No more typing reviews! Try our Samantha, our new voice AI agent.

CyberArk Certificate Manager vs RSA Identity Governance and Lifecycle comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Certificate Manager
Average Rating
8.2
Reviews Sentiment
6.0
Number of Reviews
19
Ranking in other categories
Authentication Systems (8th), Certificate Management Software (2nd)
RSA Identity Governance and...
Average Rating
7.0
Reviews Sentiment
5.9
Number of Reviews
10
Ranking in other categories
Identity Management (IM) (20th)
 

Mindshare comparison

While both are Identity and Access Management solutions, they serve different purposes. CyberArk Certificate Manager is designed for Authentication Systems and holds a mindshare of 1.9%, up 1.0% compared to last year.
RSA Identity Governance and Lifecycle, on the other hand, focuses on Identity Management (IM), holds 1.2% mindshare, down 1.3% since last year.
Authentication Systems Mindshare Distribution
ProductMindshare (%)
CyberArk Certificate Manager1.9%
Microsoft Entra ID7.8%
Okta Platform5.0%
Other85.3%
Authentication Systems
Identity Management (IM) Mindshare Distribution
ProductMindshare (%)
RSA Identity Governance and Lifecycle1.2%
SailPoint Identity Security Cloud12.2%
Microsoft Entra ID8.8%
Other77.8%
Identity Management (IM)
 

Featured Reviews

Karthik Kashyap T H - PeerSpot reviewer
Lead Engineer at a retailer with 10,001+ employees
Eliminates certificate expiration outages and offers good customization and reporting capabilities
Even though it allows for email editing, until version 23.1, you had to log on to the server, and the console itself used to take a lot of time. That has changed from the last release onwards. When you're defining the flow, there are some areas that can probably cause confusion to the users. If you want to rename the default field, you cannot rename it, which caused a lot of confusion during the initial days until everyone got settled in. Allowing the renaming or updating of the default field is something Certificate Manager can improve on. Certificate Manager has both the on-prem and the cloud versions, but the on-prem version is far more mature than the cloud version, which lacks a lot of features that the on-prem version offers, at least when we did the POC and evaluated the product. The maturity of the cloud version needs improvement. Additionally, when considering the on-prem version, there is a minor glitch in the system. When an administrator makes changes, they have flexibility regarding the approval flow. When dealing with a certificate that requires approval from several different teams, there is a minor glitch in the system where the name of the approver does not appear. This is a bug that we are currently addressing. Additionally, there is room for improvement in key management. Changing the default account name is not a straightforward process; it can be quite tedious. This is an area where improvements could be made. If there is a particular workflow that we want to tweak, right now, we can achieve it only via a PowerShell script. It would be great if they could also support a small Python script or anything to expand their scripting or adaptable workflow code base. Even though we can call another script from a PowerShell script, if someone doesn't have knowledge of PowerShell, that would be challenging.
Harshul Nayak - PeerSpot reviewer
Senior Project Manager at a consultancy with 10,001+ employees
Streamline identity lifecycle management with intuitive interfaces and robust policy features
The functions of RSA Identity Governance and Lifecycle, especially the IGA, are quite strong with their custom forms and workflows integrated. The user interface is very friendly and easy to use, making it a good product overall. However, it still has to be on-premise and the cloud version is not easily accessible, as dedicated instances are required and machines cannot be shared as multi-tenant for various customers. The advanced policy features of RSA definitely help in defining certain policies such as segregation of duties. That's particularly useful along with creating different access reviews. Regarding access control in simplifying access management, RSA Identity Governance and Lifecycle has strong foundations of groups and roles, which help in defining all policies very easily. This makes it very easy to integrate with other access management tools or privileged access management tools.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have reduced 80% to 90% of our outages with Venafi, which impacts the revenue substantially."
"CyberArk Certificate Manager is doing its best with multiple layers of security, and while they face challenges with legacy applications, they can still connect to web applications, rich applications, desktop applications, and cloud-native applications."
"The support is definitely great. What I like best about Venafi is that it's very easy to get somebody on a call and get any of my questions answered. That's probably the biggest thing. Besides the fact that it's a mature product and it works, the support is a big deal."
"CyberArk Certificate Manager has positively impacted my organization by automating the credential process, allowing users to rotate and share passwords with no human intervention required."
"It's definitely worth the money to have Venafi as a tool; it's definitely miles away from the competition, in my opinion."
"By using Certificate Manager, we have reduced our potential risk significantly due to certificate expiry, as all teams are getting emails before 60 days and 90 days, which is helpful."
"Venafi's automation capabilities were significant, as they allowed us to automate certificate rotation and deployment effectively."
"CyberArk Certificate Manager has excellent capability in handling certification renewals; whenever you specify any validity period that needs to be renewed within certain days, it triggers automatically, and I appreciate that aspect."
"Soft and hard tokens for two factor authentication has been introduced."
"RSA Identity Governance and lifecycles are good for the access certification and auditing sections."
"With the tool in place, you need to hire fewer people to provide access, and you have control over your processes."
"The data collection is excellent and easy to do."
"Never - one thing I can say about RSA is that the boxes are stable and solid."
"All of the features in this product are good and this is a product that I recommend."
"Roles, connectors for provisioning and re-accreditation or reviews help greatly to govern user access."
"The data collection is excellent and easy to do. It does not require a lot of configuration nor does it require rules to be written like other competitors do."
 

