TigerTrust vs Sectigo

A CA-agnostic platform around your Sectigo certs.

Sectigo Certificate Manager is a capable management console for Sectigo-issued certificates. TigerTrust adds the CLM layer above it — one platform for every CA you use, with discovery, reporting, and modern DevOps integrations.

Why teams switch

Keep Sectigo as a CA. Upgrade the platform.

Sectigo is a widely-trusted public CA and their SCM console works well for Sectigo-issued certificates. Teams switch when they need the same lifecycle discipline across every CA in the estate.

Multi-CA orchestration
Sectigo, DigiCert, Entrust, GlobalSign, Let's Encrypt, private CAs, ADCS, Vault — one policy plane across all of them.
Cloud-native + DevOps ready
Kubernetes cert-manager, Terraform, GitOps workflows, and cross-cloud discovery built in — not bolted on.
Deeper automation
Full ACME support, webhook-driven renewals, deployment orchestration to endpoints, and event-driven policy — beyond SCM's renewal workflows.
Platform + cert costs separated
One platform fee. Certificates at whatever rate you negotiate with Sectigo or any other CA, or free via Let's Encrypt where policy allows.
The move off

What changes when every CA is in scope.

Without Sectigo
  • Lifecycle management scoped to Sectigo-issued certificates
  • Limited discovery outside Sectigo-managed inventory
  • Basic ACME support; modern DevOps workflows require workarounds
  • No SSH certificate lifecycle in the same platform
  • Cost tied to Sectigo certificate consumption
With TigerTrust
  • Every certificate — Sectigo or not — in one inventory
  • Network, cloud, and Kubernetes discovery across the estate
  • First-class ACME, cert-manager, Terraform, and webhook workflows
  • SSH certificates and code signing alongside TLS
  • Platform pricing separate from CA spend

Capability comparison, head to head.

Sectigo is a mainstream public CA and SCM is its management console. Here is where the two overlap and where the delivery differs.

CapabilityTigerTrustSectigo Certificate Manager
Sectigo CA issuance & renewal
Sectigo is authoritative for Sectigo-issued certs
Multi-CA orchestration
ACME protocol / Let's Encrypt
Cross-cloud discovery (AWS, Azure, GCP)
Kubernetes cert-manager integration
SSH certificate lifecycle
GraphQL API
GitOps / Terraform workflows
Public CA trust anchors
Sectigo operates its own public trust anchors; TigerTrust orchestrates trusted CAs

Adding TigerTrust on top of Sectigo Certificate Manager.

You do not have to leave Sectigo to gain a CLM. Most teams keep Sectigo as a CA and add TigerTrust as the platform.

01

Connect Sectigo SCM

Add Sectigo as an issuer in TigerTrust using your existing SCM credentials. Current inventory imports and stays in sync.

02

Add other CAs

Bring in DigiCert, private CAs, ADCS, Let's Encrypt, Vault — whatever else is in play. Policy decides which certificate routes to which CA.

03

Turn on discovery

Point discovery at your networks, clouds, and Kubernetes clusters. Every certificate appears in one inventory, regardless of issuer.

04

Automate deployment

Enable ACME endpoints, cert-manager issuers, and webhook renewals. Sectigo keeps issuing; TigerTrust handles the lifecycle.

Frequently asked questions

Do we have to leave Sectigo to use TigerTrust?

No — and most teams don't. Sectigo stays as an issuer for the certificates you already trust it for. TigerTrust sits above SCM as the CLM plane, adding cross-CA orchestration, discovery, and modern DevOps integrations.

Can we mix Let's Encrypt with Sectigo?

Yes. Policy in TigerTrust routes each request to the appropriate CA based on hostname, environment, tags, or approver. Free issuers for commodity TLS; Sectigo for the certificates that warrant public-CA assurance.

How does SCM integration work?

TigerTrust uses the Sectigo Certificate Manager API to enroll, retrieve, and revoke Sectigo-issued certificates. Your Sectigo contract, account structure, and validation model stay intact.

What about SSH certificates?

TigerTrust manages SSH certificates as first-class citizens. SCM is scoped to X.509, so if you want SSH lifecycle in the same platform alongside your TLS certs, that consolidation is part of the switch.

How is pricing structured?

Platform pricing is separate from what you pay for Sectigo certificates. You can keep spending at Sectigo where it makes sense and route commodity certs to free issuers. Ask us for a side-by-side against your current line items.

Case study
Global · Retail & e-commerce

Kept Sectigo for public trust, added TigerTrust for everything else.

Sectigo stayed for our storefronts. Internal service mesh moved to Let's Encrypt and Vault. One inventory, one alerting story, one policy plane.
Head of Application Security
5 wk
Time to unified inventory
780K
Certificates across 3 CAs
38%
Reduction in commodity cert spend
Integrations

Sectigo plus every other CA under one policy plane.

Keep Sectigo where it makes sense. Add the CAs and DevOps integrations Certificate Manager was never built to orchestrate.

Sectigo Certificate Manager
CA
Let's Encrypt
CA
DigiCert
CA
Microsoft ADCS
CA
HashiCorp Vault
CA
Kubernetes cert-manager
DevOps
HashiCorp Terraform
IaC
GitHub Actions
CI/CD
ServiceNow
ITSM

Add the CLM layer above your CA.