Certificate lifecycle management (CLM) is the practice, and the software, an organization uses to keep track of its digital certificates and manage each one from request to retirement: discovering where certificates are, issuing them, deploying them to the right servers and devices, renewing them before they expire and revoking them when they are no longer trusted. Certificates underpin encrypted connections and machine identity across websites, applications, devices and cloud services, so losing track of them leads to outages and security gaps.
At a glance
- CLM covers the full life of a certificate: discovery, request, issuance, deployment, renewal, revocation and reporting.
- It applies to public TLS certificates for websites and often to internal certificates for servers, devices, Wi-Fi and VPN.
- Shorter maximum lifetimes for public TLS certificates are making automated renewal the expected norm.
- Many platforms can renew their own certificates; CLM tools add a central inventory, policy and automation across many systems and authorities.
- Expired or forgotten certificates are a common cause of avoidable outages.
What problem it solves
Encrypted websites, APIs, load balancers, VPN gateways and many devices rely on certificates, and every certificate expires. In many organizations, certificates were bought by different teams from different authorities, installed by hand and tracked in a spreadsheet, if at all. When one expires unnoticed, the service it protects stops working for users or breaks an integration, often at an awkward time and with a frantic search for who owns it. The same lack of visibility hides weak or unapproved certificates and makes it slow to replace certificates in bulk if an authority is distrusted or a key is exposed.
The problem is growing. Publicly trusted Transport Layer Security (TLS) certificates are moving to much shorter maximum lifetimes, which multiplies how often each one must be renewed. Machine identities such as certificates for workloads and devices are also multiplying, and they are a large share of non-human identities. CLM gives organizations an inventory, ownership and automation so renewals happen without people having to remember them.
How it works
Discovery. The CLM tool finds certificates by scanning networks and ports, connecting to certificate authorities, cloud accounts, load balancers and key stores, and, in some products, monitoring public certificate transparency logs for certificates issued for your domains.
Inventory and policy. Certificates are recorded with owner, location, issuer, expiry and key strength. Administrators set policy, such as approved authorities, key types and maximum lifetimes, and the tool flags anything that breaks it.
Issuance and renewal. The tool requests certificates from public authorities and from internal public key infrastructure (PKI), commonly using standard protocols such as ACME. Renewal can be triggered automatically well ahead of expiry.
Deployment. Agents or integrations install renewed certificates on web servers, load balancers, cloud services and devices, and restart services where needed. Systems that can’t be automated generate tasks for their owners.
Revocation and reporting. Compromised or unneeded certificates are revoked and replaced. Dashboards and alerts show upcoming expirations, policy violations and audit evidence.
When it matters for buyers
- After a certificate outage. One expired certificate in production is often what starts the project.
- As public TLS lifetimes shrink. Manual renewal workloads grow with each step down, so plan automation before the shorter limits apply.
- When certificates are scattered. Several authorities, teams and clouds without a central view make outages and audit findings likely.
- When managing many devices. Network equipment, IoT devices and laptops using certificate-based authentication need lifecycle control.
- When auditors ask about encryption controls. An inventory and policy show how keys and certificates are governed. See our governance, risk and compliance overview.
Questions to ask vendors
- How do you discover certificates, and can you find ones we don’t know about?
- Which public and private certificate authorities do you integrate with?
- Which servers, load balancers, cloud services and devices can you renew and deploy to automatically?
- Do you support ACME and other standard enrollment protocols?
- How do you handle systems that can’t be automated?
- Can you replace certificates in bulk if an authority is distrusted or a key is exposed?
- Is the platform priced per certificate, per managed endpoint or another way?
How it differs from PKI
Public key infrastructure (PKI) is the system that creates trust: certificate authorities, keys, policies and the processes that issue and verify certificates. CLM is the management layer that keeps track of the certificates PKI produces and makes sure each one is deployed, renewed and retired correctly, whether it came from a public authority or your internal PKI. An organization can run PKI without CLM, but it then relies on people or individual systems to manage renewals. Some PKI products include CLM features, and some CLM vendors also offer certificate authority services. Secure Sockets Layer (SSL), still a common name for these certificates, is the older protocol replaced by TLS.
