What Is Certificate Lifecycle Management (CLM)?

Certificate lifecycle management (CLM) is the process of finding, tracking, issuing, renewing and revoking every digital certificate an organization uses. Its goal is that no certificate expires by surprise and no certificate is weak, unknown or without an owner.

Why certificates need managing

Every digital certificate has an end date. When it expires, browsers, apps and devices stop trusting it. Services go down and users see security warnings.

A large organization can have a very high number of certificates. They come from several certificate authorities (CAs) and sit on web servers, load balancers, cloud services, containers, network devices and IoT devices.

Different teams request them, and often nobody has the full list. This is how many certificate outages start.

The certificate lifecycle, step by step

  1. Discovery: scan networks, cloud accounts and CA records to find every certificate.
  2. Inventory: record each certificate with its owner, issuer, expiry date, key type and location.
  3. Request and approval: check each request against policy, such as allowed CAs, key sizes and lifetimes.
  4. Issuance: the CA signs and issues the certificate.
  5. Deployment: install the certificate and its key on the right server or device.
  6. Monitoring: track expiry dates, weak algorithms and policy breaks, and alert the owner.
  7. Renewal or replacement: issue a new certificate before the old one ends, and deploy it.
  8. Revocation: cancel a certificate at once if its key is exposed or it is no longer needed.
  9. Retirement: remove old certificates and keys safely.

Shorter certificate lifetimes

In April 2025 the CA/Browser Forum approved Ballot SC-081. It cuts the maximum lifetime of publicly trusted TLS certificates in steps:

  • 200 days from March 15, 2026 (already in force)
  • 100 days from March 15, 2027
  • 47 days from March 15, 2029

At 47 days, each public certificate must be renewed about eight times a year. Spreadsheets and calendar reminders do not scale to this, so automation becomes the only safe option.

Automation protocols

CLM tools use standard protocols so machines can request and renew certificates without people:

  • ACME (RFC 8555): automated issuance and renewal, widely used for TLS certificates.
  • SCEP (RFC 8894): an older protocol, common for mobile devices, network equipment and device management tools.
  • EST (RFC 7030): certificate enrollment over a secure TLS connection, for devices and enterprise clients.
  • REST APIs and connectors: for CAs, cloud platforms, Kubernetes and CI/CD pipelines.

CLM is not the same as a CA

A CA issues certificates. A CLM platform manages certificates from many CAs, public and private, in one place. You can add CLM on top of the CAs you already have; you do not need to replace them. For how CAs fit into the bigger picture, see what PKI is.

What good CLM gives you

  • Fewer outages: owners get warnings, and renewals happen on time.
  • Better security: you find weak keys, old algorithms and certificates nobody knew about.
  • Audit evidence: a record of who requested, approved and installed each certificate.
  • Crypto agility: a full inventory shows which certificates use which algorithms. This is the first step in planning a move to post-quantum cryptography.

How DictaLabs helps

Certinium CLM discovers certificates across enterprise, cloud, network, application and device environments. It keeps one inventory with owner, issuer, environment, status and lifecycle details.

It automates certificate enrollment, renewal, replacement, rotation and revocation, with alerts before expiry or policy breaks. It supports ACME, SCEP, EST and REST APIs.

Certinium CLM is CA-agnostic. It works with Microsoft Active Directory Certificate Services (ADCS), EJBCA, DictaLabs CA and other enterprise, public, private and cloud CAs, without replacing them. Its integration framework is designed to support Kubernetes and cert-manager, Terraform, Ansible, Jenkins, GitHub, GitLab, ServiceNow and Active Directory, subject to connector availability and implementation scope. It can be deployed on-premises, in the cloud or in a hybrid setup.

For a longer walkthrough of the risks and how to automate each stage, read our plain-English guide to certificate lifecycle management.

Next step

Not sure how many certificates you have? Start with a free PKI and certificate risk assessment, or contact DictaLabs to talk through your setup.

Related