x509.systems

Smallstep vs cert-manager

How Smallstep and cert-manager differ on deployment, pricing, openness and what each is actually built for.

Smallstepcert-manager
TypePrivate CA (ACME)Kubernetes controller
DeploymentSelf-hosted + SaaSSelf-hosted (K8s)
How it worksstep-ca is an open-source private certificate authority that speaks ACME, so internal services renew exactly the way public ones do. The hosted product adds device identity, SSH certificates and single sign-on integration.A Kubernetes controller that turns Certificate resources into real certificates from any configured issuer — ACME, Vault, private CAs — and renews them automatically as secrets. A CNCF graduated project.
Pricing*Free (OSS); hosted by quoteFree
Free tierYesYes
Open sourcestep-ca (Apache-2.0)Apache-2.0
ComplianceSOC 2 (hosted)—
Best forInternal mTLS and short-lived certificatesCertificates inside a Kubernetes cluster

Smallstep

  • Genuinely quick to stand up
  • ACME internally — same tooling as public TLS
  • Excellent short-lived certificate and SSH support
  • Not a public CA — internal trust only
  • Smaller company than the incumbents

cert-manager

  • The de facto standard in Kubernetes
  • Issuer-agnostic — ACME, Vault, private CAs
  • Free and heavily battle-tested
  • Kubernetes only — nothing outside the cluster
  • No estate-wide visibility or reporting

Bottom line

Choose Smallstep for internal mtls and short-lived certificates. Choose cert-manager for certificates inside a kubernetes cluster.

* Indicative list pricing (vendor documentation and public pricing pages, August 2026).