LICENSEWARE

DigiCert Master Services Agreement and service terms

This article is about the contract documents that govern DigiCert purchases: the Master Services Agreement, Service Specific Terms, Services Addendum, Transactional Subscription Terms and the Web PKI Certificate Terms of Use. For product metrics see the DigiCert licensing overview. It is not legal advice.

On This Page

DigiCert’s commercial terms are spread over several documents that reference each other. Reading a purchase correctly means identifying which document governs which part of it: the Master Services Agreement (MSA) for the legal relationship, the Service Specific Terms for service-by-service additions, the Services Addendum for entitlements, overage and audit on DigiCert ONE products, the Transactional Subscription Terms and Conditions for CertCentral subscriptions, and the Certificate Terms of Use for the certificates themselves.

The document stack

The MSA is made between the customer and the “DigiCert Contracting Party” and applies together with appendices, addenda, Order Forms, schedules and other terms referenced in it. The Service Specific Terms are incorporated by reference.[1] The Contracting Party depends on the billing address: DigiCert, Inc. (a Utah corporation) for the United States, DigiCert Ireland Limited for any country other than the United States or Japan, and DigiCert Japan G.K. for Japan. If a customer changes its billing address to another country, the MSA is assigned to the corresponding Contracting Party without further action.[1] Catalog proof: The DigiCert contracting party depends on the billing address.

The Service Specific Terms say they apply only to the services to which they relate, and that if they conflict with the definitive agreement governing a purchase, the Service Specific Terms control.[2] For certificate orders they direct customers to the applicable Certificate Terms of Use, the Certification Practices Statement and the Privacy Policy in DigiCert’s legal repository. Separate Terms of Use exist for publicly trusted TLS/SSL certificates, publicly trusted S/MIME certificates, qualified certificates, X9 certificates and all other certificates.[2] For services related to DigiCert ONE, Software Trust Manager, Trust Lifecycle Manager and similar offers, and for enterprise certificate subscriptions through CertCentral, the Services Addendum applies.[2]

The Transactional Subscription Terms apply to services ordered on subscription through CertCentral or another portal. They state that if they conflict with the MSA, the Subscription Terms control, and that customers must agree to them before using the subscription services.[3]

Order Forms and Quotes

Under the MSA a customer buys specific services through quotes, purchase schedules, purchase orders or order forms that name the services, the Service Term and the payment terms. An order form is “mutually agreed” when both parties sign it, when the customer electronically accepts one that DigiCert presents, or when DigiCert presents one and the customer accepts it by issuing a purchase order.[1] The Services Addendum applies the same idea to Quotes. Each accepted Quote is an Order Form, and the customer is to issue a purchase order for the full amount of annual fees on acceptance and on or before each anniversary of a Service Term. Additional or modified terms in a customer purchase order are expressly rejected.[4]

Entitlements, expiry and the Excess Usage Fee

The Services Addendum is the key document for counting. Quotes set a customer’s entitlement to seats, certificate subscription services and related services, and specify a stated period for each entitlement, for example quarterly or annually. Entitlements expire at the end of the stated period and the customer gets no credit, refund or rollover, including if it fails to use the entitlement. If the customer exceeds its entitlement at any time during the period, DigiCert invoices an Excess Usage Fee at the end of the period applicable to the excess services, calculated under the Service Description unless the Quote says otherwise.[4] The fee is the number of excess entitlements multiplied by the price of the entitlement. Where excess services also carry support, an excess usage fee for support is calculated by applying the applicable support pricing method to the excess fees.[4]

For certificates bought as Certificate Subscription Services on a minimum commitment basis, the excess is calculated from the SANs on issued and active TLS certificates and from non-TLS certificates, each measured at peak usage in the entitlement period, multiplied by the price at peak usage.[4] A Remaining Certificate Plan Life Fee applies if the subscription is not renewed. It is calculated in aggregate as the price of each issued and active non-TLS certificate and each SAN on an active TLS certificate on the last day of the Service Term, divided by 12, multiplied by the estimated remaining certificate life. The customer can avoid the fee by revoking all the certificates within 24 hours of the entitlement’s expiration, and if it pays the fee it keeps portal access solely to manage existing certificates until they expire or are revoked.[4] The Subscription Terms contain a parallel formula for subscription services: the number of each entitlement on the last day of the Service Term multiplied by the annual entitlement price divided by 12 and by the months of validity remaining.[3] Catalog proof: Excess Usage Fee is invoiced at the end of the period; Excess Usage Fee equals excess entitlements times the entitlement price; Certificate subscription overage is measured at peak usage; Remaining Certificate Plan Life Fee applies if a certificate subscription is not renewed.

