Try our new research platform with insights from 80,000+ expert users

CyberArk Certificate Manager vs Symantec Advanced Authentication comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Certificate Manager
Ranking in Authentication Systems
8th
Average Rating
8.2
Reviews Sentiment
6.0
Number of Reviews
20
Ranking in other categories
Certificate Management Software (2nd)
Symantec Advanced Authentic...
Ranking in Authentication Systems
23rd
Average Rating
7.8
Reviews Sentiment
8.7
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Authentication Systems category, the mindshare of CyberArk Certificate Manager is 1.9%, up from 1.0% compared to the previous year. The mindshare of Symantec Advanced Authentication is 1.5%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Authentication Systems Mindshare Distribution
ProductMindshare (%)
CyberArk Certificate Manager1.9%
Symantec Advanced Authentication1.5%
Other96.6%
Authentication Systems
 

Featured Reviews

Karthik Kashyap T H - PeerSpot reviewer
Lead Engineer at a retailer with 10,001+ employees
Eliminates certificate expiration outages and offers good customization and reporting capabilities
Even though it allows for email editing, until version 23.1, you had to log on to the server, and the console itself used to take a lot of time. That has changed from the last release onwards. When you're defining the flow, there are some areas that can probably cause confusion to the users. If you want to rename the default field, you cannot rename it, which caused a lot of confusion during the initial days until everyone got settled in. Allowing the renaming or updating of the default field is something Certificate Manager can improve on. Certificate Manager has both the on-prem and the cloud versions, but the on-prem version is far more mature than the cloud version, which lacks a lot of features that the on-prem version offers, at least when we did the POC and evaluated the product. The maturity of the cloud version needs improvement. Additionally, when considering the on-prem version, there is a minor glitch in the system. When an administrator makes changes, they have flexibility regarding the approval flow. When dealing with a certificate that requires approval from several different teams, there is a minor glitch in the system where the name of the approver does not appear. This is a bug that we are currently addressing. Additionally, there is room for improvement in key management. Changing the default account name is not a straightforward process; it can be quite tedious. This is an area where improvements could be made. If there is a particular workflow that we want to tweak, right now, we can achieve it only via a PowerShell script. It would be great if they could also support a small Python script or anything to expand their scripting or adaptable workflow code base. Even though we can call another script from a PowerShell script, if someone doesn't have knowledge of PowerShell, that would be challenging.
Umair (Abu Mohaymin) Akhlaque - PeerSpot reviewer
Group CEO at Flexsolutions
Ensures robust security features and ease of deployment, although it may lack some of the more modern authentication options
There has been a need for aggressive development to modernize the product and align it with contemporary security requirements. While the rebranding has been a step forward, further enhancements are essential to meet the evolving demands of the market. It lacks features such as ActiveSync Exchange security, and it doesn't offer alternatives like password-less authentication via biometrics or patches. While Symantec mainly relies on traditional token-based or password-based methods, newer authentication methods are missing from its repertoire. Support services often lack promptness and depth of knowledge, leaving customers waiting for weeks to resolve issues. In the realm of multifactor authentication, swift resolution of problems is critical, as any slowdown or interruption can significantly impact operations. Urgent improvement is necessary to ensure that support responses are faster and more effective, aligning with the demands of MFA implementation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CyberArk Certificate Manager has positively impacted my organization as a powerful tool for enhancing the security certificate management process, and by automating the lifecycle of TLS and SSL certificates, it has improved security and ensured operational efficiency, making it a vital component of modern IT infrastructure management."
"Automated certificate lifecycle management is not optional but a principal job, and from my professional perspective, if properly integrated into governance and DevOps, especially in DevSecOps workflow, it provides measurable risk reduction, improved availability, stronger cryptographic governance, and a better audit posture."
"It's definitely worth the money to have Venafi as a tool; it's definitely miles away from the competition, in my opinion."
"Venafi is super stable, and we experienced no issues with its stability."
"By using Certificate Manager, we have reduced our potential risk significantly due to certificate expiry, as all teams are getting emails before 60 days and 90 days, which is helpful."
"Certificate Manager's ability to help with compliance and regulatory requirements, including SOX and Swift, was great; this is a major selling point."
"We have reduced 80% to 90% of our outages with Venafi, which impacts the revenue substantially."
"The most important feature for us is the ease of use. If something is not available, we can develop our own scripts for it. We can create change management around this tool."
"CA products are the best fit with our backend systems."
"It allows us to assure our customers that we are protecting their data."
"It actually increases our revenue and the customer base."
"It tells us exactly what we want in terms of authentication to various applications and provides protection for users who access them."
"One of the most valuable aspects is its remarkable stability."
"One of the most valuable features of this solution is that it's a strong authentication solution that's able to integrate with applications."
"The most valuable feature is that we get a wide range of authentication methods and authentication integrators, so different platforms can get service authentication with transparency to the final user while providing strong authentication forms and connectors."
"Ease of deployment: no need to keep up with physical devices for multi-factor authentication; no software to deploy on end-user computers requiring administrative rights."
 

