Sectigo Certificate Manager is a capable management console for Sectigo-issued certificates. TigerTrust adds the CLM layer above it — one platform for every CA you use, with discovery, reporting, and modern DevOps integrations.
Sectigo is a widely-trusted public CA and their SCM console works well for Sectigo-issued certificates. Teams switch when they need the same lifecycle discipline across every CA in the estate.
Sectigo is a mainstream public CA and SCM is its management console. Here is where the two overlap and where the delivery differs.
| Capability | TigerTrust | Sectigo Certificate Manager |
|---|---|---|
Sectigo CA issuance & renewal Sectigo is authoritative for Sectigo-issued certs | ||
Multi-CA orchestration | ||
ACME protocol / Let's Encrypt | ||
Cross-cloud discovery (AWS, Azure, GCP) | ||
Kubernetes cert-manager integration | ||
SSH certificate lifecycle | ||
GraphQL API | ||
GitOps / Terraform workflows | ||
Public CA trust anchors Sectigo operates its own public trust anchors; TigerTrust orchestrates trusted CAs |
You do not have to leave Sectigo to gain a CLM. Most teams keep Sectigo as a CA and add TigerTrust as the platform.
Add Sectigo as an issuer in TigerTrust using your existing SCM credentials. Current inventory imports and stays in sync.
Bring in DigiCert, private CAs, ADCS, Let's Encrypt, Vault — whatever else is in play. Policy decides which certificate routes to which CA.
Point discovery at your networks, clouds, and Kubernetes clusters. Every certificate appears in one inventory, regardless of issuer.
Enable ACME endpoints, cert-manager issuers, and webhook renewals. Sectigo keeps issuing; TigerTrust handles the lifecycle.
No — and most teams don't. Sectigo stays as an issuer for the certificates you already trust it for. TigerTrust sits above SCM as the CLM plane, adding cross-CA orchestration, discovery, and modern DevOps integrations.
Yes. Policy in TigerTrust routes each request to the appropriate CA based on hostname, environment, tags, or approver. Free issuers for commodity TLS; Sectigo for the certificates that warrant public-CA assurance.
TigerTrust uses the Sectigo Certificate Manager API to enroll, retrieve, and revoke Sectigo-issued certificates. Your Sectigo contract, account structure, and validation model stay intact.
TigerTrust manages SSH certificates as first-class citizens. SCM is scoped to X.509, so if you want SSH lifecycle in the same platform alongside your TLS certs, that consolidation is part of the switch.
Platform pricing is separate from what you pay for Sectigo certificates. You can keep spending at Sectigo where it makes sense and route commodity certs to free issuers. Ask us for a side-by-side against your current line items.
“Sectigo stayed for our storefronts. Internal service mesh moved to Let's Encrypt and Vault. One inventory, one alerting story, one policy plane.”
Keep Sectigo where it makes sense. Add the CAs and DevOps integrations Certificate Manager was never built to orchestrate.
The other mainstream public CA teams often evaluate alongside Sectigo — same portal-vs-CLM gap.
The third commercial-CA portal customers weigh a proper CLM against.
The CA-agnostic CLM that sits above Sectigo and every other issuer in your estate.
The buyer journey for teams consolidating multi-CA estates onto a single platform.