Under the Subscription Terms, the service term is one year from purchase, renewing yearly until cancelled at then-current prices. Services bought during the term are charged pro rata for the remaining days and at the full annual amount on the next renewal. A customer that exceeds its entitlement owes an excess usage fee and authorizes DigiCert to charge it to the payment method on the account at the beginning of the next Service Term without further notice.[3]

Fees, payment and price escalation

Unless a Quote says otherwise, DigiCert invoices all fees in advance on acceptance of the Quote and the customer pays within 30 days of the invoice date.[4] The MSA states that fees are paid for the provision of services and are not a royalty or licence fee. Undisputed amounts not paid by the due date accrue interest at 1.5% of the outstanding balance per month, or the lawful maximum if lower, DigiCert may accelerate unpaid fees, and it may suspend or limit access without notice. Disputes must be raised within 30 days of the invoice date or the invoice is deemed accepted.[1] Funds put into a portal account that are not tied to an order must be used within 12 months, after which they are treated as earned.[1] Catalog proof: Invoices are issued in advance and payable within 30 days; Fees are not a royalty or licence fee and late amounts accrue 1.5% a month.

The Services Addendum includes an annual escalator. On each anniversary of a Quote, fees for services increase by the greater of 3% and the percentage increase in the “Inflation Adjustment Metric”. That metric is the US consumer price index for customers in the Americas and countries not otherwise covered, the euro area harmonised index for customers in Europe, Russia, the Middle East or Africa, Japan’s consumer price index for customers in Japan, and the International Monetary Fund East Asia consumer price figure for customers in Asia outside Japan, Australia, New Zealand or the Pacific.[4] DigiCert may calculate the increase from then-available numbers before each anniversary. The clause applies on every anniversary of a Quote, so a multi-year commitment is exposed to it each year. Catalog proof: Inflation Adjustment.

Entitlement verification and audit

Under the Services Addendum the customer must keep systems and procedures that let it track, document and report installations, deployment, access and operation of each service in the quantities and versions used, and that let DigiCert audit them. DigiCert or its contractors give at least ten days’ written notice and audit during normal business hours at the customer’s facilities. If the audit finds use above the entitlement or outside the scope of the licence (“Overuse”), the customer pays for all Overuse quantities at DigiCert’s then-existing list price plus interest on past due amounts, and if Overuse is more than 5% of the entitlement it also reimburses DigiCert’s reasonable out-of-pocket audit costs. Unless a signed agreement says otherwise, DigiCert does not submit to customer audits.[4] The clause is tied to the Services Addendum, so it governs DigiCert ONE products and enterprise subscriptions rather than ordinary certificate purchases. Catalog proof: DigiCert may audit entitlements on ten days’ notice; Overuse above five percent shifts audit costs to the customer. See also the software license audit and true-up concept articles.

Use restrictions, on-premises software and resale

The MSA restrictions bar a customer from, among other things, reverse engineering the services (except interoperability decompilation of on-premises software where law permits), transferring or sublicensing the services, using them “for the benefit of a third party” in a service bureau, facility management, timeshare or service provider activity, benchmarking them or using them to build a competing product, and scanning a DigiCert IP address without prior written consent.[1] The service bureau restriction matters to managed service providers and shared-service teams that operate DigiCert products for other legal entities. Catalog proof: Service bureau use of the Services is prohibited.

Where a service includes on-premises software, DigiCert grants a non-exclusive, non-transferable licence to use, reproduce and install a reasonable number of copies on the customer’s hardware, solely in connection with the services the software accompanies, and it may restrict where the software is installed.[1] The software may include open source components whose licences are not altered by the MSA.[1] Purchases for resale are governed by a separate Master Partner Agreement.[1] The customer cannot assign the MSA without DigiCert’s written consent, while DigiCert can assign without consent.[1] Catalog proof: On-Premises Software licence covers a reasonable number of copies; Resale purchases fall under the Master Partner Agreement; Customer may not assign the Agreement without consent.

