Managed Detection & Response Service for Enterprises
Our Swiss SOC offers comprehensive threat detection and quick response to protect your company's critical business assets and your reputation.
Automated Certificate Lifecycle Management CLM
What is CLM?
Certificate Lifecycle Management automates the management of digital certificates across their entire lifecycle – enrollment and deployment to renewal or revocation – regardless of the underlying PKI technology. As digital certificates are essential for secure communication, encryption, and trusted digital identities, CLM helps organizations maintain security and compliance.
However, with growing certificate volumes, shorter validity periods, and stricter regulations, management becomes more complex. Swiss Post Cybersecurity's CLM helps organizations automate processes, minimizes risk, and ensures continuous certificate visibility and control.
The added value of CLM for organizations
Digital Sovereignty
Swiss Post Cybersecurity is your implementation and hosting partner for CLM. We operate your CLM instance on Swiss infrastructure using a European tool.
Why should your organization care about CLM now?
There are four main reasons why Swiss Post Cybersecurity recommends caring about CLM now. Waiting is no longer an option.
More about this will also be explained in our CLM webinar on September 3, 2026. Register now for free.
Post-quantum migration has started
Organizations must act before quantum computers become a reality. They should understand the risks and address them.
- Crypto-agility will become a necessity, almost mandatory.
- Current certificates will need to be replaced (new algorithms)
- A time-bounded threat, predicted to arrive 2030 to 2035
- "Harvest now, decrypt" later makes todays data vulnerable
- Recommendations by NIST and ANSSI
Rising pressure caused by compliance and regulations
Certificates and keys have already become a board-level compliance topic.
- NIS2 requires full inventory and continuous management of crypto assets
- DORA requires proof of operational and cryptographic resilience
- ISO 27001:2022 focuses on key, certificate and algorithm management
- eIDAS 2.0 reinforces strong digital identities and trust
Validity periods are shrinking dramatically
Explosion of certificate usage
For some organizations, the number of machine identities is already 60 times higher than that of human identities. Just consider the proliferation of APIs, microservices, containers and connected devices. Furthermore, cloud and AI services increase the number of short-lived certificates.
Shrinking validity periods and growing CA numbers will increase the workload for all IT security teams, who will constantly need to update these certificates.
Management of certificates will become more and more complex, time-consuming and expensive.
Which components should a modern CLM tool provide?
Swiss Post Cybersecurity has defined three essential components for a CLM. Based on these criteria we decided to use the Certificate Lifecyle Management service from SwissSign, powered by Evertrust. Live demo on September 3, 2026.
- One central console
- Intuitive user interface
- 100 % European sovereignty
-
AUDIT - track your certificates
-
GOVERNANCE – organize your certificates
-
AUTOMATION – reduce manual work
AUDIT - transparency for your certificates
- Discovery by scanning for all public and private certificates, across architectures
- Real-time inventory provided by tracking of discovery, issuance and renewal
- Risk detection by identifying weak algorithms, expired certificates, unauthorized CAs and policy violations
- Centralized visibility by monitoring ownership and proactive alerts before critical expirations
GOVERNANCE – organizing your certificates
- Automatic blocking: Prevent non-compliant certificate requests and apply clear remediation guidance
- Ownership assignment: Link certificates to business units, teams or individuals for accountability
- Tamper-proof audit logs: Track all actions for forensic details
- Quality scoring: Grade certificates based on NIST, ANSSI or other standards to prioritize
- Automated compliance reporting: Schedule email reports and create dashboards for leadership and trend analysis
AUTOMATION – reduce manual work
- End-to-end automation: Create custom workflows for issuance, deployment, renewal and revocation
- Policy-based renewals: Schedule renewals to ensure uninterrupted protection
- Management at scale: Perform bulk operations from mass revocations to policy updates
- Automated deployment: Push certificates across apps and infrastructures
Get in touch with us
Do you want to automate your Certificate Lifecycle Management?
Get in touch with us today.
Ask for a demo free of charge.
How to deploy CLM: Delivery & operational models
We design our solution to be flexible and predictable with regards to costs. Our recommendation: start small with a proof of concept (PoC) and then scale progressively, if needed as you move to a managed solution.
CLM licensing
The "committed usage tiers" licensing model allows predictable costs per certificate holder and scalability as your environment grows. The consultants at Swiss Post Cybersecurity offer support with finding the best solution for each organization.
Delivery and operations
Start with a PoC or opt for a hosted or on-premises solution straightaway.
More about this will also be explained in our CLM webinar on September 3, 2026. Register now for free.
Hosted CLM
CLM is hosted on the Swiss infrastructure of Swiss Post Cybersecurity, who also oversees the platform operations, monitoring and software maintenance. The customer has configuration access to their own CLM instance.
100 % Swiss infrastructure
100 % European CLM tool
On-premises on customer's platform
CLM is hosted on the customer's own infrastructure. The customer is fully responsible for the CLM configuration and the CLM platform operations.
Swiss Post Cybersecurity provides on-demand support.
Proof of concept
If you are not yet sure about the right approach, start with a PoC to validate different solutions before committing.
A pre-defined set of use cases and scenarios will support your evaluation.
Our services for your CLM project
Each project is unique, and we are prepared to customize our services to meet the specific needs of each client.
The following is an example of a standard CLM project, showing the services that could be made use of.
Project Management
Kick-off and workshop to design the solution.
