LICENSEWARE

CyberArk certificate and machine identity licensing

This article is about how CyberArk licenses the machine identity products that came from Venafi: Certificate Manager - SaaS, its add-ons, Zero Touch PKI and the self-hosted Trust Protection Platform. It is not about Secrets Manager, privileged access products or the general CyberArk contract terms. It is not legal advice.

On This Page

CyberArk certificate and machine identity licensing covers the products that CyberArk gained with Venafi and renamed: Certificate Manager - SaaS (formerly TLS Protect Cloud), Certificate Manager for Kubernetes (formerly TLS Protect for Kubernetes), Workload Identity Manager (formerly Venafi Firefly) and the self-hosted Trust Protection Platform, together with Zero Touch PKI.[1] Some Venafi references remain in code, file paths, screenshots and legacy areas.[1] The unit that matters most is the Secured Certificate Instance, which is not the same as a certificate in an inventory.

Editions

Certificate Manager - SaaS packages

Certificate Manager - SaaS is available in two base packages, Standard and Enterprise, with optional add-ons for advanced use cases. Every organisation must license one of the two base packages, and license usage is measured separately from package selection by the Secured Certificate Instance metric.[2]

Capability Standard Enterprise 
SSO and IdP integrations, discovery, monitoring and TLS validation, notifications, custom reports Yes Yes 
Certificate issuance and CA connectors, revocation and approval workflows, built-in CA Yes Yes 
Event log retention 90 days 13 months 
Push provisioning, provisioning connectors, machine and cloud keystore discovery No Yes 
SIEM, webhook and Slack alerting; credential management; HSM integration No Yes 
Full lifecycle APIs; advanced revocation; compliance policies; adaptable workflows No Yes 
Automation frameworks (ACME, SCEP, EST) No Partial: currently supported in Zero Touch PKI and self-hosted 

The package comparison and the footnote on automation frameworks are from the packaging page.[2]

Add-ons

Add-ons are licensed separately and must be used with a base package.[2]

  • Certificate Manager for Kubernetes adds visibility and automation of certificates in Kubernetes environments, including discovery, cert-manager integration and service binding awareness.[2]
  • Workload Identity Manager provides a private certificate authority that the customer hosts in its own environment. The platform issues and manages the certificates it creates, but they do not count towards SCI usage.[2]

Zero Touch PKI

Zero Touch PKI uses a consumption-based model built around one metric, active certificates. A certificate is active when it is issued by Zero Touch PKI, not revoked and not expired. Revoked or expired certificates no longer count.[3]

Trust Protection Platform (self-hosted)

The self-hosted platform guides carry the copyright of Venafi, Inc and CyberArk Inc.[4] Agentless Provisioning drivers install TLS certificates automatically to host systems, and they require a Trust Force licence for each endpoint that is installed to.[5] Unassigned certificates are unlicensed certificates that do not allow network validation, expiration monitoring, enrollment, provisioning or onboard validation, although they appear in selected reports and on the dashboard.[4]

Metrics

Metric Product Unit 
Secured Certificate Instance (SCI) Certificate Manager - SaaS and add-ons Certificate counted per qualifying state and installation location 
Zero Touch PKI active certificate Zero Touch PKI Certificate issued, not revoked, not expired 
Trust Force endpoint licence Trust Protection Platform Endpoint receiving agentless provisioning 
Managed certificate (Trust Protection Platform) Trust Protection Platform Managed certificate, with managed SSH and symmetric keys, reported in the Licensing Report 

Counting and floors

What counts as an SCI

A certificate is counted as an SCI if it meets any one of the following: it is assigned to an application; it has been requested, renewed or installed using the service (a qualifying lifecycle operation); it is monitored through inventory monitoring settings; or it is installed at an active installation location.[6]

The following do not count: retired certificates, old certificates that are no longer installed or monitored, certificates that are only detected at TLS server endpoints, and certificates issued by Workload Identity Manager, even if they are discovered or visible in the service.[6]

Worked examples from the documentation

Scenario SCI count 
A certificate is requested through the service but not installed 1 (the request is a qualifying lifecycle operation) 
A certificate is installed on one machine 1 
A certificate is installed on two machines 2 
A certificate is found on 100 TLS server endpoints but installed nowhere 0 
An old certificate is still installed on one machine 1 
A retired certificate is still installed 0 
A certificate is discovered in a cluster but not issued by the service 0 
A certificate is issued by the service through cert-manager 1 
A monitored certificate is installed with 3 service attachments 3 

The scenario list is from the usage calculation page.[6] Each unique installation location, such as a server, a Kubernetes service or a keystore, counts as a separate SCI, so deploying one certificate to many endpoints raises the count.[7]

