DigiCert

Identity AccessNetwork Security also known as DigiCert, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Advanced: Market readiness of 31 or above. Above the typical band, which few analyzed companies reach.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate.
Founded 2003
Last updated 2026-08-25

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

DigiCert issues publicly trusted certificates and sells the enterprise software that manages them. An independent web survey records DigiCert certificates on 1.6% of all websites, behind Let's Encrypt at 64.4%, GlobalSign at 20.3%, Sectigo at 4.8% and GoDaddy Group at 3.5%. The same survey includes Facebook, Microsoft, Apple and Netflix among sites carrying DigiCert certificates, and DigiCert says over 90% of the Fortune 500 are customers. IDC named it a Leader in a January 2026 assessment of certificate lifecycle management. The browser makers decide which certificate authorities stay trusted, and DigiCert's issuance business depends on that decision.

Sourced Details

Description Certificate authority and digital-trust vendor whose DigiCert ONE platform issues publicly trusted certificates and unifies public key infrastructure, DNS, and certificate lifecycle management across infrastructure, software, devices, content, and email. [f1]
Founded 2003 [f2]
HQ Lehi, Utah, United States [f3]
Latest funding PE-owned by Clearlake Capital and TA Associates (2019 acquisition), with Crosspoint Capital Partners joining in Dec 2021 [f4]

Products

Product What it does
DigiCert ONE Unified digital-trust platform spanning certificate lifecycle management, code signing, device identity, content signing, managed DNS, and email authentication.
CertCentral Console for requesting, renewing, and reporting on public trust certificates, covering more than 20 certificate types across Web PKI, PSD2, and eIDAS.
Trust Lifecycle Manager Certificate lifecycle management that discovers certificates across cloud and infrastructure and imports them from any certificate authority or trust store.
UltraDNS Managed authoritative DNS with DDoS and application protection, acquired with Vercara and integrated into the DigiCert ONE platform.
Messaging Trust Email authentication built on the Valimail acquisition, moving sending domains to DMARC enforcement and delivering verified logos in the inbox.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