We define requirements, roles and responsibilities, scope and timeline, as well as desired output and deliverables.
Deployment
We handle the CLM software deployment and organize the integration and configuration. Deployment could be on the customer's premises or hosted on the 100 % Swiss infrastructure of Swiss Post Cybersecurity.
Use Cases
Swiss Post Cybersecurity implements selected use cases chosen together during an initial workshop.
Maintenance
Swiss Post Cybersecurity handles recurring software maintenance and product support.
Different SLAs are available offering various kinds of support.
Consulting
Swiss Post Cybersecurity provides consulting services for the CLM solution.
TAMs, Technical Account Managers, are certified and trained on CLM.
100 % Swiss hosting
The customer's CLM solution is hosted in Swiss Post Cybersecurity's cloud in Switzerland.
The customer has configuration access.
Training
Standard training sessions enable the customer's administrators to operate the CLM solution.
Sessions are offered on-site or by video conferencing.
PKI
The management of the customer's public key infrastructure is offered by Swiss Post Cybersecurity as an extension of the CLM solution.
Book a CLM demo for free
Learn more about the CLM tool in a 50-minutes live demonstration.
You will be introduced to the full range of features and learn how the CLM solution can assist you in the management of your certificates.
PKI – safe & compliant with Public Key Infrastructure
Organizations looking for digital trust and maximum security need to rely on their PKI - and even more so as we prepare for the world of quantum computers.
Swiss Post Cybersecurity offers PKI services as a stand-alone option or as an extension to Certificate Lifecycle Management.
-
Certificate Authority Management
-
Certificate Lifecycle Management
-
Revocation & Validation Management
Certificate Authority Management
- Create and manage hierarchical certificate authorities with root, intermediate, and external CA support
- Easily migrate existing legacy PKI without service interruption
- Enforce key unicity to prevent certificate issuance with duplicate private keys
- Visualize complete trust chains including external certificate authorities
Certificate Lifecycle Management
- Issue certificates using customizable templates and business constraints
- Renew, revoke and recover certificates automatically
- Benefit from granular permission management by user or team and approval processes with multi-step workflows
- Customizable notifications and alerts
Revocation & Validation Management
- Automatically generate CRLs with configurable policies
- Benefit from a high-performance OCSP responder compliant with RFC 6960 standards
- Utilize multiple CRL distribution methods: HTTP, LDAP, S3, SCP/SFTP
- Take advantage of an RFC 3161-compliant time-stamping authority with NTP synchronization
Stronger together – our partners for digital sovereignty
Erfolgreiche ISO-Zertifizierung
Swiss Post Cybersecurity ist der Kompetenz und der Qualität unserer Prozesse verpflichtet. Unsere Zertifizierung nach ISO 27001:2022 ist Teil unseres umfassenden ISMS (Information Security Management System), mit dem wir die Vertraulichkeit, Integrität und Verfügbarkeit von Daten sicherstellen.
SwissSign – 100 % Swiss
SwissSign offers Swiss-made certificates and is part of Swiss Post's strong network. Since 2025, SwissSign is also the most important partner of Evertrust in Switzerland.
-
Officially recognized as a Certificate Authority and Trust Service Provider
-
Among the top TLS certificate providers globally for sites with high traffic
-
Data storage, operation and geo-redundant infrastructure located 100% in Switzerland
-
Compliant with ETSI, GDPR, DSG and ISO/IEC 27001; more than 10 audits per year
-
20 years of experience in PKI; trusted partner for banks, energy providers and the public sector
Evertrust – 100 % European
Evertrust, a French cybersecurity vendor, provides a single European platform that unifies Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM), offering an automated and governed control level for digital trust.
By decoupling certificate lifecycle management from the issuing PKI, Evertrust Horizon enables:
- Centralized management of a multi-PKI infrastructure
- Simplified transitions during trust infrastructure changes (PKI migration, CA renewal, trust simplification)
- Cost optimization in certificate lifecycle management
- Sovereignty-aware services designed for hybrid IT + OT
- Deep automation and governance capabilities
- Post-quantum preparedness
Live demo of SwissSign's CLM solution powered by Evertrust on September 3, 2026.
FAQ
Here you will find answers to frequently asked questions about CLM, Certificate Lifecyle Management.
Do I need to replace my existing PKI when using the CLM from Swiss Post Cybersecurity?
No. You can use our CLM with your existing PKIs. You can implement certificates from SwissSign, Evertrust and others without any great migration effort.
What is the difference between PKI and CLM?
- PKI offers core PKI services such as issuing, validating and revoking certificates.
-
CLM is a solution layer on top of PKI. CLM creates transparency through inventories and automates certificates whether from internal or external PKIs or public CAs.
Is the CLM solution by Swiss Post Cybersecurity on-premesis, SaaS or hybrid?
Our CLM solution supports all models, meaning that you can choose between an on-premises solution using your infrastructure and a CLM solution managed by us as SaaS or a hybrid of the two. We support you in finding the right option to meet your needs and the applicable regulations.
How many certificates can the CLM manage?
The CLM provided by Swiss Post Cybersecurity is highly scalable, as is the pricing model. Our standard CLM deployment can manage up to 200,000 certificates. For needs of large enterprises we can scale up to tens of millions.
Where is my data stored?
If you choose a CLM managed by Swiss Post Cybersecurity your data will stay in Switzerland.
