TigerTrust vs DigiCert

CA-agnostic lifecycle without vendor lock-in.

DigiCert CertCentral is an excellent portal for managing DigiCert-issued certificates. TigerTrust adds the layer above it — a CA-agnostic lifecycle platform that treats DigiCert as one issuer among many, plus discovery and reporting for the certs DigiCert never saw.

Why teams switch

Keep DigiCert as a CA. Drop DigiCert as the platform.

DigiCert is a top-tier public CA — most enterprises rightly keep them for EV, code signing, and high-assurance workloads. CertCentral is a good portal for those certificates, but not a full CLM.

True multi-CA orchestration
DigiCert, Sectigo, Entrust, GlobalSign, Let's Encrypt, private CAs, ADCS, Vault — all managed through one policy plane.
Deep automation
Full ACME, webhooks, cert-manager, Terraform, and a first-class API. Zero-touch renewal and deployment beyond DigiCert-managed certs.
Cloud + on-prem discovery
Discovery across AWS, Azure, GCP, Kubernetes, and on-premise load balancers surfaces every cert, regardless of who issued it.
Platform pricing, cert pass-through
One platform fee. Certificates at whatever CA rate you negotiate — including free with Let's Encrypt where policy allows.
The move off

What changes when the platform is CA-agnostic.

Without DigiCert
  • Lifecycle tooling scoped to DigiCert-issued certificates
  • Limited discovery outside DigiCert-managed inventory
  • Basic automation — mostly renewal orchestration
  • No SSH certificate lifecycle in the same platform
  • Cost model tied to DigiCert certificate consumption
With TigerTrust
  • Every certificate in the estate, regardless of issuer
  • Full network, cloud, and Kubernetes discovery
  • ACME, webhooks, cert-manager, Terraform, event-driven policy
  • SSH certificates, code signing, and workload identity together
  • Platform pricing separate from what you spend at any CA

Capability comparison, head to head.

DigiCert is a top-tier CA. CertCentral is its management portal, not a full CLM. Here is where the two overlap and where they don't.

CapabilityTigerTrustDigiCert CertCentral
DigiCert CA issuance & renewal
DigiCert is authoritative for DigiCert-issued certs
Multi-CA orchestration (non-DigiCert issuers)
ACME protocol / Let's Encrypt
Certificate discovery across the estate
Kubernetes cert-manager integration
SSH certificate lifecycle
GraphQL API
GitOps / Terraform workflows
Public CA trust & compliance pedigree
DigiCert operates its own public trust anchors; TigerTrust orchestrates trusted CAs but is not itself a WebTrust-audited public CA

Adding TigerTrust on top of CertCentral.

You do not have to leave DigiCert to gain a CLM. Most teams keep DigiCert as a preferred CA and add TigerTrust as the platform.

01

Connect CertCentral

Add DigiCert as an issuer in TigerTrust using your existing CertCentral API key. Existing DigiCert inventory imports automatically.

02

Add other issuers

Connect any other CAs in play — Sectigo, Entrust, private CAs, Let's Encrypt for lower-assurance workloads. Policy decides which cert type routes to which CA.

03

Turn on discovery

Point discovery at your clouds, Kubernetes clusters, and network ranges. Every certificate — DigiCert or not — appears in one inventory.

04

Automate deployment

Enable ACME endpoints, cert-manager issuers, webhook renewals, and Terraform. DigiCert keeps issuing; TigerTrust keeps deploying and reporting.

Frequently asked questions

Do we have to leave DigiCert to use TigerTrust?

No — and most teams don't. DigiCert stays as a preferred CA for EV, code signing, and high-assurance workloads. TigerTrust sits above it as the CLM plane, adding multi-CA orchestration, discovery, and reporting.

Can we use Let's Encrypt for lower-assurance certs and DigiCert for the rest?

Yes. Policy in TigerTrust routes each certificate request to the appropriate CA based on hostname, environment, tags, or approver. This is one of the most common patterns customers adopt on switch-day.

How does CertCentral integration work?

TigerTrust uses the CertCentral API to enroll, retrieve, and revoke DigiCert-issued certificates. Your DigiCert contract, sub-account structure, and validation model stay intact.

What about SSH certificates and code signing?

Both are managed in TigerTrust as first-class citizens. CertCentral is scoped to X.509, so if you want a single platform for SSH and code signing alongside your TLS certificates, that consolidation is part of the switch.

How is pricing structured?

Platform pricing is separate from what you spend on certificates. You can keep spending at DigiCert for the certs that need it, and route commodity TLS to free issuers where policy allows. Ask us for a side-by-side against your current DigiCert contract.

Case study
Global · Consumer technology

Kept DigiCert as the trust anchor, added TigerTrust as the platform above it.

We did not want to leave DigiCert for the certs that matter. We wanted a CLM around them — plus Let's Encrypt for commodity workloads and Vault for internal service mesh.
Principal Security Architect
6 wk
Time to unified inventory
1.2M
Certificates across 4 CAs
43%
Reduction in commodity CA spend
Integrations

Every CA in your estate, one policy plane.

DigiCert remains a first-class issuer — alongside every other CA teams need in a real multi-issuer estate.

DigiCert CertCentral
CA
Let's Encrypt
CA
Sectigo
CA
Entrust
CA
Microsoft ADCS
CA
HashiCorp Vault
CA
Kubernetes cert-manager
DevOps
HashiCorp Terraform
IaC
ServiceNow
ITSM

Add the CLM layer above your CA.