DigiCert ONE issues publicly trusted certificates, manages certificate lifecycles, signs code and content, gives devices verifiable identities, and runs UltraDNS managed authoritative DNS. These capabilities are mapped to the Cyber Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Advanced 31 /40 Advanced: Market readiness of 31 or above. Above the typical band, which few analyzed companies reach.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 4/5 Non-vendor records name the buyer and size the pain. Twenty-five certificate authorities voted to cut public TLS validity from 398 days to 47, SecurityWeek reported 83,267 certificates across 6,807 subscribers facing revocation on 24 hours' notice in 2024, and the IDC write-up puts certificate lifecycle management in front of security and infrastructure teams as inventories expand. Standards record, incident history and analyst commentary agree on the same problem. [s6, s16, s18]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The DigiCert ONE page documents six modules, covering certificate discovery and automation, code signing, device identity, content signing, authoritative DNS and email authentication, and DigiCert says the product provides centralised discovery, policy-based governance and automation across public and private certificate authorities, and the IDC write-up cited delivery options and customer feedback as strengths. Google's published Certificate Transparency log list records six DigiCert logs, capability a third party can check, and no cited benchmark measures the platform against rivals. [s2, s11, s18]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Buyer-side signals of three kinds are live. IDC assessed certificate lifecycle management in January 2026, an analyst category. Google decided in February 2026 to keep post-quantum X.509 certificates out of the Chrome Root Store, a root-program change. The CA/Browser Forum ballot that cuts public TLS validity to 47 days carries an April 2025 date and its reductions began in March 2026, so the deadline landed inside the window even though the vote did not. These are conditions the market moved into and not demand DigiCert created. [s6, s18, s10]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Zscaler's proxy statement records DigiCert's chief executive Amit Sinha as Zscaler's chief technology officer from December 2010 to January 2022 and then as its president, and records more than 15 years as an architect and technical manager in networking and security. That is a decade of in-domain leadership at a security platform vendor, documented by a third party rather than by DigiCert. CA/Browser Forum ballot records name DigiCert's Stephen Davidson proposing Ballot SMC017 in April 2026, so the standards work carries identifiable names. [s20, s7, s1]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 An independent web survey includes Facebook, Microsoft, Apple, LinkedIn and Netflix among popular sites carrying DigiCert certificates, IDC named DigiCert a Leader in certificate lifecycle management, and DigiCert records an AWS Marketplace listing plus Trust Lifecycle Manager integrations with F5, HashiCorp, Jamf and NetScaler. The same survey records DigiCert certificates on 1.6% of websites, below GlobalSign and Sectigo, so the evidence is solid without showing exceptional scale. [s12, s18, s4, s13]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 DigiCert kept shipping through fiscal 2026, acquiring Valimail in September 2025, folding UltraDNS into DigiCert ONE and taking 12 patent grants. It reports its largest fourth quarter in annual recurring revenue without publishing a figure, its own measurement, so the record shows activity and leaves output per dollar unconfirmed. [s19, s4]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 IDC ran an assessment of worldwide certificate lifecycle management and named DigiCert a Leader, and an independent web survey tracks SSL certificate authorities as its own category with DigiCert Group listed inside it. Buyers place the company without vendor coaching, and nothing in the record shows DigiCert defining the category rather than fitting it. [s18, s13, s12]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 4/5 Google describes Chrome Root Store inclusion as exceptionally rigorous, puts the burden of proof entirely on the applicant, and guarantees no processing time. Its draft quantum-resistant root policy restricts early entry to operators of a usable Certificate Transparency log before February 2026, and two of DigiCert's logs have been usable since November 2024 and the rest since December 2025. Bundling does not produce that position. The browser makers grant it on their own terms, and Mozilla and Chrome removed DigiCert's G1 roots in April 2026, which is why the score stops below the top rung. [s9, s10, s11, s5]
Business Risks The browser makers grant root-program standing and can withdraw it…
  • The browser makers grant root-program standing and can withdraw it. Google distrusted peer Entrust's newly issued public TLS certificates in 2024, and Mozilla and Chrome removed DigiCert's own G1 root certificates in April 2026, so a compliance failure would land on the issuance business.
  • A threat actor compromised a DigiCert support analyst in April 2026 through a malicious file sent over a customer chat channel, and DigiCert revoked 60 code-signing certificates, 27 of them explicitly linked to that actor. DigiCert isolated a compromised machine on 3 April and found another on 14 April, which a malfunctioning endpoint agent had hidden from the earlier investigation.
  • Chrome will limit each authority to two active TLS roots in the Chrome Root Store from September 2027, which narrows the room DigiCert has to run parallel hierarchies for customers whose devices cannot follow a root transition.
  • Trust Lifecycle Manager imports certificates from any authority, so a rival can compete for the management layer without operating a publicly trusted root, leaving DigiCert to defend issuance and management on different grounds.
  • An independent web survey records one other authority on 64.4% of websites against DigiCert Group on 1.6%, so the volume of public web certificates sits elsewhere and DigiCert's growth has to come from enterprise assurance and management rather than from certificate count.
Problem & Market DigiCert sells into a problem the industry has put on a published clock…

DigiCert sells into a problem the industry has put on a published clock. The CA/Browser Forum has scheduled public TLS certificate validity down from 398 days to 47 days, with reductions running from March 2026 to March 2029, so renewal cycles keep shortening across that schedule.

The same buyer now faces a second change. NIST approved three post-quantum FIPS standards on 13 August 2024, and Google announced in February 2026 that Chrome will not add traditional X.509 certificates carrying post-quantum cryptography to its root store, routing that future through a separate quantum-resistant program. A buyer has to find and replace the cryptography inside its own estate.

The buyers are the security and infrastructure teams the IDC write-up puts in front of this work. DigiCert's own chief information security officer said during the 2024 revocation that many large organizations could not reissue and deploy new certificates everywhere in time, and named customers running critical infrastructure, telecommunications networks, cloud services and healthcare. [s6, s8, s10, s16, s18]

Product Capabilities DigiCert sells a platform alongside the certificates…

DigiCert sells a platform alongside the certificates. Its own platform page documents Trust Lifecycle Manager for certificate discovery and automation, Software Trust Manager for code signing, Device Trust Manager for device identity, Content Trust Manager for documents and content, UltraDNS for managed DNS, and Messaging Trust for email authentication.