Cons

"Regarding needed improvements, the UI needs enhancement. Sometimes it experiences latency-wise issues."
"For Java applications, we currently convert the certificate in JKS manually. It would be helpful to have the capability to download certificates in JKS automatically."
"Currently, specific processes require manual installations due to the lack of built-in integrations."
"The product was really good when it was a Venafi product. However, since its acquisition by CyberArk, there has been a lack of significant innovations. They are pushing for cloud adoption, but we prefer on-premises solutions due to regulatory concerns."
"Venafi could enhance its offerings by providing more automation features."
"Regarding stability, I observed that in the last year, CyberArk Certificate Manager was down two to three times without any notification."
"I would like to see included in the next release of Venafi integration with the cloud HSM's, Hardware Security Module. Additionally, I would say other cloud services, because it's not only cloud that's essential. If you have a customer that has a lot of their IT moved into cloud, integration with different cloud services is always an area to improve."
"Currently lacks the capability to automatically download certificates in JKS."
"Application and appliance stability needs improvement."
"We were excited that the self-provision feature was now built into the box but disappointed at the implementation."
"This product is missing a lot of features which other competitors are providing. One of the key features that are missing right now is risk scoring. Additionally, there is not much scope for customization - everything is hard-coded and predefined, so it does not allow the developers to make many modifications."
"It could be a little more flexible with the installation of the product."
"RSA Identity Governance and Lifecycle could improve out-of-the-box customization."
"Technical support in Pakistan can be improved."
"There are scalability issues. This product does not scale very well. It is not a good product for load balancing / active–active architecture."
"If you use the appliance version then it won't handle a huge database volume."
 

Pricing and Cost Advice

"Venafi's pricing appears to be competitive within the market."
"The pricing model is complex, considering factors beyond the number of certificates. This complexity can make our payments to Venafi challenging if costs continue to rise. It is good but more expensive than the competitors."
"I rate the product's price a five on a scale of one to ten, where one is cheap, and ten is expensive."
"Pricing varies based on user count/number of modules you need."
"We are using the cloud platform, but we don't find it compatible to be served as a multi-tenant platform. This is a large drawback. It becomes expensive because it is then an all-dedicated solution. You have to have a separate tenant for each client, which increases the cost. The overall unit pricing can be less expensive than how it is right now."
report
Use our free recommendation engine to learn which Authentication Systems solutions are best for your needs.
885,837 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
8%
Insurance Company
7%
Government
7%
Comms Service Provider
12%
Financial Services Firm
12%
Computer Software Company
9%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise18
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Venafi?
In terms of pricing, they are a little costly, but they are the best in the market today, so I would say they are worth every penny, rating them again at seven or eight.
What needs improvement with Venafi?
CyberArk Certificate Manager can be improved, particularly in terms of integrations with other tools. I would like to see improvements in integrations with ID, Kerberos, or with other companies for...
What advice do you have for others considering Venafi?
Since using CyberArk Certificate Manager, I have seen specific outcomes such as a reduction in incidents because I can work with CyberArk Certificate Manager, where digital certificates are everywh...
What needs improvement with RSA Identity Governance and Lifecycle?
There is room for improvement with RSA Identity Governance and Lifecycle. As the size becomes larger, the collections and unifications of the IDs process become quite slow, which can be improved fu...
What is your primary use case for RSA Identity Governance and Lifecycle?
We provide RSA Identity Governance and Lifecycle as a service, mainly to oversee the digital identity lifecycle, from the initiation to the off-boarding at the end of that digital identity. Our cli...
What advice do you have for others considering RSA Identity Governance and Lifecycle?
Overall, I would rate RSA Identity Governance and Lifecycle at an eight out of ten.
 

Also Known As

Venafi
SecurID
 

Overview

 

Sample Customers

Surescripts, CME Group, TD Bank Group, Aetna, MoneyGram, Zions Bancorp, Cisco
NTT Com Asia, Virgin Blue, Bank of Uganda, EMEA Telecommunications Company, LAit (Lazio Innovazione Tecnologica), NyNet, OTP Bank, Red Bull Racing, Rupert House School, Signify, UK Local Authority, Bancolombia, Banco Popular de Puerto Rico (BPPR), TIVIT, Array Services, International Computerware, KPMG LLP, Moffitt Cancer Center
Find out what your peers are saying about Microsoft, Cisco, Fortinet and others in Authentication Systems. Updated: March 2026.
885,837 professionals have used our research since 2012.