CertCentral and Trust Lifecycle Manager: understanding DigiCert certificate management options
DigiCert offers multiple products for certificate and digital trust management. CertCentral and Trust Lifecycle Manager solve related but different certificate management problems. DigiCert ONE is the broader digital-trust platform and product suite that includes Trust Lifecycle Manager and other DigiCert trust solutions.
- CertCentral — Primary role: DigiCert platform for managing public trust certificate products and related lifecycle workflows. Key functionality: Order, validate, approve, renew, report on, and automate supported DigiCert public-trust certificate workflows.
- Trust Lifecycle Manager — Primary role: Enterprise certificate lifecycle management and PKI services with CA-agnostic discovery, inventory, policy, automation, and integrations. Key functionality: Govern and automate certificates across multiple CAs, public and private trust, servers, appliances, cloud platforms, vaults, and business units.
- DigiCert ONE — Primary role: Broader DigiCert digital-trust product suite and platform. Key functionality: Use TLM and other specialized DigiCert services for private PKI, software trust, device trust, content trust, and related digital trust use cases.
CertCentral
CertCentral is DigiCert's platform for managing digital certificates and certificate lifecycle workflows. It supports public TLS/SSL, Verified Mark, Code Signing, Document Signing, Client, and S/MIME certificates and centralizes certificate requests, approvals, renewals, validation, reporting, automation, and access control.
CertCentral remains a core platform for DigiCert public trust certificate issuance and management, and supports standards-based ACME and API automation.
Note: DigiCert is retiring CertCentral Managed Automation and CertCentral Discovery on October 1, 2026. Customers who need those managed discovery and automation capabilities after that date should use Trust Lifecycle Manager. This retirement does not remove CertCentral certificate orders or its standards-based ACME and API automation capabilities.
When CertCentral may be a fit
- Your primary need is to order and manage DigiCert public trust certificates.
- You want to use supported standards-based ACME clients or APIs for certificate issuance and renewal workflows.
- You do not need enterprise-wide, CA-agnostic discovery, centralized certificate inventory, or managed automation across heterogeneous infrastructure.
Trust Lifecycle Manager
DigiCert Trust Lifecycle Manager (TLM) is a unified digital-trust solution that combines CA-agnostic certificate lifecycle management with PKI services. It is designed for organizations that need to discover, inventory, govern, automate, and monitor certificates across a heterogeneous enterprise environment rather than manage only a single issuing source or a limited set of endpoints.
Trust Lifecycle Manager can help organizations:
- Discover certificates across servers, networks, cloud environments, and connected platforms, and maintain a centralized inventory with ownership and operational context.
- Manage public and private trust certificates from DigiCert, and supported external issuing CAs through CA connectors.
- Apply centralized certificate profiles, policy, role-based controls, reporting, and governance across certificate sources and business units.
- Require certificate automation, including DigiCert agents for server-level automation, sensors for network-level discovery and integrations, ACME, APIs, enrollment protocols, and purpose-built connectors where supported.
- Integrate with network appliances, cloud services, DNS providers, certificate authorities, vaults, secrets-management platforms, IT service-management systems, and other enterprise tooling.
How CertCentral and Trust Lifecycle Manager work together
Trust Lifecycle Manager does not necessarily replace CertCentral. For DigiCert public trust certificates, CertCentral can remain the issuing platform while TLM provides the broader lifecycle-management layer.
- Certificate sources (issuance sources): DigiCert CertCentral, DigiCert Private CA, and supported external CAs.
- Trust Lifecycle Manager (lifecycle-management layer): centralized inventory, policy and profiles, discovery and automation, governance and reporting.
- Managed environments (deployment and discovery targets): servers, appliances / load balancers, cloud services, vaults and other integrations.
For DigiCert public-trust issuance, specifically, a CertCentral account is required, and a CA connector links CertCentral to the TLM account. DigiCert Private CA supports private certificate issuance, while supported third-party CAs can be connected through CA connectors.
What is DigiCert ONE?
DigiCert ONE is DigiCert's broader digital-trust product suite, not a third certificate management product or a replacement for CertCentral or TLM. Trust Lifecycle Manager is one of the services accessed through the DigiCert ONE ecosystem, alongside other DigiCert solutions for private PKI, software trust, device trust, content trust, and additional digital trust use cases.
Which DigiCert solutions should I evaluate?
- Order and manage DigiCert public-trust certificates — CertCentral.
- Automate supported public-trust certificate workflows using standards-based ACME or APIs — CertCentral may be sufficient; Trust Lifecycle Manager is preferred.
- Discover and inventory certificates across enterprise infrastructure — Trust Lifecycle Manager.
- Manage public and private certificates from multiple CA sources — Trust Lifecycle Manager.
- Apply centralized lifecycle policy, ownership, governance, and reporting — Trust Lifecycle Manager.
- Automate certificates across servers, appliances, cloud services, vaults, and other integrated platforms — Trust Lifecycle Manager, using the appropriate supported automation pattern.
- Manage specialized digital trust use cases beyond enterprise certificate lifecycle management — the relevant DigiCert ONE service.