and slipping.
  • You want predictable commercial terms. Base licence in the region of $50,000 to $100,000, against Venafi's $100,000 to $300,000, with per-certificate rates typically lower.
  • You want a PKI company. Keyfactor's roadmap is set by certificate and cryptographic requirements, not by a broader identity portfolio strategy.
  • Your operational team is small. Advanced RBAC, customisable dashboards and included ServiceNow integration mean a lean team can run it without a dedicated platform function.

Venafi is the better fit if

The profile Venafi suits is narrower than its market position suggests.

  • Your estate is genuinely approaching or beyond one million certificates. Venafi has the longest track record at that scale. Below roughly 500,000 the advantage does not materialise, and you are paying for headroom you will not use.
  • Your environment is unusually fragmented. The 200+ out-of-the-box integrations are the platform's real differentiator — but they exist because Venafi is deployed in estates with hundreds of distinct systems. If your integration list runs to a dozen, the breadth is not a benefit, it is a reason the implementation takes six months.
  • You have a dedicated PKI or platform engineering function. Venafi rewards investment in operating it. Organisations without that capability frequently deploy a fraction of what they have licensed.
  • You are consolidating on CyberArk. If certificate management is being folded into a wider identity security programme, the integration argument is real.

The honest summary

For the large majority of enterprises we assess, Keyfactor Command delivers the capability that will actually be used, at a lower total cost, on a shorter timeline, with a clearer position on post-quantum.

Venafi earns its place in a specific set of conditions: estates beyond half a million certificates, highly fragmented environments, a dedicated PKI function to operate it, or a strategic commitment to CyberArk. Outside those conditions, organisations buy it for the scale ceiling and the integration count, then run a mid-sized estate on a platform sized for something considerably larger — and pay for the difference in licence, professional services and elapsed time.

Establish your real certificate count and your real integration list before you shortlist. Those two numbers decide this comparison more reliably than any feature matrix.

Head-to-Head: DigiCert Trust Lifecycle Manager vs Sectigo Certificate Manager

Both are CA-agnostic, cloud-first platforms from organisations whose primary business is certificate issuance. The comparison usually comes down to deployment constraints and where your certificates are bought.

Choose DigiCert Trust Lifecycle Manager if

  • You already buy public trust certificates from DigiCert. Bundling materially changes the economics — unbundled per-certificate costs at enterprise scale are hard to justify.
  • You need public and private trust managed from one platform.
  • UEM integration matters. Intune and JAMF support is stronger than Sectigo's.
  • Seat-based licensing suits your shape. If you issue many certificates per endpoint, decoupling cost from certificate volume is an advantage, particularly at 47-day lifetimes.

Choose Sectigo Certificate Manager if

  • ACME automation is central to your approach. Sectigo's DNS-based domain control validation is stronger, and DigiCert's ACME support is limited to DV.
  • You are a smaller organisation. SCM Pro's flat-rate per-domain pricing is one of the more sensible options below enterprise scale.
  • Cost is the binding constraint and you do not need enterprise ITSM or SIEM depth.

What rules out both

  • On-premises or air-gapped deployment. Neither offers it. If that is a requirement, this comparison is moot — look at Keyfactor, Venafi or Entrust.
  • Code signing governance or SSH key management. Sectigo does not offer them.
  • Estates above roughly 200,000 certificates. Sectigo is less proven at that scale, and DigiCert has reported performance degradation at peak volumes.

The honest summary

DigiCert is the stronger platform if you are standardising on DigiCert as a CA. Sectigo is the better value option for mid-sized, automation-led, cloud-native estates. Neither is the right answer for a regulated on-premises environment.

Head-to-Head: AD CS with scripts vs a commercial CLM platform

Many organisations are not choosing between vendors. They are deciding whether to buy anything at all.

Microsoft AD CS is free, already deployed and issues certificates perfectly well. The gap is not issuance. It is everything around it: no discovery, no central inventory, no dashboard, no automated renewal beyond auto-enrolment on domain-joined Windows machines, no visibility of anything outside the domain.