Two of those lines are recent additions. DigiCert reports converging public key infrastructure and DNS by integrating UltraDNS into DigiCert ONE, and it acquired Valimail in September 2025, which an independent analyst describes as merging DMARC, SPF and DKIM policy automation with the mark certificates DigiCert already issued.

The management layer is deliberately open. Trust Lifecycle Manager imports certificates from any authority or trust store and builds inventory from cloud discovery scans, Certificate Transparency logs, APIs and CSV imports, so a buyer can point it at an estate DigiCert did not issue. [s2, s3, s4, s19]

Competitive Positioning DigiCert competes in two different contests at once…

DigiCert competes in two different contests at once. For public issuance an independent web survey records DigiCert certificates on 1.6% of all websites, behind Let's Encrypt at 64.4%, GlobalSign at 20.3%, Sectigo at 4.8% and GoDaddy Group at 3.5%. For management software the contest is with certificate lifecycle vendors, and IDC's January 2026 assessment named DigiCert a Leader there.

The root-program position separates DigiCert from a software-only rival. Google describes Chrome Root Store inclusion as exceptionally rigorous and places the burden of proof entirely on the applicant, and it counts operating a usable Certificate Transparency log among the behaviors it reads as a commitment to ecosystem resilience.

The record documents how that position can end. Google severed trust in Entrust in 2024 after what it described as a protracted period of compliance failures.

A separate kind of change runs on a schedule. Mozilla and Chrome removed DigiCert's G1 root certificates in April 2026, DigiCert moves default issuance to its G5 roots in October 2026, and Chrome caps each authority at two active TLS roots from September 2027, all root-generation work rather than a compliance sanction. [s12, s13, s18, s9, s17, s5]

Go-to-Market & Traction DigiCert's traction is visible in records it does not control…

DigiCert's traction is visible in records it does not control. An independent web survey includes Facebook, Microsoft, Apple, LinkedIn and Netflix among popular sites carrying DigiCert certificates, and IDC named DigiCert a Leader in its assessment of worldwide certificate lifecycle management in January 2026.

DigiCert's own record adds distribution and partnership motion. It reports a DigiCert ONE listing in AWS Marketplace, Trust Lifecycle Manager integrations with F5, HashiCorp, Jamf and NetScaler, and selection by ASC X9 to provide managed public key infrastructure for the financial services industry.

The scale numbers stay the company's own. DigiCert states more than 125,000 customers including over 90% of the Fortune 500, and reports its largest fourth quarter in annual recurring revenue without publishing the figure, so an outside reader cannot size the business. [s12, s18, s4, s1]

Team & Credibility DigiCert's leadership record is verifiable outside its own pages…

DigiCert's leadership record is verifiable outside its own pages. Zscaler's proxy statement records Amit Sinha as Zscaler's chief technology officer from December 2010 to January 2022 and then as its president, states that he became DigiCert's chief executive in October 2022, and describes more than 15 years as an architect and technical manager in networking and security.

DigiCert describes the bench around him. Its About page credits Sinha with 39 US patents granted or pending, chief technology officer Jason Sabin with more than 60 issued patents, chief product officer Deepika Chauhan with leading strategy for Symantec's Website Security business, and chief trust officer Lakshmi Hanspal with the global chief information security officer role at Amazon Devices and Services.

The standards work has names on it. The CA/Browser Forum's own record of Ballot SMC017 names DigiCert's Stephen Davidson as its proposer in April 2026, and SecurityWeek quoted DigiCert's chief information security officer Jeremy Rowley by name during the 2024 revocation. [s20, s1, s7, s6, s16]

Trust Readiness DigiCert sells trust, and its own conduct is on the public record…

DigiCert sells trust, and its own conduct is on the public record. Root-program rules, CA/Browser Forum ballots and Mozilla's certificate authority compliance bug tracker are all open, and a buyer can read that record instead of taking a briefing.

The record documents two failures. A domain validation bug forced DigiCert to revoke 83,267 certificates across 6,807 subscribers on 24 hours' notice in 2024, and its own chief information security officer said customers in critical infrastructure, telecommunications, cloud and healthcare could not reissue in time. In April 2026 a threat actor reached a support analyst through a customer chat channel with a malicious file, obtained initialization codes for approved code-signing orders, and DigiCert revoked 60 certificates, 27 of them explicitly linked to that actor.

