DigiCert’s non-TLS “trust workflow” products are metered by what the customer does with keys and certificates: how many signatures it produces, how many devices it manages or how many documents it signs. The Services Addendum’s Schedule 1 holds the contractual seat descriptions, and the product documentation holds the plan details.[1][2]
Software Trust Manager
Software Trust Manager secures code signing, releases and software supply chain workflows.[2] DigiCert’s documentation says an account may use either the current or the legacy licensing model, depending on when the subscription began. The current model, being introduced in September 2026, offers Essentials, Advanced and Premium plans and a single unit licence type. The current plans add secure release features not available to legacy customers.[3]
Current model
Each licensing unit can be used for up to 1,000 software signatures, and the Services Addendum describes the entitlement the same way, as up to 1,000 software signing events during the applicable entitlement period.[3][1] All plans include at least one HSM keypair when buying one or more units. Advanced and Premium plans include two HSM keypairs when buying 10 or more signing units, and Premium includes three when buying 20 or more. Additional HSM keypairs are available for a fee, and unit pricing varies by plan.[3] Catalog proof: Software Trust Manager units cover up to 1,000 signatures and include HSM keypairs; Software Trust Manager signing unit.
Legacy model
Subscriptions that began before September 2026 and have not transitioned use separate unit types for signing, cryptographic operations, testing, key management and threat detection.[3] DigiCert describes each.[4]
- Signature units count the hashes signed with a production keypair; every hash signed consumes one unit.
- Test signature units count hashes signed with a test keypair, again one unit per hash.
- Cryptographic units count all operations on cryptographic assets other than signatures: creating, updating, exporting or importing a keypair; creating, updating, importing or revoking a certificate; and generating a certificate signing request.
- Threat detection is measured in gigabytes scanned, one unit per gigabyte.
- HSM keypair units count keypairs created on DigiCert’s HSMs, with space sized to the public trust certificates licensed.
Hosted customers have a soft limit on signature units and may exceed it with overages, while HSM keypair units are a hard limit that cannot be exceeded unless Sales amends the licence.[4] The Services Addendum also lists a “Software Trust Manager - Code Signing Seat (Legacy)”, which entitles the customer to sign a single file once with a code signing certificate; four files signed three times consume twelve seats.[1] A build pipeline that signs the same artifact repeatedly can therefore multiply consumption under legacy terms. Catalog proof: Software Trust Manager signature unit; Software Trust Manager cryptographic unit; HSM keypair unit; Code Signing Seat (Legacy).
Third-party and hosted HSM terms
Software Trust Manager Threat Detection includes ReversingLabs components, whose use is subject to the ReversingLabs end-user software licence agreement.[5] When DigiCert hosts HSMs for a customer’s keys under the HSM Services terms, DigiCert retains title to the HSMs, the minimum Service Term is three years unless the Order Form says otherwise, and a dedicated HSM can be retrieved on 30 days’ notice for a retrieval fee and any remaining service fees.[1] Catalog proof: HSM Services.
DigiCert KeyLocker
DigiCert KeyLocker holds code signing certificates for signing. Its licensing page says KeyLocker certificates have a standard service fee regardless of validity period, entitling the customer to one signer and 1,000 signatures per certificate. Signatures can be bought in increments of 1,000. DigiCert updated the KeyLocker terms on November 3, 2023 to restrict customers to 1,000 signatures per certificate and one designated signer per certificate.[6]
Signatures are tied to the certificate’s validity, at 1,000 for each year the certificate is valid (2,000 for a two-year certificate and 3,000 for a three-year one), and remaining signatures cannot be transferred to another certificate. DigiCert-hosted customers have a hard limit and cannot exceed the signature limit, but can buy more signatures in CertCentral while the certificate is valid.[6] Each binary or artifact signed consumes one signature unit. Signing an outer binary that embeds internal binaries may consume several units, and batch signing with the SMCTL tool does not reduce consumption.[6] Several users can exist in a KeyLocker account, but only one can be assigned to each certificate, and a KeyLocker lead can reassign the user at any time. On CertCentral retail subscription accounts, a code signing certificate gets 1,000 signatures usable until the subscription expires, and 1,000 more are added on renewal.[6] The Services Addendum lists a separate KeyLocker Seat that entitles a user to access private keys for up to 1,000 signing events.[1] Catalog proof: KeyLocker allows 1,000 signatures per year of certificate validity; KeyLocker batch signing does not reduce signature consumption; KeyLocker assigns one signer per certificate.