Liability and termination

Either party may terminate the MSA immediately if the other materially breaches and fails to remedy within 30 days of notice, or on listed insolvency or fraud events.[1] DigiCert’s limitation of liability caps its total cumulative liability at the amounts the customer paid in the twelve months before the event giving rise to liability, and bars claims brought more than one year after the basis for the claim becomes known to the customer, subject to carve-outs for death or personal injury from negligence, gross negligence or wilful misconduct, and fraud.[1] DigiCert’s intellectual property indemnity is limited to copyright, patent or trademark rights in the United States.[1]

Other service terms

  • Third-party components. Thales, Gemalto or SafeNet products bought from DigiCert are subject to Thales terms. Software Trust Manager Threat Detection uses ReversingLabs components under the ReversingLabs end-user licence agreement, and Device Trust Manager uses HiveMQ components under the HiveMQ end user licence agreement.[2]
  • Trial and beta offerings. Rights are solely for internal testing and evaluation, production use needs DigiCert’s written approval, and DigiCert may discontinue them at any time.[2]
  • HSM Services. When DigiCert hosts hardware security modules for a customer’s keys, DigiCert keeps title to the HSMs and may migrate keys between them. Unless the Order Form says otherwise the minimum Service Term is three years. The customer may retrieve a dedicated HSM on 30 days’ notice by paying a retrieval fee and, if retrieving before the end of the term, the remaining service fees without refund or credit.[4] Catalog proof: HSM Services have a three-year minimum term.
  • Channel partners. For certificate subscriptions bought through a partner, pricing and payment terms are those agreed with the partner, but DigiCert may still invoice the customer directly for usage.[4]

Web PKI Certificate Terms of Use

The Terms of Use for publicly trusted TLS/SSL certificates (DV, OV and EV, including wildcard) apply on top of the MSA and the Certification Practices Statement. They limit use to domain names the subscriber owns or is explicitly authorized to use, and allow installation on several servers or devices only if all are under the subscriber’s control. The certificates are for TLS/SSL web server security and must not be used for email encryption, code signing, document signing or VPN authentication.[5] Subscribers must protect the private key, accept the certificate’s contents, stop using a certificate on expiry or revocation and respond promptly to DigiCert’s inquiries. DigiCert may revoke at any time, without notice, for breach or where required by the Certification Practices Statement, law or industry standards, and the subscriber waives damages for a conforming revocation.[5]

DigiCert states that it revokes within 24 hours for listed critical events, such as private key compromise or a subscriber’s written revocation request, and within 5 days for other events, such as a certificate that no longer meets technical standards.[5] It does not support pinning of its certificates or keys and will not delay revocation for a pinned environment.[5] Any Relying Party Warranty runs to persons who rely on a certificate in good faith, not to the subscriber.[5] Catalog proof: Web PKI certificates must be revoked within 24 hours or 5 days in listed events; DigiCert does not support certificate pinning; Relying party warranty does not run to the subscriber.

Out of scope

This article does not reproduce the Certification Practices Statements, the Relying Party Agreement or the QTSP terms, and it does not address tax, data processing or privacy terms. It covers neither the Services Addendum’s China privacy consent nor professional services scoping beyond what is cited. Product-level counting rules are in the other DigiCert articles listed under See also.

References

  1. Master Services Agreement (English text, Japanese edition, Version: 9 February 2026)English text of the Japanese edition: sections 1.4, 2, 3.1, 4.2, 5.1, 7, 8.3, 9.5. Version: 9 February 2026.Effective 2026-02-09. Retrieved 2026-10-08.
  2. Service Specific Terms (Version: 1 September 2025)Sections 1 to 6: Certificate Terms of Use, Services Addendum, Thales, ReversingLabs, HiveMQ and Trial/Beta terms. Version: 1 September 2025.Effective 2025-09-01. Retrieved 2026-10-08.
  3. Transactional Subscription Terms and Conditions (Version: 18 May 2026)Sections 1 to 5: Service Term, entitlement table, Remaining Certificate Plan Life Fee, TLM Essentials terms. Version: 18 May 2026.Effective 2026-05-18. Retrieved 2026-10-08.
  4. Services Addendum (Version: 28 September 2026)Section 1 definitions; section 2 purchases and entitlements; Schedule 1 seat table, Site, Certificate Subscription Services, HSM Services, inflation adjustment, entitlement verification. Version: 28 September 2026.Effective 2026-09-28. Retrieved 2026-10-08.
  5. DigiCert Web PKI Certificate Terms of Use: Publicly Trusted TLS/SSL (Last Updated: August 25, 2025)Sections 1 to 10. Last Updated: August 25, 2025.Effective 2025-08-25. Retrieved 2026-10-08.

See also

Catalog Rows Cited

17Rules5Programs1Metrics

Esc