Cons

"Venafi excels in automating certificate rotation and deployment but could enhance its offering by improving support for hardware security modules like Fortanix and providing more advanced, out-of-the-box integrations with public certificate authorities for DNS re-verification."
"Venafi excels in automating certificate rotation and deployment but could enhance its offering by improving support for hardware security modules like Fortanix and providing more advanced, out-of-the-box integrations with public certificate authorities for DNS re-verification."
"Regarding stability, I observed that in the last year, CyberArk Certificate Manager was down two to three times without any notification."
"Regarding needed improvements, the UI needs enhancement. Sometimes it experiences latency-wise issues."
"The on-prem version is far more mature than the cloud version, which lacks a lot of features that the on-prem version offers, at least when we did the POC and evaluated the product."
"The initial setup is complex. You need third-party support or support from CyberArk Certificate Manager if you do not have a lot of skillset inside your own company."
"There's definitely lots of room for improvement with Venafi. They have a website where we can suggest new features, and they need to take that a little bit more seriously."
"Currently, specific processes require manual installations due to the lack of built-in integrations."
"Advanced Authentication talks about the Device ID. But how the device ID is captured, I want to know more about that."
"We have seen quite a few issues with bugginess. It is indeed pretty buggy and we have had to install some fixes."
"Sometimes getting this set up does take a bit longer. It's not always install, next, next, next, finish."
"They definitely need to automate a few processes like the Wiley process."
"Arcot itself is based on a browser technology. This means that the office ID is effectively stored as a cookie in the browser."
"It needs faster implementation on the cloud for our customers."
"We have seen quite a few issues with bugginess. It is indeed pretty buggy and we have had to install some fixes."
"This solution could be improved with risk-based authentication. I think that this product has everything that most customers are looking for, but modern technology has people looking for security tools with risk-based authentication, which they have a separate tool for. If they could integrate this, it would improve Symantec Advanced Authentication. They have to look at what's newly trending and how things are moving forward, and then adapt and adopt those features. Symantec's technical support should also be improved, in terms of response time."
 

Pricing and Cost Advice

"Venafi's pricing appears to be competitive within the market."
"The pricing model is complex, considering factors beyond the number of certificates. This complexity can make our payments to Venafi challenging if costs continue to rise. It is good but more expensive than the competitors."
"The price is reasonable."
"There are eventually going to be implementation costs. Sometimes you're required to have custom code developments there, so that has to be part of the implementation price."
report
Use our free recommendation engine to learn which Authentication Systems solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
9%
Insurance Company
7%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise17
By reviewers
Company SizeCount
Small Business2
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for Venafi?
In terms of pricing, they are a little costly, but they are the best in the market today, so I would say they are worth every penny, rating them again at seven or eight.
What needs improvement with Venafi?
CyberArk Certificate Manager can be improved, particularly in terms of integrations with other tools. I would like to see improvements in integrations with ID, Kerberos, or with other companies for...
What advice do you have for others considering Venafi?
Since using CyberArk Certificate Manager, I have seen specific outcomes such as a reduction in incidents because I can work with CyberArk Certificate Manager, where digital certificates are everywh...
Ask a question
Earn 20 points
 

Also Known As

Venafi
CA Advanced Authentication, CA Strong Authentication, CA Risk Authentication, Arcot WebFort, Arcot RiskFort
 

Overview

 

Sample Customers

Surescripts, CME Group, TD Bank Group, Aetna, MoneyGram, Zions Bancorp, Cisco
Global bank, Large Filipino Bank and SK Infosec
Find out what your peers are saying about CyberArk Certificate Manager vs. Symantec Advanced Authentication and other solutions. Updated: March 2026.
884,873 professionals have used our research since 2012.