LICENSEWARE

DigiCert CertCentral and TLS certificate licensing

This article is about how DigiCert sells publicly trusted certificates through CertCentral: account types, annual plans, Multi-year Plans, the 12-month subscription model, Flex certificates and the rules for ending a subscription. It is not legal advice.

On This Page

CertCentral is DigiCert’s web portal and API for ordering and managing publicly trusted certificates. DigiCert’s documentation names it a “trust source”, meaning a service that issues certificates recognized by public trust stores such as browsers and operating systems, as opposed to DigiCert Private CA, which issues certificates trusted only by systems configured to trust the private CA.[1] How a CertCentral customer is licensed depends first on the account type, and the account type decides whether the customer buys certificates on a plan or buys protected assets on a subscription.

Account types and coverage models

CertCentral has four account paths: Enterprise, for organizations that manage certificates at scale; Partner, for resellers and service providers who manage customer subaccounts; Subscription, for organizations with predictable certificate usage; and Legacy, for accounts created under older models.[2] The coverage model follows from the type.[3]

Account type Coverage model 
Subscription 12-month subscription per protected asset; no Annual Plans or Multi-year Plans 
Enterprise Annual Plans and Multi-year Plans; up to five user roles 
Partner Annual Plans and Multi-year Plans; reseller and subaccount management 
Legacy Transitioning to the Subscription model 

In Enterprise, Partner and Legacy accounts, public TLS certificates are issued on Annual Plans (one-year default) or Multi-year Plans (up to three years), and the maximum certificate validity is 199 days. Subscription accounts pay per protected asset and no per-certificate payment is required when a certificate is requested.[3] Catalog proof: Annual Plan; Multi-year Plan.

Annual Plans

DigiCert describes an annual plan as one year of TLS/SSL certificate coverage for a single price, applying to Enterprise, Partner and Legacy accounts. As of February 24, 2026 DigiCert TLS/SSL certificate plans are one year by default.[4] The first certificate on a plan is issued with a maximum validity of 199 days. When it nears expiry the customer reissues it, and the second certificate’s validity aligns with the time left on the plan. Near the end of the second certificate the customer renews the certificate and the plan together.[4]

What a customer can do within an annual plan is defined: reissue at any time at no extra cost, renew the plan up to 90 days before it expires, and add domains, with additional domain costs prorated to the time remaining. Removing or changing domains causes DigiCert to revoke all previously issued certificates on the order, including reissues and duplicates, within 48 to 72 hours, so the replacements must be installed in that window.[4] Reissuing does not install the new certificate on the web server automatically.[4] The licence boundary here is the plan and its domain list, not a count of certificates: the customer can reissue repeatedly within the plan. Catalog proof: Annual plan first certificate is limited to 199 days and reissues are free; Changing domains on an annual plan revokes issued certificates.

The documentation sets out the CA/Browser Forum schedule for maximum validity of TLS certificates: 199 days as of March 15, 2026, 99 days as of March 15, 2027 and 46 days as of March 15, 2029.[4] DigiCert’s Web PKI Terms of Use, dated August 25, 2025, describe the same industry direction in slightly different rounded figures and say that DigiCert may offer annual subscriptions or longer bundles for convenience while certificates are still re-issued at industry-mandated intervals.[5] For asset managers this means that the number of certificates issued per covered domain rises as validity shortens, even though the price of a plan is per year of coverage.

Multi-year Plans

A Multi-year Plan (MyP) allows one price for up to three years of TLS/SSL coverage and applies to Enterprise, Partner and Legacy accounts. Subscription accounts do not offer Multi-year Plans.[6] The mechanics match an annual plan: the first certificate has a maximum validity of 199 days and is reissued at no extra cost to use the remaining coverage until the plan expires. Customers may have to revalidate domains and organizations several times during a plan, because validation reuse is limited to the allowed reuse period.[6] Enterprise License Agreement (ELA) and Flat Fee contracts support one- and two-year plans, and standard accounts support up to three-year plans where available.[6] Existing active Multi-year Plans are not being converted to the subscription model, unless the order comes up for renewal, when it aligns to the account-level 12-month subscription term at a prorated cost.[7] Catalog proof: Multi-year Plans exclude Subscription accounts and cap at three years.