Staying with AD CS and scripts is defensible when

  • Your estate is small, largely Windows and domain-joined, and auto-enrolment covers most of it.
  • You have few public TLS certificates and they are managed by a small, stable team.
  • There is no regulatory requirement to evidence cryptographic control.

It stops being defensible when

  • Certificates exist outside the Windows domain — Linux, appliances, cloud services, containers, operational technology. Auto-enrolment does not reach them.
  • The scripts have a single author. This is the most common failure we encounter, and it surfaces when that person leaves.
  • You cannot answer "how many certificates do we have" with confidence.
  • You have a post-quantum obligation. Migration requires a cryptographic inventory that AD CS does not produce.
  • Public TLS lifetimes drop to 47 days and your manual process multiplies eightfold.

The honest summary

The cost of AD CS is not zero, it is just not on a licence line. It is engineering hours, key-person risk and the outages you have not had yet. Model those against a commercial licence before assuming the free option is cheaper. For some organisations it genuinely is.

Head-to-Head: Certdog vs Microsoft AD CS

If the previous section applies to you, this is the comparison that follows it. Most organisations outgrowing AD CS assume the next step is a six-figure enterprise platform. For mid-sized, Microsoft-centric estates it usually is not.

Certdog, developed by UK vendor Krestfield, occupies a position nothing else in this comparison does. It is a Certificate Authority and a certificate lifecycle management platform in one product. Keyfactor, Venafi, DigiCert and Sectigo all require a CA underneath them. Certdog can be the CA, or sit in front of the CA you already have.

What AD CS gives you

  • Certificate issuance, at no licence cost, already deployed.
  • Auto-enrolment for domain-joined Windows machines.
  • Template-based policy within the Windows domain.

That is the complete list. AD CS is an issuance engine. It was never designed to be a management platform, and it does not pretend to be one.

What Certdog adds on top

  • It connects to your existing AD CS rather than replacing it. This is the critical point. You are not ripping out a working CA — you are putting management, automation and visibility in front of it. Existing Microsoft CA keys and certificates can be imported.
  • Discovery. Network TLS scanning finds certificates across the estate and imports them into a central inventory, including systems that were never domain-joined and therefore never appeared in AD CS.
  • A central console and searchable inventory. Every certificate, its status, its expiry, in one place. AD CS has no equivalent.
  • Expiry alerting and managed renewal across the whole estate, not only the machines auto-enrolment reaches.
  • Automation beyond the Windows domain. A full REST API, with PowerShell, .NET and Java clients. Linux servers, appliances, non-domain-joined systems and DevOps pipelines all become addressable without group policy changes.
  • Its own CAs where you need them. Unlimited root and intermediate CAs, multiple hierarchies, CRL and OCSP enabled directly. Useful where AD CS is the wrong trust anchor for a given use case.
  • EJBCA support as well as AD CS, so a future CA migration does not mean a platform migration.
  • Flexible key protection. PKCS#11 HSMs, Azure Key Vault, Google KMS, YubiHSM 2 or software key stores.
  • Deploys on Windows, Linux or as a container, in minutes rather than months.

Where Certdog is the right answer

  • Your estate is AD CS-centric, and the problem is management rather than issuance.
  • You have certificates outside the Windows domain that auto-enrolment has never covered.
  • You need a defensible certificate inventory for audit, and currently have a spreadsheet.
  • Budget will not support a tier-one platform, and the alternative on the table is doing nothing.
  • You want to prove the value of CLM before asking for capital. The free tier makes a real pilot possible without a procurement cycle.
  • You need on-premises deployment and UK-based support. Certdog is UK-developed and UK-supported, which matters where sovereignty or data residency appears in the requirements.

Where it stops being the right answer

  • Estates beyond roughly 100,000 certificates at high concurrency.
  • You need native ServiceNow, Splunk or SIEM connectors. Certdog's API will integrate, but the work is yours.
  • You need native Kubernetes certificate management.
  • Post-quantum migration is a near-term programme with a published roadmap requirement.

