Sectigo EPKI Manager is retiring
Effective February 15, 2027, Sectigo EPKI Manager will reach end of life (EOL) and end of support (EOS). After this date, EPKI Manager will no longer be available.
Built for the next era of certificate lifecycle management (CLM)
The digital trust landscape has changed significantly since EPKI Manager was introduced. Public TLS certificate lifespans and domain validity periods are shortening — the next reduction lands March 11, 2027, when TLS certificate terms drop to 99 days and DCV reuse is limited to 98 days. Compliance requirements are evolving too: on February 11, 2027, Sectigo will no longer include the Client Authentication EKU in any SSL/TLS certificates. And the number of certificates organizations must manage has grown substantially — today's environments require more visibility, automation, and operational control than traditional certificate administration tools were designed to provide.
To meet these changing demands, Sectigo has focused its innovation and development investments on two modern, cloud-based certificate lifecycle management (CLM) platforms: Sectigo Certificate Manager (SCM) Pro for small and midsize organizations managing DV/OV SSL certificates, and Sectigo Certificate Manager (SCM) Enterprise for larger and more complex environments, including S/MIME, private PKI, and multi-CA use cases. Both platforms help you move beyond managing individual certificate transactions and toward a proactive, lifecycle-based approach to digital trust.
What did EPKI Manager do and what changes for you?
EPKI Manager was a web-based console that let your administrators bulk-issue and manage SSL/TLS certificates, S/MIME (secure email) certificates, and Personal Authentication (client) certificates for your organization from one place, on a prepaid account funded by credit card or purchase order.
If your team used EPKI Manager for any of the following, here's where that capability lives going forward:
SCM Pro (DV/OV, with ACME automation on Plus and Advanced plans) or SCM Enterprise (DV/OV/EV, with automation across multiple CAs and your full technology stack).
SCM Pro (DV/OV, with ACME automation on Plus and Advanced plans) or SCM Enterprise (DV/OV/EV, with automation across multiple CAs and your full technology stack).
SCM Enterprise, which supports S/MIME issuance and lifecycle management end to end.
SCM Enterprise, via Private PKI and client certificate management.
Both SCM platforms are built around today's much shorter, automation-first validity periods (99 days starting March 2027), so multi-year terms are no longer offered — automated renewal replaces manual multi-year purchasing.
Replaced by flat-rate monthly/annual subscriptions (SCM Pro) or a custom enterprise agreement (SCM Enterprise). There's no account balance to maintain or top up.
Both SCM platforms include user management and reporting; SCM Enterprise adds full role-based access control for teams managing multiple certificate types at scale.
Both platforms support automation; SCM Enterprise offers a full REST API (SSL, client, device, and code signing certificates) plus ACME, SCEP, and EST for deeper automation than EPKI Manager's API access.
Moving forward with confidence
Explore the two paths forward below, compare SCM Pro and SCM Enterprise side by side, and check our FAQs for answers to common migration questions. If you're not sure which path is right for you, talk to a Sectigo specialist — we're here to help.
SCM Pro Path
Make DV/OV SSL transition planning a priority — Sectigo can help.
SCM Pro is Sectigo’s certificate lifecycle management platform purpose-built for TLS certificate issuance, risk visibility, and automated renewal. There are three subscription plans to fit most public certificate use cases and each plan begins with a free, no-commitment 30-day trial. No credit card needed.
During your free SCM Pro trial period you can run an automated certificate discovery scan, which has the benefit of bringing your inventory from E-PKI into SCM Pro’s centralized inventory, saving you hours of time in manually provisioning each certificate. Discovery also surfaces previously unknown and unmanaged TLS certificates, adds them to a centralized inventory, and gives you an intuitive dashboard view of your current certificate environment.
Getting started is easy: no credit card is required, and you can issue five free 90-day DV certificates during your trial period. To further support your transition, Sectigo is offering EPKI customers 30% off their SCM Pro subscription through October with code EPKI30.*
Best for: teams that only need DV/OV SSL certificates and want a fast, self-serve path off E-PKI Manager.
SCM Enterprise Path
Managing more than DV/OV SSL? Let's build the right plan together.
If your EPKI Manager usage includes S/MIME certificates, private PKI, code signing, multi-CA environments, or certificate volumes at enterprise scale, SCM Enterprise is designed to support the full breadth of what you're managing today — not just public SSL/TLS.
