No more typing reviews! Try our Samantha, our new voice AI agent.

CyberArk Certificate Manager vs RSA Identity Governance and Lifecycle comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Certificate Manager
Average Rating
8.2
Reviews Sentiment
6.0
Number of Reviews
19
Ranking in other categories
Authentication Systems (8th), Certificate Management Software (2nd)
RSA Identity Governance and...
Average Rating
7.0
Reviews Sentiment
5.9
Number of Reviews
10
Ranking in other categories
Identity Management (IM) (20th)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. CyberArk Certificate Manager is designed for Authentication Systems and holds a mindshare of 1.9%, up 1.0% compared to last year.
RSA Identity Governance and Lifecycle, on the other hand, focuses on Identity Management (IM), holds 1.2% mindshare, down 1.3% since last year.
Authentication Systems Mindshare Distribution
ProductMindshare (%)
CyberArk Certificate Manager1.9%
Microsoft Entra ID7.8%
Okta Platform5.0%
Other85.3%
Authentication Systems
Identity Management (IM) Mindshare Distribution
ProductMindshare (%)
RSA Identity Governance and Lifecycle1.2%
SailPoint Identity Security Cloud12.2%
Microsoft Entra ID8.8%
Other77.8%
Identity Management (IM)
 

Featured Reviews

Karthik Kashyap T H - PeerSpot reviewer
Lead Engineer at a retailer with 10,001+ employees
Eliminates certificate expiration outages and offers good customization and reporting capabilities
Even though it allows for email editing, until version 23.1, you had to log on to the server, and the console itself used to take a lot of time. That has changed from the last release onwards. When you're defining the flow, there are some areas that can probably cause confusion to the users. If you want to rename the default field, you cannot rename it, which caused a lot of confusion during the initial days until everyone got settled in. Allowing the renaming or updating of the default field is something Certificate Manager can improve on. Certificate Manager has both the on-prem and the cloud versions, but the on-prem version is far more mature than the cloud version, which lacks a lot of features that the on-prem version offers, at least when we did the POC and evaluated the product. The maturity of the cloud version needs improvement. Additionally, when considering the on-prem version, there is a minor glitch in the system. When an administrator makes changes, they have flexibility regarding the approval flow. When dealing with a certificate that requires approval from several different teams, there is a minor glitch in the system where the name of the approver does not appear. This is a bug that we are currently addressing. Additionally, there is room for improvement in key management. Changing the default account name is not a straightforward process; it can be quite tedious. This is an area where improvements could be made. If there is a particular workflow that we want to tweak, right now, we can achieve it only via a PowerShell script. It would be great if they could also support a small Python script or anything to expand their scripting or adaptable workflow code base. Even though we can call another script from a PowerShell script, if someone doesn't have knowledge of PowerShell, that would be challenging.
Harshul Nayak - PeerSpot reviewer
Senior Project Manager at a consultancy with 10,001+ employees
Streamline identity lifecycle management with intuitive interfaces and robust policy features
The functions of RSA Identity Governance and Lifecycle, especially the IGA, are quite strong with their custom forms and workflows integrated. The user interface is very friendly and easy to use, making it a good product overall. However, it still has to be on-premise and the cloud version is not easily accessible, as dedicated instances are required and machines cannot be shared as multi-tenant for various customers. The advanced policy features of RSA definitely help in defining certain policies such as segregation of duties. That's particularly useful along with creating different access reviews. Regarding access control in simplifying access management, RSA Identity Governance and Lifecycle has strong foundations of groups and roles, which help in defining all policies very easily. This makes it very easy to integrate with other access management tools or privileged access management tools.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CyberArk Certificate Manager has impacted our organization positively by making our life much easier by automatically updating and deploying certificates so our sites load correctly and we save a lot of time."
"Venafi's technical support is impressively fast."
"So, from the perspective of risk reduction, it can be directly quantified in the value for the customer."
"CyberArk Certificate Manager has positively impacted my organization as a powerful tool for enhancing the security certificate management process, and by automating the lifecycle of TLS and SSL certificates, it has improved security and ensured operational efficiency, making it a vital component of modern IT infrastructure management."
"The most valuable feature of Venafi is the automation that helps save time and reduce human error."
"Certificate Manager's ability to help with compliance and regulatory requirements, including SOX and Swift, was great; this is a major selling point."
"The feature that I have found most valuable is their certificate discovery."
"The reporting analysis is what I liked the most about it; that was the nicest thing about it—it helped keep track of certificates and their status and where we needed to make improvements, update, replace things."
"It improved security."
"Soft and hard tokens for two factor authentication has been introduced."
"The most valuable feature is the security, in particular, the One Time Password support."
"Roles, connectors for provisioning and re-accreditation or reviews help greatly to govern user access."
"The data collection is excellent and easy to do. It does not require a lot of configuration nor does it require rules to be written like other competitors do."
"RSA Identity Governance and lifecycles are good for the access certification and auditing sections."
"The user interface is very friendly and easy to use, making it a good product overall."
"Never - one thing I can say about RSA is that the boxes are stable and solid."
 