The honest summary

The choice facing most AD CS organisations is not Certdog against Keyfactor. It is Certdog against another two years of scripts and spreadsheets, because the enterprise platforms priced themselves out of the conversation before it started.

Certdog closes the gap that matters — discovery, inventory, alerting and automation across the whole estate — while leaving the CA you already run in place. It will not carry a 500,000-certificate global enterprise. It was not built to. What it does is make certificate management achievable for the large number of organisations that have been told the only options are free and unmanaged, or six figures and eighteen months.

Unsung works closely with Krestfield and deploys Certdog across UK public and private sector environments. More detail on the Certdog platform and our partnership.

Which CLM Platform Fits Your Organisation

Platform capability only matters relative to your environment. These are the profiles we encounter most often and where each typically lands.

Profile 1: Mid-sized enterprise, 5,000 to 20,000 certificates, mostly Microsoft

Typical shape

AD CS in place, a handful of public TLS certificates from one or two CAs, growing cloud footprint, small infrastructure team, no dedicated PKI function.

Usually lands on

Keyfactor Command, Sectigo SCM, or Certdog depending on budget.

What to weigh

At this scale per-certificate pricing is still affordable, so licensing model matters less than implementation effort. Certdog is worth serious consideration if the estate is AD CS-centric and you do not need ServiceNow or SIEM integration — the cost difference against tier-one platforms is substantial. Discount it if you expect to exceed 100,000 certificates or need a published PQC roadmap.

Most common mistake

Buying enterprise capability for an estate that does not need it, then using perhaps a third of the platform.

Profile 2: Large hybrid enterprise, 200,000+ certificates

Typical shape

Multiple CAs public and private, on-premises and multi-cloud, Kubernetes in production, existing SIEM and ServiceNow, distributed application teams.

Usually lands on

Keyfactor Command in most cases. Venafi where the estate is approaching one million certificates or the integration list runs to hundreds of systems.

What to weigh

Proven scale and integration breadth are the deciding factors, and both need testing against your actual numbers rather than your projected ones. Stress-test per-certificate pricing against 47-day renewal frequency before signing — a model that works at 398-day validity may not survive the transition. Where deployment must be on-premises or air-gapped, the shortlist narrows immediately.

Most common mistake

Selecting on the demo environment rather than on the hardest 20% of the estate. The legacy systems and appliances are where deployments stall.

Profile 3: Defence, government or any air-gapped environment

Typical shape

Segregated or fully air-gapped networks, on-premises mandatory, cleared personnel required, strict assurance and accreditation requirements.

Usually lands on

Keyfactor Command or Entrust PKI Hub. EJBCA where a CA is also required.

What to weigh

Deployment model eliminates most of the market immediately. DigiCert and Sectigo are SaaS-only and therefore out. Entrust PKI Hub is attractive where you need CA and CLM together in a single accredited appliance, though the ecosystem is newer and third-party integration documentation is thinner. Confirm FedRAMP or equivalent assurance requirements early — it is a genuine constraint in some US-linked programmes and an assumed one in many others.

Most common mistake

Leaving the accreditation conversation until after platform selection. It should be the first filter, not the last.

Profile 4: DevOps-first, cloud-native, container-heavy

Typical shape

Kubernetes in production, short-lived workloads, infrastructure as code, certificates issued and discarded continuously, engineering owns security tooling.

Usually lands on

HashiCorp Vault PKI or cert-manager for the workload layer, with a commercial CLM above it for everything else.

What to weigh

This is rarely a single-platform answer. Vault and cert-manager handle ephemeral certificates well, but neither provides enterprise discovery, governance or reporting across the wider estate. The realistic architecture is Vault or cert-manager for workloads, with a commercial platform providing visibility and policy across the whole environment. Keyfactor, Venafi and AppViewX all address this layer; the deciding factor is usually what the rest of your estate looks like, not the container platform.

Most common mistake

Assuming that because the container estate is solved, the estate is solved. The certificates that cause outages are usually on the systems nobody automated.

Profile 5: Cost-constrained, technically capable, small team

Typical shape

Limited budget, strong engineering, tolerance for self-managed infrastructure, no procurement appetite for a six-figure licence.