A careful buyer takes the same question from both episodes. DigiCert's own timeline shows it isolating a compromised machine on 3 April and receiving a third-party report on 5 April, then finding another compromised machine on 14 April that a malfunctioning endpoint agent had hidden, so the question a buyer asks is how much of the fault its own pipeline sees. [s9, s15, s16, s14]

Competitors Sectigo, GlobalSign, Entrust…
Company Relationship Note Compare
Sectigo competes with Competes for the same public certificate issuance and lifecycle management buyers as another publicly trusted certificate authority. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
GlobalSign competes with Another publicly trusted certificate authority selling into the same public TLS and enterprise PKI buyers. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Entrust competes with Another publicly trusted certificate authority selling into the same public TLS buyers. Google announced in 2024 that Chrome would stop trusting Entrust's newly issued certificates by default. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with DigiCert.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Defensible 17 /21 Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate. press the advantage

DigiCert holds admission to the root programs Apple, Microsoft, Mozilla and Google run, which software does not supply. Google calls its own inclusion process exceptionally rigorous, puts the burden of proof on the applicant, and guarantees no processing time. Google's draft policy for a quantum-resistant trust store restricts early entry to operators of a usable Certificate Transparency log before February 2026, and Google's published list names six DigiCert logs, two of them usable since November 2024. The browser makers grant that standing and can narrow it. Trust Lifecycle Manager imports certificates from any authority, so a rival can match that management layer without root-program admission.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Code and expertise blend here. What a certificate buyer pays for is DigiCert's validation and the browser-accepted attestation that follows, and DigiCert carries the consequence when validation fails, revoking 83,267 certificates on 24 hours' notice in 2024 and 60 code-signing certificates in 2026. The six DigiCert ONE modules alongside that are software the customer configures and runs, which holds the score below the rung where judgment is the whole product.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving DigiCert means reissuing a certificate estate from another authority, which stays at the meaningful-friction level whatever the estate's size. Trust Lifecycle Manager imports certificates from any authority, so the management layer holds no estate in place either, and the cited record documents no hardware key custody, no code-embedded policy language and no sized migration that would carry the score higher.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 2/3 Root-program inclusion is an externally administered admission process rather than a certification DigiCert self-attests, and Google calls its own version exceptionally rigorous with the burden of proof entirely on the applicant. The same page says Google welcomes all organizations that can demonstrate meeting its high standard, so replacement stays slow and feasible rather than carrying the non-transferable mandate a higher score would need.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Running publicly trusted certificate authorities at internet scale, operating six of the Certificate Transparency logs Google publishes, and filing patents on post-quantum cryptography is cryptographic and distributed-systems engineering rather than integration work.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 DigiCert's own chief information security officer named affected customers running critical infrastructure, telecommunications networks, cloud services and healthcare during the 2024 revocation, an independent web survey includes Facebook, Microsoft, Apple, LinkedIn and Netflix among sites carrying its certificates, and DigiCert reports selection by ASC X9 to provide managed public key infrastructure for financial services. That is the regulated enterprise buyer class this rung describes.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Publicly trusted certificates and managed DNS carry the authentication and name resolution other systems need to work at all, and the 2024 revocation showed the dependency directly, with DigiCert's own chief information security officer saying customers could not reissue without risking critical service interruptions.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 The cited record evidences named assets DigiCert retains rather than a technique it uses. Root hierarchies admitted to browser and operating-system trust stores, six Certificate Transparency logs on Google's published list, and a patent portfolio DigiCert states at 230 are each named and held. A rival can reach the same position by satisfying an admission process Google guarantees no timeline for, the replicable-with-effort level, and no cross-customer telemetry corpus appears in the record.
Strategic Market Segmentation DigiCert targets the large organization that has to manage cryptographic trust at machine scale…

DigiCert targets the large organization that has to manage cryptographic trust at machine scale. The pain carries a published date. Twenty-five certificate authorities voted yes on the CA/Browser Forum ballot cutting public TLS validity from 398 days to 47, with reductions running from March 2026 to March 2029, and an IDC analyst describes certificate outages already reaching applications, supply chains and digital services.

