Trust Lifecycle Manager (TLM) is the DigiCert ONE product that discovers, monitors, automates and governs certificates across an organization’s environments. DigiCert’s documentation says it is CA agnostic and can automate private or public trust certificates from a variety of issuing CAs.[1] DigiCert Private CA is a separate trust source in the same platform that issues non-publicly trusted certificates for systems an organization controls.[2] The two are licensed separately: TLM by seats, Private CA by counts of roots, intermediate CAs and end-entity certificates.
Trust Lifecycle Manager: current model
DigiCert states that TLM operates on a subscription licensing model. The current model, being introduced in October 2025, uses multi-tiered plans, Essentials, Advanced and Premium, and a single, unified seat licence type across all of them. Seats are the licensing unit, and each seat entitles the customer to use DigiCert’s discovery, management and automation tools; seats may be consumed for servers, sites, users and devices.[3] The plans differ in capability and in per-seat price, not in the unit counted, and documentation says seat pricing varies by plan and reflects the management capabilities included.[3] Customers can compare plans in DigiCert ONE under the account’s Licenses section, where higher plans include everything from the level below.[4]
The Services Addendum defines the seat in contract terms: a TLM Seat “entitles Customer to use DigiCert’s discovery, management, and automation tools in Trust Lifecycle Manager”, and may be consumed for servers, Sites, Users, devices or other active endpoints managed by TLM according to the customer’s Seat Templates. Some use cases consume more than one seat, depending on those templates.[5] The Seat Templates, which the Services Addendum defines as the number, types, limitations and configurations of seats made available to the customer in its portal account, are therefore part of the entitlement, not a mere configuration detail. Catalog proof: Trust Lifecycle Manager seats cover servers, Sites, Users and devices; Some Trust Lifecycle Manager use cases consume multiple seats.
Sites
A “Site” is a unique fully qualified domain name together with its associated IP address that is hosted on or served by a customer server. The Services Addendum says each distinct combination of an FQDN and an IP address is a separate Site, regardless of whether several FQDNs resolve to one IP address or one FQDN resolves to several IP addresses.[5] Two names on one load balancer address count as two Sites, and one name served from three addresses counts as three. For an asset manager this is the counting rule to apply to inventory data: Sites are derived from name-and-address pairs, not from servers or certificates. Catalog proof: Each FQDN and IP address pair is a separate Site.
Essentials and active endpoints
For subscriptions ordered through CertCentral or another portal, the Subscription Terms say a TLM Essentials seat is consumed per “active endpoint” managed by TLM. An active endpoint includes any endpoint that is discovered through scanning, configured for monitoring, or has a certificate deployed and managed through TLM. Each endpoint is a unique FQDN and IP combination, determined by DigiCert under its then-current seat calculation methodology. Seats are consumed and reassigned dynamically, and the customer is responsible for managing its active endpoints. Endpoints found by automated discovery or scanning are deemed active on detection and consume Essentials seats unless and until removed. Essentials seats may be used solely to manage certificates issued by DigiCert. Certificates imported without an active endpoint do not consume a seat; they stay in the inventory for a set retention period, during which the customer can monitor them or place them under management.[6]
Two consequences follow. A discovery scan can raise seat consumption without anyone ordering a certificate, so scan scope is a licensing decision. And Essentials does not extend to certificates from other issuers, which need a higher plan or a different seat arrangement. Catalog proof: TLM Essentials seat is consumed per active endpoint, including discovered ones; TLM Essentials manages DigiCert-issued certificates only.
Discovery and managed automation
To run object discovery, the customer installs a DigiCert agent on a target server or a sensor in its network; the Services Addendum defines “Server” here as a physical or virtual server (a virtual machine), not a CPU.[5] Discovery finds certificates and keys on a service and scans binaries and archives for algorithms in order to spot weak ciphers.[5] For plans, DigiCert’s notice on the CertCentral Discovery service says cloud scans need an Essentials subscription and network scans an Advanced subscription; that service is retired on October 1, 2026 and its capabilities move to TLM.[7] Managed automation needs an Automation feature on the account and, under the current model, a subscription plan that includes fully managed automation and has seats available. The customer can check whether the plan includes it by looking for the Agents and Sensors options under Discovery and automation tools.[1] Catalog proof: Managed automation needs a plan or seat type that includes automation; Discovery agent target is a server, not a CPU.
Add-ons and other items in the seat table
The Services Addendum lists DigiCert Continuous Validation as an add-on available only to TLM customers, entitling use for one domain.[5] It also lists DigiCert AI Trust Manager, counted by managed AI assets (agents, models and MCP servers) based on active passports, and DigiCert Quantum Central, for the discovery, remediation and governance of up to 1,000 crypto assets during the entitlement period.[5] These sit outside the TLM seat but are bought on the same Quote.
