Skip to main content
Cloud / AWS / Products / AWS Certificate Manager: SSL/TLS Certificates

AWS Certificate Manager: SSL/TLS Certificates

AWS Certificate Manager manages SSL/TLS certificates for AWS services, with both free and paid options.

Security, Identity & Compliance
Pricing Model Free for public certificates on integrated AWS services; paid for ACME/exportable certificates and Private CA
Availability Many AWS regions, check availability per region
Data Sovereignty EU regions available
Reliability No separate SLA for ACM itself; AWS Private CA has its own SLA (see official SLA page) SLA

What is AWS Certificate Manager?

AWS Certificate Manager (ACM) is a service for provisioning and managing public and private SSL/TLS certificates for AWS resources. The service automates certificate creation, validation, and renewal for AWS services integrated with ACM, and additionally offers ACME-based automation and exportable certificates for your own servers and infrastructure outside AWS.

Key Features

  • Free public SSL/TLS certificates for ACM-integrated AWS services
  • Automatic renewal before expiration as long as domain validation remains confirmed
  • DNS or email-based domain validation
  • ACME protocol support for automated certificate issuance on your own servers (e.g., EC2)
  • Exportable public certificates (paid) for use outside AWS
  • AWS Private CA for private certificate authorities and internal PKI
  • Wildcard certificates for an unlimited number of subdomains

Common Use Cases

HTTPS for Web Applications: Secure websites and APIs with free SSL certificates for integrated services. Integration with CloudFront or Application Load Balancer requires no manual certificate configuration.

Multi-Domain Certificates: An ACM certificate can cover up to 10 domains (SANs) by default, with more available via a quota increase. Wildcard certificates (*.example.com) automatically secure all subdomains.

Private PKI for Enterprises: AWS Private CA creates a private Certificate Authority for internal applications, IoT devices, or microservices communication with full control over the certificate chain and exportable certificates.

Benefits

  • No cost for public certificates on AWS services
  • Automated renewal processes for integrated services
  • Native integration with AWS load balancers and CDN
  • Flexible options for certificates outside AWS via ACME or export
  • Audit logs via AWS CloudTrail

Integration with innFactory

As an AWS Reseller, innFactory supports you with AWS Certificate Manager: architecture for secure TLS communication, building private PKI infrastructure, and migrating existing certificates to ACM.

Typical Use Cases

HTTPS for websites
API encryption
Internal resources
Certificate management

Frequently Asked Questions

Are ACM certificates really free?

Public certificates for AWS services integrated with ACM (e.g., CloudFront, load balancers, API Gateway) are free. Exportable public certificates, ACME certificates for your own servers, and private certificates via AWS Private CA are paid options.

Which AWS services does ACM support?

ACM certificates work natively with CloudFront, Elastic Load Balancing, API Gateway, Elastic Beanstalk, and CloudFormation. For your own servers or EC2 instances, exportable certificates or ACME-based automation are available.

How does automatic renewal work?

ACM automatically renews certificates for integrated AWS services before expiration, provided domain validation can still be confirmed. With DNS validation, no manual action is typically required.

Can I export ACM certificates?

Free public certificates for integrated services cannot be exported. Paid exportable public certificates and private certificates via AWS Private CA can be exported and used on any servers.

How many domains can a certificate cover?

An ACM certificate can cover up to 10 domain names (SANs) by default; this limit can be increased up to 100 via a quota increase. Wildcard certificates additionally protect an unlimited number of subdomains.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of AWS (official documentation). This page does not represent an offer by AWS.

AWS Cloud Expertise

innFactory is an AWS Reseller with certified cloud architects. We provide consulting, implementation, and managed services for AWS.

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Access Approval - Google Cloud Access Control

Access Approval for Google Cloud: manual approval before support accesses your data. Transparency and control for GDPR …

Pricing No extra cost, requires at least …
SLA SLA as published by the provider
Compare →
Google Cloud

Access Transparency - Access Logging

Access Transparency logs Google personnel access to your cloud data. Transparency and compliance for regulated …

Pricing No extra cost, requires at least …
SLA SLA as published by the provider
Compare →
Google Cloud

AI Protection - AI Security

AI Protection in Security Command Center inventories AI assets, scores AI risks via attack-path simulation, and detects …

Pricing Included in SCC Premium/Enterprise, no …
SLA N/A (part of Security Command Center)
Compare →
Google Cloud

Assured Workloads - Compliance Controls for Regulated Workloads

Assured Workloads enables compliance with regulatory requirements for regulated workloads in Google Cloud.

Pricing No additional charge for the service …
SLA SLA as published by the provider
Compare →
Azure

Azure Attestation - Trusted Execution Verification

Azure Attestation verifies the trustworthiness of TEEs like Intel SGX, AMD SEV-SNP, VBS enclaves, and TPM.

Pricing Free
SLA SLA as published by the provider
Compare →
Azure

Azure Cloud HSM - Hardware Security Module

Azure Cloud HSM provides FIPS 140-3 Level 3 validated hardware security modules for cryptographic keys.

Pricing Usage-based per HSM cluster hour, …
SLA SLA as published by the provider
Compare →

39 comparable products found across other clouds.

Ready to start with AWS Certificate Manager: SSL/TLS Certificates?

Our certified AWS experts help you with architecture, integration, and optimization.

Schedule Consultation