Because SCM Enterprise trials are guided rather than self-serve, a Sectigo specialist will work with you directly to scope your environment, map your current EPKI Manager use cases (including S/MIME), and build a migration plan suited to your organization's scale and compliance needs.
Best for: teams managing S/MIME, private PKI/device identities, multiple CAs, or large/complex certificate estates.
Choose the right path forward
Compare Sectigo Certificate Manager Pro and Enterprise side by side to see which platform matches the certificates you manage today and the ones you'll need tomorrow. No matter which path you choose, you'll gain capabilities EPKI Manager never offered: a centralized dashboard for at-a-glance visibility, automated certificate discovery to surface unknown or unmanaged certs, and more flexible, customizable reporting — a significant step forward in how you manage risk.
Not sure which one you need?
Choose SCM Pro if you:
- Only issue DV and/or OV SSL/TLS certificates for your websites
- Manage a limited number of domains (roughly 2–200+ certificates)
- Don't have dedicated PKI or security specialists on staff
- Want simple, flat-rate subscription pricing and a self-serve setup
- Note: If you need ACME automation, automated renewals, or pre-coded install snippets, choose the Plus or Advanced SCM Pro plan — Basic covers discovery and guided (manual) workflows only
Choose SCM Enterprise if you:
- Require the highest level of Extended Validation (EV) SSL authentication
- Issue or manage S/MIME certificates for secure email
- Need a private CA/PKI to authenticate internal users, devices, or applications
- Manage certificates across multiple CAs, hybrid, multi-cloud, or legacy environments
- Require custom role-based access control, advanced reporting, or premium support
- Operate at enterprise scale (50 to 50,000+ certificates)
Still unsure? Talk to us before signing up.
We'll help you map your current and future certificate needs to the right plan the first time.
FAQs
E-PKI Manager will remain available until February 15, 2027. After that date, the platform will no longer be available or supported. Certificates already issued through E-PKI Manager will remain valid until their normal expiration date unless revoked or otherwise impacted by standard certificate lifecycle events.
The certificate management landscape has evolved significantly, with shorter certificate lifespans, growing compliance requirements, larger certificate inventories, and increased demand for automation. To better support these needs, Sectigo is focusing innovation and development on its modern certificate lifecycle management platforms: SCM Pro and SCM Enterprise.
SCM Pro is designed for organizations that primarily manage DV and OV SSL/TLS certificates and want a simple, self-service certificate lifecycle management solution.
SCM Enterprise is recommended if you manage:
- S/MIME certificates
- Private PKI or client certificates
- Code signing certificates
- Multiple certificate authorities
- Large or complex certificate environments
If you're unsure, speak with a Sectigo specialist before choosing a platform.
Existing certificates remain valid until expiration and are not automatically migrated. Both SCM Pro and SCM Enterprise include certificate discovery capabilities that can identify certificates already deployed across your environment and help create a centralized inventory for ongoing management.
These use cases are supported through SCM Enterprise.
If your organization relies on:
- S/MIME certificates
- Personal Authentication/client certificates
- Private PKI
- Mutual TLS (mTLS) or non-web device/user identities
Contact a Sectigo specialist to discuss the appropriate migration approach.
E-PKI Manager used a prepaid, per-certificate purchasing model. SCM platforms use subscription-based pricing:
- SCM Pro: Flat-rate monthly or annual plans
- SCM Enterprise: Custom pricing based on organizational requirements
There are no prepaid balances or account top-ups to manage.
Both platforms support certificate lifecycle automation.
- SCM Pro supports ACME-based automation and automated renewals on Plus and Advanced plans.
- SCM Enterprise provides broader automation through ACME, REST APIs, SCEP, EST, and additional enterprise integrations.
Organizations currently using E-PKI Manager APIs or large-scale automation workflows should consider SCM Enterprise
Public TLS certificate lifespans continue to decrease, making manual certificate management increasingly difficult. SCM Pro and SCM Enterprise help address this challenge through certificate discovery, centralized visibility, automated issuance, monitoring, alerts, and automated renewals, reducing operational effort and outage risk.
Yes. SCM Pro is designed for organizations that need improved certificate visibility and automation without dedicated PKI specialists. Guided workflows, certificate discovery, reporting, and automated lifecycle management simplify day-to-day certificate operations.
Yes. Sectigo will provide migration guidance, product comparisons, enablement resources, and transition support to help customers move from E-PKI Manager before the February 15, 2027 end-of-life date.



