CyberArk certificate and machine identity licensing covers the products that CyberArk gained with Venafi and renamed: Certificate Manager - SaaS (formerly TLS Protect Cloud), Certificate Manager for Kubernetes (formerly TLS Protect for Kubernetes), Workload Identity Manager (formerly Venafi Firefly) and the self-hosted Trust Protection Platform, together with Zero Touch PKI.[1] Some Venafi references remain in code, file paths, screenshots and legacy areas.[1] The unit that matters most is the Secured Certificate Instance, which is not the same as a certificate in an inventory.
Editions
Certificate Manager - SaaS packages
Certificate Manager - SaaS is available in two base packages, Standard and Enterprise, with optional add-ons for advanced use cases. Every organisation must license one of the two base packages, and license usage is measured separately from package selection by the Secured Certificate Instance metric.[2]
| Capability | Standard | Enterprise |
|---|---|---|
| SSO and IdP integrations, discovery, monitoring and TLS validation, notifications, custom reports | Yes | Yes |
| Certificate issuance and CA connectors, revocation and approval workflows, built-in CA | Yes | Yes |
| Event log retention | 90 days | 13 months |
| Push provisioning, provisioning connectors, machine and cloud keystore discovery | No | Yes |
| SIEM, webhook and Slack alerting; credential management; HSM integration | No | Yes |
| Full lifecycle APIs; advanced revocation; compliance policies; adaptable workflows | No | Yes |
| Automation frameworks (ACME, SCEP, EST) | No | Partial: currently supported in Zero Touch PKI and self-hosted |
The package comparison and the footnote on automation frameworks are from the packaging page.[2]
Add-ons
Add-ons are licensed separately and must be used with a base package.[2]
- Certificate Manager for Kubernetes adds visibility and automation of certificates in Kubernetes environments, including discovery, cert-manager integration and service binding awareness.[2]
- Workload Identity Manager provides a private certificate authority that the customer hosts in its own environment. The platform issues and manages the certificates it creates, but they do not count towards SCI usage.[2]
Zero Touch PKI
Zero Touch PKI uses a consumption-based model built around one metric, active certificates. A certificate is active when it is issued by Zero Touch PKI, not revoked and not expired. Revoked or expired certificates no longer count.[3]
Trust Protection Platform (self-hosted)
The self-hosted platform guides carry the copyright of Venafi, Inc and CyberArk Inc.[4] Agentless Provisioning drivers install TLS certificates automatically to host systems, and they require a Trust Force licence for each endpoint that is installed to.[5] Unassigned certificates are unlicensed certificates that do not allow network validation, expiration monitoring, enrollment, provisioning or onboard validation, although they appear in selected reports and on the dashboard.[4]
Metrics
| Metric | Product | Unit |
|---|---|---|
| Secured Certificate Instance (SCI) | Certificate Manager - SaaS and add-ons | Certificate counted per qualifying state and installation location |
| Zero Touch PKI active certificate | Zero Touch PKI | Certificate issued, not revoked, not expired |
| Trust Force endpoint licence | Trust Protection Platform | Endpoint receiving agentless provisioning |
| Managed certificate (Trust Protection Platform) | Trust Protection Platform | Managed certificate, with managed SSH and symmetric keys, reported in the Licensing Report |
Counting and floors
What counts as an SCI
A certificate is counted as an SCI if it meets any one of the following: it is assigned to an application; it has been requested, renewed or installed using the service (a qualifying lifecycle operation); it is monitored through inventory monitoring settings; or it is installed at an active installation location.[6]
The following do not count: retired certificates, old certificates that are no longer installed or monitored, certificates that are only detected at TLS server endpoints, and certificates issued by Workload Identity Manager, even if they are discovered or visible in the service.[6]
Worked examples from the documentation
| Scenario | SCI count |
|---|---|
| A certificate is requested through the service but not installed | 1 (the request is a qualifying lifecycle operation) |
| A certificate is installed on one machine | 1 |
| A certificate is installed on two machines | 2 |
| A certificate is found on 100 TLS server endpoints but installed nowhere | 0 |
| An old certificate is still installed on one machine | 1 |
| A retired certificate is still installed | 0 |
| A certificate is discovered in a cluster but not issued by the service | 0 |
| A certificate is issued by the service through cert-manager | 1 |
| A monitored certificate is installed with 3 service attachments | 3 |
The scenario list is from the usage calculation page.[6] Each unique installation location, such as a server, a Kubernetes service or a keystore, counts as a separate SCI, so deploying one certificate to many endpoints raises the count.[7]
Settings that change usage
By default Certificate Manager - SaaS does not monitor certificates that are not assigned to an application. Enabling the setting Monitor certificates that are not assigned to any application makes those monitored certificates count as SCIs, and a warning explains the licensing impact before the setting is saved. The documentation notes that heavy inventory monitoring without application assignment may increase usage significantly.[7] Discovery and import jobs use reconciliation logic so that re-imported certificates do not create duplicate SCIs, and discovery alone does not use SCIs unless the discovered certificate meets a qualifying criterion.[7]
Measurement and enforcement
The Licensing page shows the billing cycle, package, licensing model version, entitled SCIs, current SCI usage, the time of last measurement and the total certificates in inventory. The inventory total does not affect usage. Usage is calculated once daily at a fixed UTC time and cannot be refreshed manually, so a change in monitoring settings or installation locations appears the next day.[8] SCI usage is not enforced by the platform; it is evaluated contractually each day, an entitlement can be exceeded temporarily, and consistent overages may trigger action during renewals or audits.[6]
Each tenant has one entitlement, which defines licensed access, and a plan, which is the collection of packages and features; a tenant with a plan is considered licensed.[9]
Virtualization and partitioning
The retrieved documents define no processor, core or hypervisor rules. For containers, the usage examples show that a monitored certificate installed with three service attachments counts three times.[6]
Cloud and self-hosted
The SaaS products follow the SaaS Terms of Service, which grant access during the Subscription Term in the quantity specified in the Order.[10] The self-hosted Trust Protection Platform follows the Software License Agreement, whose definition of Documentation includes the Venafi documentation sites.[11] In Trust Protection Platform 25.1 participation in the Customer Experience Improvement Project is required for all customers so that licence utilisation and product usage telemetry can be gathered, and a component without a valid licence for its product is not available during installation.[5] The Licensing Report counts managed certificates and their applications, and managed SSH and symmetric keys, and feeds the License Status tab so that administrators can check compliance.[4]
Programs
- 2024 licensing model. The model of Certificate Manager - SaaS changed in 2024, and the documentation describes the current model by default while noting that some customers continue to use the legacy model.[9]
- Support options. Production, Premium, Platinum and Trusted (US only) apply to SaaS and self-hosted products alike.[12]
- Trials. Free trials and proofs of concept for SaaS products are for internal evaluation only.[10]
Audits and compliance
For a SaaS tenant a customer that exceeds licensed quantities must cooperate to resolve the non-compliance, including possible payment for overages at then-current rates.[10] For the self-hosted platform CyberArk may review use against licensing metrics and request usage reports not more than once a year on reasonable notice.[11] A practical position records the package, the entitled SCIs, the value of the monitoring setting, the count by installation location and the date of the last daily measurement.
Out of scope
Pricing and the legacy metric are not published in the pages retrieved. Secrets Manager, Credential Providers and Secrets Hub are described in CyberArk licensing; the public pages for those products state no licensing metric.