The 12-month subscription model

DigiCert describes the 12-month subscription as the new standard payment structure for customers buying DigiCert services, including CertCentral certificate products and DNS. It is based on the assets to be protected: a web server domain name, an employee email account or an organization that publishes software.[7] A subscription activates on a new purchase or a certificate renewal and then acts as a pool of licences. Licences added later take the account-level 12-month term at a prorated cost, and at renewal all active licences renew together at their full annual price.[7]

The Subscription Terms define the licensing unit for each certificate category.[8]

Entitlement category Licensing model 
TLS/SSL certificates per fully qualified domain name (FQDN) per year; wildcard domain names billed at a different rate 
Verified Mark and Common Mark certificates per FQDN per year 
S/MIME (email) certificates per user per year 
Code signing certificates per organization per year 
Document signing certificates per organization or individual per year 
Encryption and authentication certificates per organization or individual per year 
Authoritative DNS queries per million queries per month 
Trust Lifecycle Manager Essentials seat per active endpoint managed, as set in the seat template 

The change from the old purchasing model is that the customer buys licences for assets, and can then issue any number of certificates against those assets. Domains or email addresses can be changed at no extra cost, and a code signing licence is bought for the organization whose code is signed.[7] A customer can remove a domain name or email address from its licence, which frees the licence for reuse. All active certificates for the removed asset are revoked within 48 to 72 hours, pending orders are cancelled and related services deactivated. A certificate cannot be transferred from one domain to another.[7] Catalog proof: TLS certificates are licensed per FQDN per year on subscription; Removing a domain from a subscription revokes its certificates.

If a customer exceeds the entitlement during a Service Term, it owes an excess usage fee equal to the excess entitlements multiplied by the price of the entitlement, which DigiCert charges automatically to the payment method on the account at the start of the next Service Term. Unused entitlements expire at the end of the Service Term with no credit, refund or rollover.[8] On the enterprise contract form of this model, called Certificate Subscription Services, DigiCert measures excess SANs on active TLS certificates and non-TLS certificates at their peak during the entitlement period.[9] A customer reconciling a subscription should therefore track peak, not average, quantities for the year. Catalog proof: Subscription excess usage is charged automatically at the next Service Term; Additional subscription services are pro-rated within the term.

Flex certificates

Flex certificates are DigiCert TLS certificates that support any combination of FQDNs and wildcard domains. They let a customer add, remove and rearrange subject alternative names during the certificate lifetime without changing products, and they are available to all four CertCentral account types.[10] For Flex requests the common name and SANs must be entered on the CertCentral request form, because CertCentral ignores those in the CSR, and both versions of a domain, such as with and without a leading label, must be added explicitly rather than assumed.[10] Catalog proof: DigiCert Flex certificate.

Ending a subscription

If a customer cancels within 30 days of activation, DigiCert gives a complete refund, revokes all active certificates and cancels pending orders, and the account becomes read-only for reports. If it cancels later, there is no refund, auto-renewal is turned off, certificates and services stay active until the subscription end date, and certificates are revoked on that date unless the remaining validity is paid for.[11] A customer that wants to keep certificates beyond the end date pays a one-time Remaining Certificate Life fee, a prorated amount based on the original purchase price and the time left on the certificate; this option is available only when cancelling more than 30 days after purchase, and without it the certificates are revoked automatically.[12] The Subscription Terms give the formula: the number of each entitlement on the last day of the Service Term multiplied by the annual entitlement price divided by 12 and by the months of validity remaining. The customer can instead revoke the certificates within 24 hours of expiry and avoid the fee, and if it pays the fee the portal stays available only to manage existing certificates.[8] Catalog proof: Cancelling within 30 days refunds in full and revokes certificates; Remaining Certificate Plan Life Fee.

