Which platform to pick when a spreadsheet has stopped being an inventory.
There is no single best CLM — there is a best one for the size of your estate and how much of it you control. The honest split: under a few hundred certificates, tooling you already own will do. Past a few thousand, spread across teams and appliances, a dedicated platform pays for itself the first time it prevents an expiry outage.
Pick it when governance is the actual requirement — many CAs, auditors asking questions, and policy that must be provable rather than asserted.
The strongest answer when you want to self-host and audit the CA itself. EJBCA underneath means you are not trusting a black box.
Worth shortlisting if your pain is pushing certificates onto F5, Citrix and NetScaler devices rather than issuing them.
For engineering-led teams: internal ACME, short-lived certificates, and running by the end of the day.
If everything lives in Kubernetes, start here and stop. Adding a platform on top solves a problem you may not have.
Size the tool to the estate. Buying Venafi for four hundred certificates is expensive shelfware; running cert-manager alone across a bank is an outage waiting for a date.
Describe the estate — roughly how many certificates, public or internal, and what has to be automated — and we’ll send back a shortlist with the reasoning. No vendor sees your details.