Usually lands on

EJBCA Community with cert-manager, or Certdog's free tier.

What to weigh

Licence cost is zero but total cost of ownership is not. Budget the engineering time for implementation, maintenance, upgrades and integration, and be honest about who owns it when that engineer moves on. There are no enterprise SLAs. Where open source works well is organisations with genuine in-house capability and a low tolerance for vendor lock-in. Where it fails is organisations that chose it purely on price.

Most common mistake

Counting the licence saving and not the operational cost. In several environments we have assessed, the fully loaded cost exceeded a commercial platform.

CLM Licensing Models Explained

CLM licensing varies significantly across vendors. Choosing the wrong model can result in costs escalating dramatically as certificate volumes grow, particularly as shorter certificate lifetimes drive up renewal frequency. There are seven distinct models in the market today.

1. Per-Certificate Pricing

Organisations are charged based on the number of certificates under active management per year, typically on top of a base platform licence. This is the most traditional model, used by Venafi (estimated $1 to $8 per certificate plus $100K to $300K base), Keyfactor Command (estimated $1 to $5 per certificate plus $50K to $100K base), and Sectigo SCM at enterprise scale.

Per-certificate pricing works well for small estates but becomes problematic as volumes grow. An estate of 50,000 certificates at $5 per certificate means $250,000 per year in certificate charges alone, before the base licence. The move to 47-day TLS certificates increases renewal frequency eightfold, making this model increasingly unsustainable for many organisations. It also encourages shadow IT, with teams avoiding registering certificates to dodge cost allocation.

2. Seat-Based / Per-User / Per-Device Licensing

Licences are purchased per user, device, or server endpoint, decoupled from certificate volume. DigiCert Trust Lifecycle Manager uses this model (since October 2025), with three subscription tiers, each using a unified seat licence consumed per server, site, or user.

This model provides predictable costs in stable-headcount environments and does not penalise organisations for issuing multiple certificates per endpoint. However, costs scale with headcount growth, and it can still be expensive at enterprise scale for large device inventories.

3. Platform / Component Licensing

Organisations pay a base platform fee with additional charges for individual feature modules. Keyfactor Command uses this approach, where your licence may not include all features and additional components can be added later. Entrust PKI Hub offers three appliance tiers (X-Small, Small, Medium) with a separate certificate volume layer.

Component licensing lets organisations pay for what they use and add features incrementally. The downside is that total cost is difficult to predict without understanding future requirements, and discovering that a needed feature requires a higher licence tier creates unwelcome surprises during procurement.

4. SAN-Based / Domain-Based Licensing

Rather than pricing per certificate, this model charges based on the number of unique Subject Alternative Names (SANs) or FQDNs in use. Multiple certificates covering the same SAN do not increase cost. GlobalSign's SAN Licensing model is the most notable example, explicitly designed for the 47-day certificate era. Sectigo SCM Pro also uses per-domain flat-rate plans for its SMB tier.

SAN-based licensing is future-proofed for short-lived certificates, because reissuing a certificate every 47 days does not increase the licence cost. It is straightforward for organisations managing a defined set of domains. However, it is less flexible for dynamic environments where SAN counts change frequently and may not cover internal PKI certificates.

5. Flat-Fee / Unlimited Subscription

A single annual fee covering unlimited certificate management, regardless of volume, type, or renewal frequency. Garantir launched this model in March 2026 at $99,000 per year for unlimited CLM and $25,000 per year for private PKI, with no cap on certificates, users, or teams.

Flat-fee licensing provides complete cost predictability and encourages full coverage, as every certificate can be monitored without cost penalty. It directly addresses the 47-day certificate challenge. The trade-off is a higher upfront cost for small estates, and Garantir is a newer market entrant with a less established track record than Venafi or Keyfactor.

6. Open Source / Infrastructure Cost Only

The software is free; organisations pay for infrastructure, optional enterprise support, and professional services. EJBCA Community (LGPL), HashiCorp Vault (self-hosted), cert-manager (Kubernetes), and Certdog's free tier all follow this model.