Seat allocation
Within the product, seat licences are allocated through business units. Discovered or imported certificates have seats allocated automatically; for other certificate types seats must be allocated to a business unit before certificates are enrolled. The dashboard reports Allocated, Created and Consumed seats, where Consumed counts seat records that have a certificate associated with them.[8] Deleting a consumed seat releases it back to the licence pool.[8] These counters are the first place to look when reconciling a Quote. Catalog proof: Seat licences are allocated to business units.
Trust Lifecycle Manager: legacy model
Subscriptions that began before October 2025 and have not moved to the current model use separate seat types, each entitling a specific certificate use case.[3]
| Legacy seat type | Issuing CA | Entitles |
|---|---|---|
| User | DigiCert Private CA or CertCentral | A public or private certificate issued to a person |
| Device | DigiCert Private CA | A private certificate issued to a physical device |
| Server | DigiCert Private CA | A private certificate issued to an internal server |
| Organization | DigiCert Private CA | A private certificate for an organization, used for private issuing CAs or private code signing |
| Imported | Any | A certificate from an external CA uploaded to TLM whose issuing CA was imported into Private CA |
| Discovery | Any | A certificate discovered and added to the account |
| Certificate management | Any | A certificate from an external CA managed in TLM through a CA connector |
The managed-automation prerequisites for the legacy model are Server seats, to automate private certificates from Private CA, and Certificate management seats, to automate certificates from issuing CAs outside Private CA.[1] The Services Addendum lists a User Seat, Organizational Seat, Device Seat, Server Seat and a Management Seat as “(Legacy)” seat types. A Management Seat entitles management of one certificate (a “Managed Certificate”), which may have been issued by a third-party issuer, and the customer may remove a certificate so that it is no longer a Managed Certificate, although it will still appear in reports.[5] The Services Addendum also reserves DigiCert’s right to revise User Seat pricing on notice if it reasonably believes the customer’s use cases are excessive.[5] Legacy seat types may not be available for new purchases but may continue to be used.[5] Catalog proof: Trust Lifecycle Manager legacy seat types; Managed Certificate; Legacy Trust Lifecycle Manager model uses seven seat types.
DigiCert Private CA
DigiCert Private CA operates on a subscription licensing model with a current model introduced in October 2025. Subscriptions that began earlier may follow the legacy model.[9] The current model has three licence types.[9]
| Licence type | One licence is consumed when you |
|---|---|
| Private root certificates | Establish a trust anchor, import trusted roots from DigiCert-hosted or third-party PKI setups, or create online or offline roots |
| Private intermediate CA (ICA) certificates | Issue, create or import an intermediate CA |
| Private end-entity certificates | Issue end-entity certificates for servers, users, organizations, code signing or wildcards |
The legacy model counts root certificates, intermediate CA certificates and dynamic intermediate CA certificates; the last is consumed when issuing multi-tenant or customer-specific certificates, short-lived or isolated trust chains for automated pipelines, or unique intermediate CAs per workload in CI/CD and IoT deployments.[9] The Services Addendum states the same units as seats: a Private Root CA Seat entitles the creation and use of one non-publicly trusted root, a Private Intermediate CA Seat one non-publicly trusted intermediate, and a Private End-Entity Seat the issuance of one or more non-publicly trusted certificates, consumed according to the customer’s Certificate Templates, with some use cases consuming multiple seats.[5]
DigiCert-hosted customers have a soft limit on each licence type and may exceed it, incurring overages. On-premises customers have a hard limit and cannot exceed the allotted number. A consumption report is available in the Private CA account.[9] A private CA is also limited by environment: DigiCert documents that no more than one Private CA can be in an environment and that it cannot be shared with another environment, though it can be shared across products inside it.[2] Catalog proof: Private Root CA Seat; Private Intermediate CA Seat; Private End-Entity Seat; Private CA on-premises licences are a hard limit.
Counting practice
- Reconcile TLM against the Quote’s seat count and the Seat Templates, and against the Consumed counter per business unit.
- For Essentials, count Sites (FQDN and IP pairs) found by scans, monitoring and managed certificates, and remove endpoints that should not be managed.
- For Private CA, count roots, intermediates and end-entity certificates separately, by deployment model.
- Expect an Excess Usage Fee at the end of the period if a seat count is exceeded; see DigiCert Master Services Agreement and service terms.
- Note which of the customer’s seat types are marked (Legacy), because they may not be renewable as sold.
Out of scope
This article does not cover TLM integrations with third-party CAs and device management products, certificate profile design or the CA connector catalogue. It does not cover public certificates issued through CertCentral, which are in CertCentral and TLS certificate licensing, or DigiCert’s signing and device products.