The segment skews to regulated and at-scale buyers. DigiCert's own chief information security officer named critical infrastructure, telecommunications networks, cloud services and healthcare among the customers affected by the 2024 revocation, and an independent web survey includes Facebook, Microsoft, Apple, LinkedIn and Netflix among popular sites carrying DigiCert certificates.

Volume on the public web sits elsewhere. The same survey records DigiCert Group on 1.6% of all websites and one other authority on 64.4%, so the addressable segment is the assurance and management work rather than the certificate count.

Product Capabilities & AI Advantages DigiCert spans the trust stack on one platform…

DigiCert spans the trust stack on one platform. Its platform page documents Trust Lifecycle Manager for certificate discovery and automation, Software Trust Manager for code signing, Device Trust Manager for device identity, Content Trust Manager for documents and content, UltraDNS for managed DNS, and Messaging Trust for email authentication.

The differentiating capability is operating the trust anchors themselves. Google calls Chrome Root Store inclusion exceptionally rigorous with the burden of proof entirely on the applicant, and it counts operating a usable Certificate Transparency log among the behaviors that indicate a commitment to ecosystem resilience. Google's published log list records DigiCert running six such logs.

That capability now has a forward option attached. Google's draft policy for a quantum-resistant trust store restricts early entry to organizations that ran a usable Certificate Transparency log before February 2026, and Google's published list names six DigiCert logs, two of them usable since November 2024.

Sales Engagement & Go-to-Market DigiCert's traction is visible in records it does not control…

DigiCert's traction is visible in records it does not control. An independent web survey includes Facebook, Microsoft, Apple, LinkedIn and Netflix among popular sites carrying DigiCert certificates, and IDC named DigiCert a Leader in its January 2026 assessment of worldwide certificate lifecycle management.

Distribution and partnership motion come from DigiCert's own account. It reports a DigiCert ONE listing in AWS Marketplace, Trust Lifecycle Manager integrations with F5, HashiCorp, Jamf and NetScaler, and selection by ASC X9 to provide managed public key infrastructure for the financial services industry.

The scale figures stay the company's own measurements. DigiCert states more than 125,000 customers including over 90% of the Fortune 500 and reports its largest fourth quarter in annual recurring revenue without publishing the number, so an outside reader cannot size the business or its growth.

Pricing Model The cited record carries no price for the platform, so an outside reader cannot forecast what a deployment costs…

The cited record carries no price for the platform, so an outside reader cannot forecast what a deployment costs. Neither the product pages nor the fiscal-year account states a billing unit, a list price or a discount structure.

The one economic claim on the record is sponsored. DigiCert's Trust Lifecycle Manager page reports 96% fewer outages, $7.9M in operational savings and a 312% return on investment, and the same page states that the Total Economic Impact study is commissioned by DigiCert, that its results come from a composite organization, and that Forrester does not endorse DigiCert.

DigiCert reports its results as annual recurring revenue. Its fiscal 2026 account leads with a record fourth quarter in that measure and publishes no figure, so a reader can see the revenue shape the company reports and not its size.

Product Delivery & Operations DigiCert delivers a centralized platform across the public and private certificate work its buyers carry…

DigiCert delivers a centralized platform across the public and private certificate work its buyers carry. Trust Lifecycle Manager discovers certificates across cloud, applications and infrastructure and imports them from any authority or trust store, which is what makes compressing validity periods operable.

The operational load is moving toward automation on both sides of the transaction. DigiCert reports integrating UltraDNS into DigiCert ONE so certificates and DNS run in one system, and reports Trust Lifecycle Manager integrations with F5, HashiCorp, Jamf and NetScaler that push renewal into the infrastructure a customer already runs.

The harder operational question is what happens when DigiCert's own pipeline faults. A domain validation bug forced revocation of 83,267 certificates across 6,807 subscribers on 24 hours' notice in 2024, and DigiCert's chief information security officer said customers in critical infrastructure, telecommunications, cloud and healthcare could not reissue in time.

Earning Customers' Trust DigiCert sells trust, and its own conduct is on the public record…

DigiCert sells trust, and its own conduct is on the public record. Root-program rules, CA/Browser Forum ballots and Mozilla's certificate authority compliance bug tracker are all public, and a buyer can read that record instead of taking a briefing.

