Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Undiscovered ('rogue') certificates are the actual outage risk; look for multi-method discovery and a real completeness figure, not just visibility into certificates the platform itself issued.
Renewal without automated deployment just shifts the manual-error risk downstream; look for named endpoint-type coverage for automated deployment and explicit failure alerting, not just renewal-then-hope.
Expired-certificate outages are almost always a process failure (an ignored alert), not a detection failure — look for escalation logic and ticketing integration, not just an email that can be missed.
CA lock-in limits negotiating leverage and creates a single point of failure; look for genuine multi-CA support, not a management console that only works well with one partnered CA.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Short-lived certificates are the clear industry direction; look for a real customer example handling high-renewal-frequency at scale, not just theoretical support for shorter validity periods.
Look for HSM-backed key generation and enforceable non-export policy — a certificate management tool that doesn't protect the private key undermines the certificate's own security value.
Look for policy-compliance reporting with historical audit trail, not just a current-state certificate inventory list requiring manual policy comparison.
CA distrust events happen and require fast, wide-scale response — look for a described bulk-reissuance/emergency-response capability, not an assumption this scenario won't occur.
Shorter certificate lifetimes mean dramatically more renewal events over the same period — ask explicitly how pricing responds to that volume growth rather than assuming a static certificate count.
A fast, tested emergency revocation/re-issuance process with real blast-radius identification is critical — ask for a concrete procedure and timeline, not just a generic 'certificates can be revoked' claim.
This is a real, common buyer question given the category overlap with Key Management platforms — a vendor should give an honest answer about the boundary and complementarity, not imply CLM is always a fully separate purchase.
Given the industry's active PQC transition, a CLM platform should have a specific, concrete PQC-readiness answer rather than treating it as entirely out of scope or a vague future promise.
Trend-over-time reporting is a distinct capability from a real-time dashboard — confirm this exists as a maintained, exportable report.
Certificate/key management is highly sensitive infrastructure — role-based access control over the platform's own management functions, not just over the certificates themselves, is an often-overlooked consideration.
Ask for an honest per-environment coverage breakdown; uneven coverage across environments is a common real gap a vendor should disclose rather than obscure.
Native ACME support and a real automation API are essential for modern DevOps workflows where certificate provisioning needs to be fully automated as part of infrastructure-as-code, not a manual console step.