Zero licence cost and high flexibility are the clear advantages. However, the total cost of ownership can exceed commercial platforms when engineering time for implementation, maintenance, and integration is factored in. Community editions lack enterprise SLAs and vendor-backed support.

7. Per-CA / Usage-Based Cloud Pricing

Charges based on the number of Certificate Authorities operated and certificates issued, billed monthly. AWS Private CA uses this model at $400 per CA per month (general-purpose) or $50 per CA per month (short-lived, 7 days or less), plus tiered per-certificate fees.

This works for AWS-native environments with a pay-as-you-grow model and no upfront capital expenditure. However, CA operational costs are fixed regardless of usage, per-certificate costs at scale can exceed commercial CLM platforms, and you are locked into the cloud vendor ecosystem.

Licensing Model Comparison

PKI CLM Licensing Model

Understanding Total Cost of Ownership

Licence fees are only part of the picture. When evaluating CLM platforms, organisations should account for:

Implementation and professional services: enterprise CLM implementations typically require two to six months and significant vendor or partner professional services. Venafi implementations tend toward the longer end (three to six months), Keyfactor toward the shorter (two to four months).

Training and onboarding: platform-specific training for security, infrastructure, and operations teams.

Integration costs: connecting the CLM platform to SIEM, ITSM, PAM, HSM, and DevOps systems often requires custom configuration.

Ongoing operations: monitoring, maintenance, support renewals, and platform upgrades.

47-day certificate impact: per-certificate pricing models should be stress-tested against eight times the current renewal frequency. A cost that looks manageable at 398-day validity may become unsustainable at 47 days.

How to Run a CLM Proof of Concept

Most CLM selections are decided on a vendor-controlled demonstration. That demonstration is built to succeed. A proof of concept in your own environment is the only reliable way to find out what you are buying.

Scope it against your hardest systems

Vendors will propose a POC against clean, modern, well-documented infrastructure. Insist on the opposite.

Include:

  • At least one legacy application nobody wants to touch.
  • An appliance or device with no ACME support.
  • A system on a segregated network with no route to public OCSP or CRL endpoints.
  • A service owned by a team outside the group running the POC.

If the platform handles those, it will handle the easy systems. The reverse is not true.

Test discovery honestly

Run discovery before you tell the vendor what is in the estate. Then compare their result against your own records.

What matters:

  • How many certificates were found that you did not know about.
  • Whether discovery reached non-domain-joined systems, cloud services and operational technology.
  • How long a full scan takes, and what load it places on the network.
  • Whether it identifies issuing CA, algorithm and key length, or only hostname and expiry.

Test renewal to completion

Issuance demonstrates well. Renewal is where deployments fail.

A renewal is only complete when the application is serving the new certificate. That usually requires a service restart or configuration reload. Confirm the platform handles that step, for your applications, without manual intervention — and confirm what happens when it fails. Silent failure is worse than no automation, because it removes the expectation of a manual check.

Test failure, not just success

  • Revoke a certificate and time the propagation.
  • Break a renewal deliberately and see whether anyone is alerted, and how quickly.
  • Take the issuing CA offline and observe the platform's behaviour.
  • Simulate an expiry on a non-critical system and watch the alerting chain end to end.

Model the cost against 47-day lifetimes

Ask every vendor to price your estate at current volumes and at eight times the renewal frequency. Get it in writing. Under per-certificate models the difference can be substantial, and it is far easier to negotiate before signature than at renewal.

What derails proofs of concept

From deployments we have run, the recurring causes are:

  • Ownership, not technology. The POC stalls because nobody can identify who owns a given system or authorise a change to it. This is a governance problem the platform cannot solve.
  • Change control. In regulated and safety-critical environments, the POC schedule assumes changes can be made in days. They cannot.
  • Undocumented certificate use. A certificate turns out to be pinned, embedded in an application, or referenced by a downstream system nobody knew about.
  • Scope creep into production. The POC quietly becomes the deployment, without the design work that should have sat between them.

Budget four to six weeks for a meaningful POC. Anything shorter tests the demonstration, not the platform.