The record documents two failures inside two years. The 2024 domain validation bug forced revocation of 83,267 certificates on 24 hours' notice. In April 2026 a threat actor reached a DigiCert support analyst through a customer chat channel with a malicious file, used the analyst's session to read initialization codes for approved code-signing orders, and DigiCert revoked 60 certificates, 27 of them explicitly linked to that actor.

The detection path is the part a buyer should weigh. DigiCert isolated a compromised machine on 3 April, received a third-party report on 5 April, and found another compromised machine on 14 April that a malfunctioning endpoint agent had hidden from the earlier investigation.

Platform Strategy & Ecosystem Positioning DigiCert positions DigiCert ONE as the platform other trust needs plug into…

DigiCert positions DigiCert ONE as the platform other trust needs plug into. Its platform page documents six modules under one console, and Trust Lifecycle Manager imports certificates from any authority or trust store, so the platform accepts estates DigiCert did not issue.

Recent additions extended the platform sideways. DigiCert reports converging public key infrastructure and DNS by integrating UltraDNS into DigiCert ONE, and it acquired Valimail in September 2025, which an independent analyst describes as joining DMARC, SPF and DKIM policy automation to the mark certificates DigiCert already issued.

The openness cuts both ways. A management layer that manages any authority's certificates is a layer a rival can also build without root-program admission, so the ecosystem widens DigiCert's reach and does not extend the barrier that protects issuance.

Team & Execution Capability DigiCert's leadership record is verifiable outside its own pages…

DigiCert's leadership record is verifiable outside its own pages. Zscaler's proxy statement records Amit Sinha as Zscaler's chief technology officer from December 2010 to January 2022 and then as its president, states that he became DigiCert's chief executive in October 2022, and describes more than 15 years as an architect and technical manager in networking and security.

DigiCert describes the bench around him. Its About page credits Sinha with 39 US patents granted or pending, chief technology officer Jason Sabin with more than 60 issued patents, chief product officer Deepika Chauhan with leading strategy for Symantec's Website Security business, and chief trust officer Lakshmi Hanspal with the global chief information security officer role at Amazon Devices and Services.