Device Trust Manager and the TrustEdge Client
Device Trust Manager establishes and manages trusted device identities throughout the device lifecycle.[2] It has two subscription plans with different counting units.[7]
| Plan | What it covers | Licensing type | How it is counted |
|---|---|---|---|
| Essentials | Single-use certificates, such as private, CSA Matter DAC, ISO 15118 and C2PA certificates; no device records | Per certificate | Each certificate issued uses one licence, and a renewal uses another |
| Advanced | Full device management with OTA updates, multiple certificates per device and automated workflows | Per device | Each registered device uses one licence; multiple certificates per device at no extra cost |
Both plans are yearly. Buying 10,000 Essentials licences allows up to 10,000 certificates a year during the agreement, for the same or different devices, and 10,000 Advanced licences cover 10,000 registered devices, billed each year at that number unless changed.[7] Unmanaged CAs and public TLS/SSL certificates are optional add-ons at extra cost under both plans, and the subscription also carries recurring fees for each private root CA and intermediate CA.[7] DigiCert-hosted customers have a soft limit and incur overages if they exceed their licences; on-premises customers have a hard limit.[8] Catalog proof: Device Trust Manager Essentials license; Device Trust Manager Advanced device license; Device Trust Manager limits are soft when hosted and hard on premises.
The Services Addendum describes the same Essentials and Advanced seats, and says Device Trust Manager includes and requires the use of TrustEdge Clients, an application provided in compiled binary form that must be installed on each device to connect to the portal.[1] DigiCert allows download and use of the TrustEdge Client without first buying seats, as the “Freeware TrustEdge Client”, for non-commercial use only, with an allowance for pre-production pilots and proofs of concept before seats are bought for production. A legacy “TrustEdge Client Device Seat” entitles installation and management of the client on a device, and a legacy “TrustCore Device Seat” entitles use of applications developed with TrustCore, an SDK that DigiCert supplies in source code.[1] Device Trust Manager also uses HiveMQ components under the HiveMQ end user licence agreement.[5] Catalog proof: Freeware TrustEdge Client is limited to non-commercial use; Freeware TrustEdge Client.
IoT Trust Manager
IoT Trust Manager operates on a subscription licensing model with four licence types: end entity certificates, the number of certificates the product can issue to end entities; end entity devices, the number of device certificates issued to actual devices; intermediate CA certificates; and intermediate CA devices. Hosted customers have a soft limit and incur overages, and on-premises customers have a hard limit.[9] Catalog proof: IoT Trust Manager meters certificates, devices and CAs separately.
Content Trust Manager
Content Trust Manager protects the authenticity, integrity and provenance of documents and digital media.[2] Its licences are seats, which let a customer’s users issue certificates according to the customer’s certificate templates, and signature units, which let users sign documents with a purchased signing certificate in the volume bought on an approved quote. The limit is soft unless a hard limit is requested, in which case overages are incurred if it is exceeded; on-premises customers have a hard limit.[10] The Services Addendum lists Individual Document Signing and Organization Document Signing Seats, a Content Trust Manager C2PA entitlement of up to 1,000 C2PA signing events in the entitlement period using DigiCert’s signing engine, and a separate C2PA Service for customers that use their own signing engine with dedicated DigiCert C2PA certificates and DigiCert timestamping.[1] DigiCert states that it may revise user seat pricing on notice if it reasonably believes a customer’s use cases are excessive.[10] Catalog proof: Content Trust Manager signature unit; Content Trust Manager limits are soft unless a hard limit is requested.
DigiCert DNS
DigiCert DNS manages authoritative DNS for availability, performance, resiliency and traffic routing.[2] A Query Seat entitles the customer to up to one million authoritative DNS queries on its domains, and a Query Log Seat to one query log capture. The entitlement period for each DNS seat is one month, so entitlements begin again each month, and excess usage is invoiced monthly in arrears unless a Quote says otherwise.[1] Catalog proof: DigiCert DNS Query Seat; DNS Seats are measured per month in million-query blocks.
Evaluation and pre-release use
Trial, preview and beta features are for internal testing and evaluation only. Production use requires DigiCert’s written approval, and DigiCert may discontinue them at any time.[5] An asset manager should keep such environments out of production entitlement counts and record any written approval. Catalog proof: Trial and beta offerings are for internal evaluation only.
Out of scope
This article does not cover Software Trust Manager signing tool configuration, the Apple, Microsoft or Java signing procedures, or the content of the CSA Matter, ISO 15118 and C2PA programmes. It does not cover Thales hardware, which is governed by Thales terms.[5] Public TLS certificates and subscriptions are in CertCentral and TLS certificate licensing, and certificate lifecycle seats are in Trust Lifecycle Manager and Private CA licensing.