Lock-In, Portability and Exit

Few buyers ask about exit during selection. It is worth ten minutes, because the answers vary considerably.

Questions to put to every vendor

  • Can we export the complete certificate inventory, including metadata, ownership and history, in a documented open format?
  • Are automation workflows portable, or are they proprietary configuration that would need rebuilding?
  • If the contract ends, what happens to certificates the platform issued or manages? Do they continue to function?
  • Where the vendor is also our CA, what is the cost and timeline to move issuance elsewhere?
  • Who holds the private keys, and where? For SaaS platforms, in which jurisdiction?

Where lock-in typically originates

  • CA and CLM from the same vendor. Bundled pricing makes the platform affordable and makes leaving expensive. This is the most common form of lock-in in the market, and it is not always visible at signature.
  • Proprietary automation. Integration work is rarely portable. Two years of workflow configuration is a real switching cost even when the data exports cleanly.
  • Cloud-native CA services. AWS Private CA and equivalents tie the trust hierarchy to a single cloud provider.
  • Platform acquisition. Roadmaps change after acquisition. The Venafi and CyberArk transition is the current example, and it will not be the last.

Reducing exposure

  • Keep the CA decision separate from the CLM decision wherever the economics allow.
  • Maintain your own copy of the certificate inventory, exported on a schedule, independent of the platform.
  • Document automation workflows outside the vendor's configuration.
  • Treat CA-agnostic support as a genuine requirement rather than a checkbox — and verify it in the POC against a CA the vendor does not own.

How Unsung Supports CLM Selection and Implementation

Unsung is a vendor-neutral PKI consultancy that helps organisations evaluate, select, and implement CLM platforms. We do not resell CLM software on commission, so our recommendations are driven by your requirements, not vendor margins.

Our certificate lifecycle management services include:

CLM readiness assessment: we evaluate your current certificate estate, management processes, and infrastructure to define requirements and inform platform selection.

Vendor evaluation support: we help you compare platforms against your specific requirements, run proof-of-concept evaluations, and negotiate with vendors.

Implementation and integration: we deliver end-to-end CLM implementation, including discovery configuration, automation workflows, policy setup, and integration with your security tooling.

Migration from legacy systems: we specialise in migrating organisations from manual processes or from platforms like AD CS to modern CLM solutions.

Ongoing advisory: we provide continuing support for CLM operations, platform upgrades, and preparation for 47-day certificate lifetimes and post-quantum cryptography transitions.

Our consultants hold SC and DV security clearance and deliver across central government, defence, financial services, healthcare, and transport. Get in touch to discuss your CLM evaluation or implementation.

Frequently Asked Questions

What are the major CLM platforms available?

Major CLM platforms include Venafi (CyberArk Certificate Manager) managing over one million certificates with 200+ integrations, Keyfactor Command with native EJBCA integration, DigiCert Trust Lifecycle Manager with seat-based licensing, Sectigo Certificate Manager for cloud-native environments, Entrust PKI Hub as a container-based appliance, and Certdog for Microsoft AD CS environments.

What licensing models are available for CLM platforms?

Seven licensing models exist: per-certificate pricing ($1-$8 per certificate annually), seat-based licensing tied to users or devices, platform/component pricing with base fees plus module charges, SAN-based/domain pricing for 47-day certificates, flat-fee subscription for unlimited certificates, open source with infrastructure costs, and per-CA usage-based cloud pricing.

What criteria should organisations evaluate when selecting a CLM vendor?

Organisations should assess certificate estate size and types, CA landscape, deployment models, integration needs, protocol support, and post-quantum cryptography readiness before selection. Understanding total cost of ownership across different licensing models is essential for making the right choice.

How has the CLM vendor landscape changed recently?

The landscape has evolved significantly with CyberArk acquiring Venafi for $1.54 billion in 2024, DigiCert introducing new seat-based licensing in October 2025, and Entrust launching a container-based PKI Hub appliance in January 2025. These changes reflect growing enterprise demand for integrated certificate management solutions.
Author
Darren Davies - CEO, Unsung Limited
September 10, 2026
-
10 minute read