Certificate Lifecycle Management Diana Štefaníková 28. 1. 2025

Certificate Lifecycle Management

Say goodbye to manual management.
Automate your certificate lifecycle and simplify your IT with our on-premises CLM.

  • Full Automation
  • On-Premises Installation
  • Regulatory Compliance

Book Your Live Demo:

Book Your Live Demo:

eli_bw
eon_bw
ahold-delhaize_bw
cez_Group_bw (1)
vig_bw
vlada-cr_ENG_bw (1)

Certificate lifecycle: 200 → 100 → 47 days

Since March 2026, public TLS certificates have had a maximum validity of 200 days, and by 2029 this period will drop to 47 days. At this pace, manual certificate issuance is no longer viable for a large organisation. Institutions subject to DORA and NIS2 must also maintain an accurate, centralised and continuously updated inventory of all certificates and cryptographic keys.

Today

200 days – the rule in force today

Public TLS certificates issued today have a maximum validity of 200 days, and a completed domain validation can be reused for the same period.

100 days – the step that changes the process

The maximum validity period drops to 100 days, and domain validation reuse is restricted accordingly. A certificate issued in January expires in April.

This is the point at which an annual cycle becomes a quarterly one. Spreadsheets and calendar reminders will not fail dramatically at this stage – but they are simply no longer a reliable control, because a single overlooked row already means a service outage. For a supervised institution, that outage is also a reportable ICT-related incident.

47 days – renewal without human intervention

The maximum validity period is 47 days, and a domain validation can be reused for 10 days. Every certificate is replaced roughly eight times a year.

Why choose our Certificate Lifecycle Management?
CLM dashboard with overviews of valid and expiring certificates
Modular architecture
Full automation
Regulatory compliance
On-premises deployment
Fast installation
Custom development
konfigurator-mockup-4

Too complicated?

Try CLM Configurator

Not sure which modules you need to automate certificate management? Answer a few questions to get a specific list of features and their implementation process.

Implementation

How does a CLM deployment work in practice?

1

Discovery workshop

We map your use cases, certification authorities, the systems that rely on certificates, and your current renewal process.

2

Proof of concept

Installation in your test environment and validation of specific use cases before you commit to a full rollout.

3

Production deployment

Following installation in the production environment, integrations with certification authorities, load balancers, servers and applications go live, and your administrators are trained.

4

Support and SLA

Agreed response times, updates and direct access to the system’s developers.

MOCKUP_datasheet_CLM

Datasheet CLM

Technical Solution Description

Supported CLM Protocols

Monet+ CLM is an on-premise Certificate Lifecycle Management platform designed to automate the full lifecycle of digital certificates, including issuance, renewal, and revocation. The system supports standardized protocols to facilitate automated certificate enrollment across diverse network entities.

ACME protocol · RFC 8555

Implementation of a general-purpose ACME server in accordance with RFC 8555, compatible with the most widely used ACME clients worldwide.

The unique ACME External Account Binding concept is tailored specifically to the internal ACME server model, in which certificates are issued by an internal certification authority. Suitable for SSL certificates (Domain Validation certificates).

Book a free demo and discover how we can simplify your digital certificate management.
Scroll to Top