Settings that change usage

By default Certificate Manager - SaaS does not monitor certificates that are not assigned to an application. Enabling the setting Monitor certificates that are not assigned to any application makes those monitored certificates count as SCIs, and a warning explains the licensing impact before the setting is saved. The documentation notes that heavy inventory monitoring without application assignment may increase usage significantly.[7] Discovery and import jobs use reconciliation logic so that re-imported certificates do not create duplicate SCIs, and discovery alone does not use SCIs unless the discovered certificate meets a qualifying criterion.[7]

Measurement and enforcement

The Licensing page shows the billing cycle, package, licensing model version, entitled SCIs, current SCI usage, the time of last measurement and the total certificates in inventory. The inventory total does not affect usage. Usage is calculated once daily at a fixed UTC time and cannot be refreshed manually, so a change in monitoring settings or installation locations appears the next day.[8] SCI usage is not enforced by the platform; it is evaluated contractually each day, an entitlement can be exceeded temporarily, and consistent overages may trigger action during renewals or audits.[6]

Each tenant has one entitlement, which defines licensed access, and a plan, which is the collection of packages and features; a tenant with a plan is considered licensed.[9]

Virtualization and partitioning

The retrieved documents define no processor, core or hypervisor rules. For containers, the usage examples show that a monitored certificate installed with three service attachments counts three times.[6]

Cloud and self-hosted

The SaaS products follow the SaaS Terms of Service, which grant access during the Subscription Term in the quantity specified in the Order.[10] The self-hosted Trust Protection Platform follows the Software License Agreement, whose definition of Documentation includes the Venafi documentation sites.[11] In Trust Protection Platform 25.1 participation in the Customer Experience Improvement Project is required for all customers so that licence utilisation and product usage telemetry can be gathered, and a component without a valid licence for its product is not available during installation.[5] The Licensing Report counts managed certificates and their applications, and managed SSH and symmetric keys, and feeds the License Status tab so that administrators can check compliance.[4]

Programs

  • 2024 licensing model. The model of Certificate Manager - SaaS changed in 2024, and the documentation describes the current model by default while noting that some customers continue to use the legacy model.[9]
  • Support options. Production, Premium, Platinum and Trusted (US only) apply to SaaS and self-hosted products alike.[12]
  • Trials. Free trials and proofs of concept for SaaS products are for internal evaluation only.[10]

Audits and compliance

For a SaaS tenant a customer that exceeds licensed quantities must cooperate to resolve the non-compliance, including possible payment for overages at then-current rates.[10] For the self-hosted platform CyberArk may review use against licensing metrics and request usage reports not more than once a year on reasonable notice.[11] A practical position records the package, the entitled SCIs, the value of the monitoring setting, the count by installation location and the date of the last daily measurement.

Out of scope

Pricing and the legacy metric are not published in the pages retrieved. Secrets Manager, Credential Providers and Secrets Hub are described in CyberArk licensing; the public pages for those products state no licensing metric.

References

  1. CyberArk rebranding updates (Machine Identity Security Docs)Venafi to CyberArk product names. Undated.Retrieved 2026-10-07.
  2. Certificate Manager - SaaS packages and add-ons (Machine Identity Security Docs)Standard and Enterprise packages and add-ons. Undated.Retrieved 2026-10-07.
  3. About licensing in Zero Touch PKI (Machine Identity Security Docs)Active certificate metric. Undated.Retrieved 2026-10-07.
  4. Venafi Trust Protection Platform 25.1 Product Overview GuideUnassigned certificates and the Licensing Report. Version 25.1.Retrieved 2026-10-07.
  5. Venafi Trust Protection Platform 25.1 Installation and Upgrade GuideTrust Force licence; licence telemetry. Version 25.1.Retrieved 2026-10-07.
  6. How license usage is calculated using Secured Certificate Instances (Machine Identity Security Docs)What counts as an SCI; enforcement notes. Undated.Retrieved 2026-10-07.
  7. Settings that affect license consumption (Machine Identity Security Docs)Settings that change SCI consumption. Undated.Retrieved 2026-10-07.
  8. Viewing your license entitlements and usage (Machine Identity Security Docs)Licensing page fields and daily refresh. Undated.Retrieved 2026-10-07.
  9. Understanding licensing in Certificate Manager - SaaS (Machine Identity Security Docs)SCI metric, entitlement, plan, 2024 model change. Undated.Retrieved 2026-10-07.
  10. CyberArk SaaS Terms of Service (Global), Rev. 10 September 2026Sections 1, 2, 13 and definitions. Rev. 10 September 2026.Effective 2026-09-10. Retrieved 2026-10-07.
  11. CyberArk Software License Agreement (Global), Rev. 10 September 2026Sections 1 (licence, review, restrictions), 2 (payment, Indirect Orders), 8, 9, 10, 12 and 18. Rev. 10 September 2026.Effective 2026-09-10. Retrieved 2026-10-07.
  12. CyberArk Support Terms (Global), 10 October 2025Severity levels, renewal, Annex 1 support options. Dated 10 October 2025.Effective 2025-10-10. Retrieved 2026-10-07.

See also

Catalog Rows Cited

4Metrics1Programs

Esc