TigerTrust vs AWS Private CA

Multi-cloud CLM when AWS is not the whole estate.

AWS Private CA is a solid private issuer if every workload lives inside AWS. Most estates end up with certificates outside AWS, per-CA standing charges that scale linearly, and no cross-cloud visibility. TigerTrust delivers multi-cloud discovery, alerting, and compliance around and above AWS Private CA.

Why teams add TigerTrust

AWS-native, but not AWS-only.

AWS Private CA is a well-integrated private CA for AWS workloads. Teams add TigerTrust when the estate stretches beyond AWS or when per-CA fees start dominating the cost model.

Cross-cloud coverage
Discovery, issuance, and lifecycle across AWS, Azure, GCP, on-prem load balancers, and Kubernetes clusters in every environment.
Discovery beyond ACM
ACM sees ACM. TigerTrust discovers certificates on EC2 pulled via SDK, third-party appliances, SaaS callbacks, and on-prem — not just ACM-managed inventory.
Alerting and owner routing
Multi-channel notifications with owner assignment and escalation. CloudWatch is not a CLM alerting layer.
Predictable pricing model
One platform fee that scales linearly with the certificate estate — not per-CA standing charges and tiered per-certificate fees stacked together.
The move above

What changes when AWS is one cloud of many.

Without AWS
  • AWS-only visibility; certs outside AWS are invisible
  • Per-CA standing charges plus tiered per-cert fees compound at scale
  • Discovery limited to ACM-managed inventory
  • CloudTrail scraping to build audit evidence
  • IAM-only tenancy; no per-BU or per-team views
With TigerTrust
  • Discovery and lifecycle across AWS, Azure, GCP, and on-prem
  • Platform pricing that scales linearly with the estate
  • Discovery of every cert on every endpoint, ACM-managed or not
  • Prebuilt compliance evidence packs — audit-ready exports
  • Multi-tenant / per-BU views alongside AWS IAM

Capability comparison, head to head.

AWS Private CA is well-designed for its scope. Here is where the offerings overlap and where the scope differs.

CapabilityTigerTrustAWS ACM Private CA
AWS-native integration
AWS Private CA is deeply integrated with the AWS control plane
Azure and GCP integration
On-premise / hybrid discovery
Kubernetes across clouds
AWS Private CA integrates with EKS via cert-manager
Discovery beyond issuance
Expiry monitoring across sources
Prebuilt compliance reports
Multi-CA orchestration (public + private)
Private root & intermediate CA hosting
Per-CA standing charge
AWS Private CA has a monthly per-CA standing charge; TigerTrust does not

Add TigerTrust above AWS Private CA.

You do not have to leave AWS Private CA to gain a CLM. Most AWS-first teams keep it as an issuer and add TigerTrust for the lifecycle layer.

01

Connect AWS accounts

TigerTrust discovers ACM certificates (public and private), Private CA-issued certs, and certificates deployed on EC2, ALB, NLB, CloudFront, API Gateway, and beyond.

02

Add other clouds and on-prem

Extend discovery to Azure, GCP, on-prem load balancers, and Kubernetes clusters across the estate. Every certificate lands in one inventory.

03

Keep Private CA as an issuer

AWS Private CA remains an upstream issuer under TigerTrust orchestration. Nothing about existing ACM auto-renewal flows changes.

04

Optimise the cost model

Once TigerTrust is authoritative for policy and routing, teams often consolidate Private CA usage — routing lower-tier workloads to alternative issuers where policy allows.

Frequently asked questions

Is AWS Private CA actually expensive?

It depends on your footprint. AWS Private CA has a per-CA monthly standing charge plus tiered per-certificate fees. For a handful of CAs and thousands of short-lived workload certs, the math climbs quickly. For a small AWS-only footprint with a couple of CAs, it can be entirely reasonable. Check the current AWS Private CA pricing page for authoritative numbers before you model the cost.

We only run on AWS. Do we still need TigerTrust?

If you truly issue and consume every certificate inside AWS and use ACM-managed private certificates exclusively, Private CA may be sufficient. Most teams have edge cases — certs on EC2 pulled via SDK, load balancers outside ALB/NLB, third-party SaaS callbacks, or an on-prem footprint. TigerTrust picks up those gaps.

Can TigerTrust use AWS Private CA as a backing issuer?

Yes. Private CA remains an upstream issuer while TigerTrust orchestrates issuance, discovery, alerting, and reporting across it and any other CAs you use (DigiCert, Vault, Sectigo, GlobalSign, private roots).

What about ACM (public and private) certificates already deployed?

TigerTrust discovers and inventories them as part of the AWS integration. You keep the auto-renewal ACM provides for managed certs; TigerTrust adds the visibility, owner routing, and compliance evidence AWS does not.

How do you handle the AWS Private CA regional deployment model?

TigerTrust operates per-region alongside your AWS Private CA deployments, aggregates inventory centrally, and respects VPC boundaries. Cross-account and cross-region views are unified in one dashboard.

Case study
Cloud-native · Digital media

Kept AWS Private CA as an issuer, added visibility across the multi-cloud estate.

We were AWS-first, then we acquired an Azure shop and inherited an on-prem DR footprint. Private CA saw one third of what we needed to see.
Head of Cloud Platform
4 wk
Time to full multi-cloud coverage
3
Clouds unified in one inventory
47%
Reduction in per-CA standing charges
Integrations

AWS-native, plus every other cloud you actually run.

AWS Private CA stays as an upstream issuer. TigerTrust ships the cross-cloud, on-prem, and Kubernetes surface it does not.

AWS ACM & Private CA
Cloud
Microsoft Azure
Cloud
Google Cloud
Cloud
Kubernetes cert-manager
DevOps
VMware NSX / ALB
On-prem
Microsoft ADCS
CA
HashiCorp Vault
CA
HashiCorp Terraform
IaC
ServiceNow
ITSM

Gain visibility beyond AWS.