Payment and account credit

CertCentral Enterprise and Partner accounts can use account credit, a prepaid balance against which certificate purchases are debited. Subscription accounts cannot set up account credit. Azure Key Vault integrations require account credit, and automatic renewal requires an account balance as the default payment method because credit card payment is not supported for auto-renew.[13][3] Catalog proof: Account credit is not available to Subscription accounts.

Certificate Discovery

CertCentral Discovery, which scans networks for certificates regardless of issuer, is being retired on October 1, 2026. DigiCert tells customers to move discovery to Trust Lifecycle Manager, with cloud scans requiring an Essentials subscription and network scans an Advanced subscription.[14] That change moves a feature that was part of CertCentral into a seat-based product; see Trust Lifecycle Manager and Private CA licensing. Catalog proof: CertCentral Discovery moves to Trust Lifecycle Manager on October 1, 2026.

Terms of use that affect licence compliance

The Web PKI Certificate Terms of Use require that a TLS/SSL certificate secures only domains the subscriber owns or has explicit authorization to use, that it is installed on multiple servers only if all are under the subscriber’s control, and that it is used for TLS/SSL web server security and not for email encryption, code signing, document signing or VPN authentication.[5] A subscriber that issues one certificate to a third party’s systems, or uses a TLS certificate for a different purpose, is outside those terms and risks revocation. The same document states that DigiCert does not support pinning of its certificates and will not delay revocation for pinned environments, which is relevant to estates that embed certificates in firmware or applications.[5] Catalog proof: Web PKI certificate may only be used for authorized domains on systems you control.

Out of scope

This article does not cover DigiCert’s validation procedures, the Certification Practices Statements, EV code signing or KeyLocker (see Software, Device and Content Trust Manager licensing), or other certificate brands DigiCert may sell. It does not state prices, which the cited documents do not publish.

References

  1. Understand the products in DigiCert ONETrust sources and trust workflow products. Undated.Retrieved 2026-10-08.
  2. Discover your CertCentral pathAccount paths. Undated.Retrieved 2026-10-08.
  3. Understand your account type and coverage modelCoverage model by account type. Undated.Retrieved 2026-10-08.
  4. Understand DigiCert annual plansOne-year default as of February 24, 2026; 199-day first certificate; validity timeline. Undated.Retrieved 2026-10-08.
  5. DigiCert Web PKI Certificate Terms of Use: Publicly Trusted TLS/SSL (Last Updated: August 25, 2025)Sections 1 to 10. Last Updated: August 25, 2025.Effective 2025-08-25. Retrieved 2026-10-08.
  6. Understand Multi-year PlansPlan coverage and limits. Undated.Retrieved 2026-10-08.
  7. Common questions about DigiCert subscriptions12-month subscription model. Undated.Retrieved 2026-10-08.
  8. Transactional Subscription Terms and Conditions (Version: 18 May 2026)Sections 1 to 5: Service Term, entitlement table, Remaining Certificate Plan Life Fee, TLM Essentials terms. Version: 18 May 2026.Effective 2026-05-18. Retrieved 2026-10-08.
  9. Services Addendum (Version: 28 September 2026)Section 1 definitions; section 2 purchases and entitlements; Schedule 1 seat table, Site, Certificate Subscription Services, HSM Services, inflation adjustment, entitlement verification. Version: 28 September 2026.Effective 2026-09-28. Retrieved 2026-10-08.
  10. Request Flex certificateFlex certificate availability. Undated.Retrieved 2026-10-08.
  11. Cancel your DigiCert subscriptionCancellation and refund rules. Undated.Retrieved 2026-10-08.
  12. Keep valid certificates after your subscription endsRemaining Certificate Life fee. Undated.Retrieved 2026-10-08.
  13. Set up account creditAccount credit. Undated.Retrieved 2026-10-08.
  14. Discovery user guideNotice of retirement on October 1, 2026.Retrieved 2026-10-08.

See also

Catalog Rows Cited

6Programs11Rules1SKUs3Metrics

Esc