The standards work has names on it. CA/Browser Forum ballot records show DigiCert's Stephen Davidson proposing Ballot SMC017 in April 2026, and SecurityWeek quoted DigiCert's chief information security officer Jeremy Rowley by name during the 2024 revocation.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 DigiCert: About page official 2026-08-25
f2 Wikipedia: DigiCert research 2026-08-25
f3 DigiCert: fiscal-year 2026 press release dateline official 2026-08-25
f4 PRNewswire: Crosspoint Capital Partners completes strategic investment in DigiCert press 2026-08-25
f5 DigiCert: DigiCert ONE platform page official 2026-08-25
Profile Analysis Sources (22)
Id Source Tier Accessed
s1 DigiCert: About page
“Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management to secure infrastructure, software, devices, messages, AI content and agents. See why we're chosen by security leaders in over 180 countries.”
official 2026-08-25
s2 DigiCert: DigiCert ONE platform page
“Unify PKI, DNS, and certificate lifecycles to enforce policy, secure AI-driven systems, and prevent outages.”
official 2026-08-25
s3 DigiCert: Trust Lifecycle Manager product page
“Import certificates from any CA or trust store”
official 2026-08-25
s4 DigiCert: fiscal-year 2026 results and portfolio press release
“Acquired Valimail, a leader in email authentication, expanding DigiCert ONE into zero trust email security to combat phishing, spoofing, and domain impersonation. During the year, Valimail surpassed 100,000 customers”
official 2026-08-25
s5 DigiCert: root strategy knowledge-base alert
“The Google Chrome Root Program is limiting certificate authorities to a maximum of two active TLS roots in the Chrome Root Store starting September 15, 2027.”
official 2026-08-25
s6 CA/Browser Forum: Ballot SC-081v3 on reducing TLS certificate validity and data-reuse periods
“Expand Section 6.3.2 to detail a schedule for reducing Public TLS certificate maximum validity periods in coming years Eventual reduction of maximum validity period from 398 days to 47 days”
regulatory 2026-08-25
s7 CA/Browser Forum: Ballot SMC017 on minimum RSA CA key size
“This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Ben Wilson (Mozilla) and Roman Fischer (SwissSign).”
regulatory 2026-08-25
s8 NIST CSRC: approval of three post-quantum cryptography FIPS standards
“The Secretary of Commerce has approved three Federal Information Processing Standards (FIPS ) for post-quantum cryptography: FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard”
regulatory 2026-08-25
s9 Chrome Root Program: apply for inclusion
“The burden of proof rests entirely on the Applicant to proactively and unequivocally demonstrate this commitment, thereby clearly offsetting the inherent and significant security risks of inclusion.”
regulatory 2026-08-25
s10 Chrome Quantum-resistant Root Program: draft policy version 0.3.0
“Initial eligibility for inclusion in the CQRS as an MTC CA Operator is restricted to organizations responsible for operating a “ usable ” Certificate Transparency (CT) Log prior to February 1, 2026.”
regulatory 2026-08-25
s11 Google: Chrome Certificate Transparency log list version 89.29
“"name": "DigiCert", "email": ["ctops@digicert.com"], "logs": [{"description": "DigiCert 'Wyvern2026h2'"”
regulatory 2026-08-25
s12 W3Techs: DigiCert Group usage as an SSL certificate authority
“DigiCert Group is used as SSL certificate authority by 1.7% of all the websites whose SSL certificate authority we know. This is 1.6% of all websites .”
research 2026-08-25
s13 W3Techs: SSL certificate authority usage overview
“Let’s Encrypt is used by 64.4% of all the websites, that is a SSL certificate authority market share of 67.8%.”
research 2026-08-25
s14 Bugzilla: DigiCert misissued code signing certificates, CA compliance incident report
“On 2026-04-02, a threat actor contacted DigiCert's support team via a customer chat channel and delivered a ZIP file disguised as a customer screenshot. The file contained a .scr executable with a malicious payload.”
regulatory 2026-08-25
s15 BleepingComputer: DigiCert mass-revoking TLS certificates over a domain validation bug
“DigiCert is warning that it will be mass-revoking SSL/TLS certificates due to a bug in how the company verified if a customer owned or operated a domain and requires impacted customers to reissue certificates within 24 hours.”
press 2026-08-25
s16 SecurityWeek: DigiCert revoking 83,000 certificates of 6,800 customers
“A DigiCert representative clarified in discussions with stakeholders that 83,267 certificates and 6,807 subscribers are affected.”
press 2026-08-25
s17 The Register: Google cuts ties with Entrust in Chrome over trust issues
“Google is severing its trust in Entrust after what it describes as a protracted period of failures around compliance and general improvements.”
press 2026-08-25
s18 SecurityBrief: DigiCert named a Leader in the IDC MarketScape for certificate lifecycle management
“DigiCert has been named a Leader in IDC MarketScape's vendor assessment for worldwide certificate lifecycle management.”
press 2026-08-25
s19 PAC: DigiCert acquires Valimail, why it matters and what to watch
“DigiCert issues VMCs (Verified Mark Certificates) and CMCs (Common Mark Certificates), while Valimail automates DMARC/SPF/DKIM management.”
research 2026-08-25