Cons

"Venafi excels in automating certificate rotation and deployment but could enhance its offering by improving support for hardware security modules like Fortanix and providing more advanced, out-of-the-box integrations with public certificate authorities for DNS re-verification."
"Regarding needed improvements, the UI needs enhancement. Sometimes it experiences latency-wise issues."
"The product was really good when it was a Venafi product. However, since its acquisition by CyberArk, there has been a lack of significant innovations. They are pushing for cloud adoption, but we prefer on-premises solutions due to regulatory concerns."
"There are quite a few different technical aspects of Venafi that I feel they just missed out on; I'd have to look at my notes for the specifics."
"The initial setup is complex. You need third-party support or support from CyberArk Certificate Manager if you do not have a lot of skillset inside your own company."
"There's definitely lots of room for improvement with Venafi. They have a website where we can suggest new features, and they need to take that a little bit more seriously."
"Venafi excels in automating certificate rotation and deployment but could enhance its offering by improving support for hardware security modules like Fortanix and providing more advanced, out-of-the-box integrations with public certificate authorities for DNS re-verification."
"Venafi could enhance its offerings by providing more automation features."
"Technical support in Pakistan can be improved."
"This product is missing a lot of features which other competitors are providing. One of the key features that are missing right now is risk scoring. Additionally, there is not much scope for customization - everything is hard-coded and predefined, so it does not allow the developers to make many modifications."
"It was expensive initially, but day to day costs are minimal."
"The user interface and workflow need improvement, and more connectors would help."
"The stability of RSA Identity Governance and Lifecycle could improve; it has some bugs that need to be fixed."
"Technical support in Pakistan can be improved."
"It could be a little more flexible with the installation of the product."
"There are scalability issues. This product does not scale very well. It is not a good product for load balancing / active–active architecture."
 

Pricing and Cost Advice

"The pricing model is complex, considering factors beyond the number of certificates. This complexity can make our payments to Venafi challenging if costs continue to rise. It is good but more expensive than the competitors."
"Venafi's pricing appears to be competitive within the market."
"Pricing varies based on user count/number of modules you need."
"We are using the cloud platform, but we don't find it compatible to be served as a multi-tenant platform. This is a large drawback. It becomes expensive because it is then an all-dedicated solution. You have to have a separate tenant for each client, which increases the cost. The overall unit pricing can be less expensive than how it is right now."
"I rate the product's price a five on a scale of one to ten, where one is cheap, and ten is expensive."
report
Use our free recommendation engine to learn which Authentication Systems solutions are best for your needs.
885,837 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
8%
Insurance Company
7%
Government
7%
Comms Service Provider
12%
Financial Services Firm
12%
Computer Software Company
9%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise18
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Venafi?
In terms of pricing, they are a little costly, but they are the best in the market today, so I would say they are worth every penny, rating them again at seven or eight.
What needs improvement with Venafi?
CyberArk Certificate Manager can be improved, particularly in terms of integrations with other tools. I would like to see improvements in integrations with ID, Kerberos, or with other companies for...
What advice do you have for others considering Venafi?
Since using CyberArk Certificate Manager, I have seen specific outcomes such as a reduction in incidents because I can work with CyberArk Certificate Manager, where digital certificates are everywh...
What needs improvement with RSA Identity Governance and Lifecycle?
There is room for improvement with RSA Identity Governance and Lifecycle. As the size becomes larger, the collections and unifications of the IDs process become quite slow, which can be improved fu...
What is your primary use case for RSA Identity Governance and Lifecycle?
We provide RSA Identity Governance and Lifecycle as a service, mainly to oversee the digital identity lifecycle, from the initiation to the off-boarding at the end of that digital identity. Our cli...
What advice do you have for others considering RSA Identity Governance and Lifecycle?
Overall, I would rate RSA Identity Governance and Lifecycle at an eight out of ten.
 

Also Known As

Venafi
SecurID
 

Overview

 

Sample Customers

Surescripts, CME Group, TD Bank Group, Aetna, MoneyGram, Zions Bancorp, Cisco
NTT Com Asia, Virgin Blue, Bank of Uganda, EMEA Telecommunications Company, LAit (Lazio Innovazione Tecnologica), NyNet, OTP Bank, Red Bull Racing, Rupert House School, Signify, UK Local Authority, Bancolombia, Banco Popular de Puerto Rico (BPPR), TIVIT, Array Services, International Computerware, KPMG LLP, Moffitt Cancer Center
Find out what your peers are saying about Microsoft, Cisco, Fortinet and others in Authentication Systems. Updated: March 2026.
885,837 professionals have used our research since 2012.