Certificate Lifecycle Management
Say goodbye to manual management.Automate your certificate lifecycle and simplify your IT with our on-premises CLM.
- Full Automation
- On-Premises Installation
- Regulatory Compliance
Book Your Live Demo:
Book Your Live Demo:
Certificate lifecycle: 200 → 100 → 47 days
Since March 2026, public TLS certificates have had a maximum validity of 200 days, and by 2029 this period will drop to 47 days. At this pace, manual certificate issuance is no longer viable for a large organisation. Institutions subject to DORA and NIS2 must also maintain an accurate, centralised and continuously updated inventory of all certificates and cryptographic keys.
200 days – the rule in force today
Public TLS certificates issued today have a maximum validity of 200 days, and a completed domain validation can be reused for the same period.
100 days – the step that changes the process
The maximum validity period drops to 100 days, and domain validation reuse is restricted accordingly. A certificate issued in January expires in April.
This is the point at which an annual cycle becomes a quarterly one. Spreadsheets and calendar reminders will not fail dramatically at this stage – but they are simply no longer a reliable control, because a single overlooked row already means a service outage. For a supervised institution, that outage is also a reportable ICT-related incident.
47 days – renewal without human intervention
The maximum validity period is 47 days, and a domain validation can be reused for 10 days. Every certificate is replaced roughly eight times a year.
Too complicated?
Try CLM Configurator
Implementation
How does a CLM deployment work in practice?
Discovery workshop
We map your use cases, certification authorities, the systems that rely on certificates, and your current renewal process.
Proof of concept
Installation in your test environment and validation of specific use cases before you commit to a full rollout.
Production deployment
Following installation in the production environment, integrations with certification authorities, load balancers, servers and applications go live, and your administrators are trained.
Support and SLA
Agreed response times, updates and direct access to the system’s developers.
Datasheet CLM
Technical Solution Description
Supported CLM Protocols
Monet+ CLM is an on-premise Certificate Lifecycle Management platform designed to automate the full lifecycle of digital certificates, including issuance, renewal, and revocation. The system supports standardized protocols to facilitate automated certificate enrollment across diverse network entities.
ACME protocol · RFC 8555
Implementation of a general-purpose ACME server in accordance with RFC 8555, compatible with the most widely used ACME clients worldwide.
The unique ACME External Account Binding concept is tailored specifically to the internal ACME server model, in which certificates are issued by an internal certification authority. Suitable for SSL certificates (Domain Validation certificates).
EST protocol · RFC 7030
Implementation of the EST protocol in accordance with RFC 7030, with dynamic configuration of authorisation rules for EST endpoints – supporting authentication via client certificate or username and password.
Optionally, the device serial number in the certificate request is verified. Suitable for, but not limited to, network device certificates.
SCEP protocol · RFC 8894
Implementation of the SCEP protocol in accordance with RFC 8894, suitable, among other uses, for network device certificates.
Proprietary protocol
We can develop support for a proprietary protocol tailored to the customer’s needs. Applicable to devices or systems with custom PKI interface implementations.
CLM protocol
Manual certificate issuance via the CLM portal – either through a form or by CSR import.
With the form, the user enters the certificate parameters (identification data); the CLM system generates the keys and the CSR and issues the certificate, which can then be exported together with the private key. With CSR import, the administrator imports an already generated certificate signing request.
KMIP protocol · OASIS
Implementation of the OASIS KMIP standard with support for multiple protocol versions for universal use. It manages the entire lifecycle of encryption keys – creation, policy management and deletion – including the secure connection of applications to a hardware security module (HSM).
Predefined scenarios cover VMware vSphere and vSAN encryption of virtual machines and disk arrays, database encryption with centralised protection and key management for core databases, and backup software such as CommVault, where sensitive backups and data are encrypted before being written to disk or tape.
Other features
Integration with network devices (e.g. F5 BIG-IP), cloud workloads (Kubernetes/Docker), and internal and public certification authorities (CAs), including public CAs in the Czech Republic and Slovakia.
Support for strong cryptography as a crypto-agile solution. We are ready for post-quantum cryptography (PQC).