What Is CLM (Certificate Lifecycle Management)?

Also called: Certificate management

Related problems: A website or app went down because a certificate expired; Nobody knows how many certificates we have or who owns them; Shorter certificate lifetimes mean renewing far more often; Certificates bought on personal cards from different authorities with no central control

Certificate lifecycle management (CLM) is the practice, and the software, an organization uses to keep track of its digital certificates and manage each one from request to retirement: discovering where certificates are, issuing them, deploying them to the right servers and devices, renewing them before they expire and revoking them when they are no longer trusted. Certificates underpin encrypted connections and machine identity across websites, applications, devices and cloud services, so losing track of them leads to outages and security gaps.

At a glance

  • CLM covers the full life of a certificate: discovery, request, issuance, deployment, renewal, revocation and reporting.
  • It applies to public TLS certificates for websites and often to internal certificates for servers, devices, Wi-Fi and VPN.
  • Shorter maximum lifetimes for public TLS certificates are making automated renewal the expected norm.
  • Many platforms can renew their own certificates; CLM tools add a central inventory, policy and automation across many systems and authorities.
  • Expired or forgotten certificates are a common cause of avoidable outages.

What problem it solves

Encrypted websites, APIs, load balancers, VPN gateways and many devices rely on certificates, and every certificate expires. In many organizations, certificates were bought by different teams from different authorities, installed by hand and tracked in a spreadsheet, if at all. When one expires unnoticed, the service it protects stops working for users or breaks an integration, often at an awkward time and with a frantic search for who owns it. The same lack of visibility hides weak or unapproved certificates and makes it slow to replace certificates in bulk if an authority is distrusted or a key is exposed.

The problem is growing. Publicly trusted Transport Layer Security (TLS) certificates are moving to much shorter maximum lifetimes, which multiplies how often each one must be renewed. Machine identities such as certificates for workloads and devices are also multiplying, and they are a large share of non-human identities. CLM gives organizations an inventory, ownership and automation so renewals happen without people having to remember them.

How it works

Discovery. The CLM tool finds certificates by scanning networks and ports, connecting to certificate authorities, cloud accounts, load balancers and key stores, and, in some products, monitoring public certificate transparency logs for certificates issued for your domains.

Inventory and policy. Certificates are recorded with owner, location, issuer, expiry and key strength. Administrators set policy, such as approved authorities, key types and maximum lifetimes, and the tool flags anything that breaks it.

Issuance and renewal. The tool requests certificates from public authorities and from internal public key infrastructure (PKI), commonly using standard protocols such as ACME. Renewal can be triggered automatically well ahead of expiry.

Deployment. Agents or integrations install renewed certificates on web servers, load balancers, cloud services and devices, and restart services where needed. Systems that can’t be automated generate tasks for their owners.

Revocation and reporting. Compromised or unneeded certificates are revoked and replaced. Dashboards and alerts show upcoming expirations, policy violations and audit evidence.

When it matters for buyers

  • After a certificate outage. One expired certificate in production is often what starts the project.
  • As public TLS lifetimes shrink. Manual renewal workloads grow with each step down, so plan automation before the shorter limits apply.
  • When certificates are scattered. Several authorities, teams and clouds without a central view make outages and audit findings likely.
  • When managing many devices. Network equipment, IoT devices and laptops using certificate-based authentication need lifecycle control.
  • When auditors ask about encryption controls. An inventory and policy show how keys and certificates are governed. See our governance, risk and compliance overview.

Questions to ask vendors

  • How do you discover certificates, and can you find ones we don’t know about?
  • Which public and private certificate authorities do you integrate with?
  • Which servers, load balancers, cloud services and devices can you renew and deploy to automatically?
  • Do you support ACME and other standard enrollment protocols?
  • How do you handle systems that can’t be automated?
  • Can you replace certificates in bulk if an authority is distrusted or a key is exposed?
  • Is the platform priced per certificate, per managed endpoint or another way?

How it differs from PKI

Public key infrastructure (PKI) is the system that creates trust: certificate authorities, keys, policies and the processes that issue and verify certificates. CLM is the management layer that keeps track of the certificates PKI produces and makes sure each one is deployed, renewed and retired correctly, whether it came from a public authority or your internal PKI. An organization can run PKI without CLM, but it then relies on people or individual systems to manage renewals. Some PKI products include CLM features, and some CLM vendors also offer certificate authority services. Secure Sockets Layer (SSL), still a common name for these certificates, is the older protocol replaced by TLS.

Frequently Asked Questions

Why are certificate lifetimes getting shorter?
Browser makers and certificate authorities, through the CA/Browser Forum, adopted a schedule in 2025 that steps down the maximum lifetime of publicly trusted TLS certificates over several years, toward 47 days. Shorter lifetimes limit how long a compromised or wrong certificate stays valid. Check the current schedule, because the practical result is that manual renewal stops being realistic for most organizations.
Do we need a CLM tool if our certificates renew automatically?
Maybe not for everything. Many cloud platforms, load balancers and web servers can renew certificates automatically using the ACME protocol. A CLM tool helps when you have certificates from several authorities, internal certificates, devices that can't automate themselves, or no central view of what you have and who owns it.
Does CLM cover internal certificates?
It can. Many CLM tools manage certificates issued by your own internal certificate authority as well as public ones, including certificates for devices, Wi-Fi, VPN and servers. Coverage varies by product, so confirm which certificate authorities and certificate types are supported.
What happens when a certificate expires?
Browsers and applications stop trusting the connection, so users see security warnings, apps fail to connect, and integrations between systems can break. Expired certificates are a common cause of avoidable outages, including for large organizations.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.