s20 SEC EDGAR: Zscaler, Inc. Form DEF 14A proxy statement
“Amit Sinha, Ph.D. has served as the chief executive officer and president, and as a board member of DigiCert, Inc., a global provider of digital trust solutions, since October 2022.”
regulatory 2026-08-25
s21 Wikipedia: DigiCert
“DigiCert was founded by Ken Bretschneider in 2003. [ 2 ] [ 3 ] [ 4 ] In 2005, DigiCert became a founding member of the CA/Browser Forum .”
research 2026-08-25
s22 PRNewswire: Crosspoint Capital Partners completes strategic investment in DigiCert
“today announced that Crosspoint Capital Partners, L.P. (together with its affiliates, "Crosspoint") has completed an investment in the Company. Crosspoint joins an ownership group that includes Clearlake Capital Group, L.P. (together with its affiliates, "Clearlake") and TA Associates ("TA").”
press 2026-08-25
Deep-Dive Sources (22)
Id Source Tier Accessed
s1 DigiCert: About page
“Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management to secure infrastructure, software, devices, messages, AI content and agents. See why we're chosen by security leaders in over 180 countries.”
official 2026-08-25
s2 DigiCert: DigiCert ONE platform page
“Unify PKI, DNS, and certificate lifecycles to enforce policy, secure AI-driven systems, and prevent outages.”
official 2026-08-25
s3 DigiCert: Trust Lifecycle Manager product page
“Import certificates from any CA or trust store”
official 2026-08-25
s4 DigiCert: fiscal-year 2026 results and portfolio press release
“Acquired Valimail, a leader in email authentication, expanding DigiCert ONE into zero trust email security to combat phishing, spoofing, and domain impersonation. During the year, Valimail surpassed 100,000 customers”
official 2026-08-25
s5 DigiCert: root strategy knowledge-base alert
“The Google Chrome Root Program is limiting certificate authorities to a maximum of two active TLS roots in the Chrome Root Store starting September 15, 2027.”
official 2026-08-25
s6 CA/Browser Forum: Ballot SC-081v3 on reducing TLS certificate validity and data-reuse periods
“Expand Section 6.3.2 to detail a schedule for reducing Public TLS certificate maximum validity periods in coming years Eventual reduction of maximum validity period from 398 days to 47 days”
regulatory 2026-08-25
s7 CA/Browser Forum: Ballot SMC017 on minimum RSA CA key size
“This ballot is proposed by Stephen Davidson (DigiCert) and endorsed by Ben Wilson (Mozilla) and Roman Fischer (SwissSign).”
regulatory 2026-08-25
s8 NIST CSRC: approval of three post-quantum cryptography FIPS standards
“The Secretary of Commerce has approved three Federal Information Processing Standards (FIPS ) for post-quantum cryptography: FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard”
regulatory 2026-08-25
s9 Chrome Root Program: apply for inclusion
“The burden of proof rests entirely on the Applicant to proactively and unequivocally demonstrate this commitment, thereby clearly offsetting the inherent and significant security risks of inclusion.”
regulatory 2026-08-25
s10 Chrome Quantum-resistant Root Program: draft policy version 0.3.0
“Initial eligibility for inclusion in the CQRS as an MTC CA Operator is restricted to organizations responsible for operating a “ usable ” Certificate Transparency (CT) Log prior to February 1, 2026.”
regulatory 2026-08-25
s11 Google: Chrome Certificate Transparency log list version 89.29
“"name": "DigiCert", "email": ["ctops@digicert.com"], "logs": [{"description": "DigiCert 'Wyvern2026h2'"”
regulatory 2026-08-25
s12 W3Techs: DigiCert Group usage as an SSL certificate authority
“DigiCert Group is used as SSL certificate authority by 1.7% of all the websites whose SSL certificate authority we know. This is 1.6% of all websites .”
research 2026-08-25
s13 W3Techs: SSL certificate authority usage overview
“Let’s Encrypt is used by 64.4% of all the websites, that is a SSL certificate authority market share of 67.8%.”
research 2026-08-25
s14 Bugzilla: DigiCert misissued code signing certificates, CA compliance incident report
“On 2026-04-02, a threat actor contacted DigiCert's support team via a customer chat channel and delivered a ZIP file disguised as a customer screenshot. The file contained a .scr executable with a malicious payload.”
regulatory 2026-08-25
s15 BleepingComputer: DigiCert mass-revoking TLS certificates over a domain validation bug
“DigiCert is warning that it will be mass-revoking SSL/TLS certificates due to a bug in how the company verified if a customer owned or operated a domain and requires impacted customers to reissue certificates within 24 hours.”
press 2026-08-25
s16 SecurityWeek: DigiCert revoking 83,000 certificates of 6,800 customers
“A DigiCert representative clarified in discussions with stakeholders that 83,267 certificates and 6,807 subscribers are affected.”
press 2026-08-25
s17 The Register: Google cuts ties with Entrust in Chrome over trust issues
“Google is severing its trust in Entrust after what it describes as a protracted period of failures around compliance and general improvements.”
press 2026-08-25
s18 SecurityBrief: DigiCert named a Leader in the IDC MarketScape for certificate lifecycle management
“DigiCert has been named a Leader in IDC MarketScape's vendor assessment for worldwide certificate lifecycle management.”
press 2026-08-25
s19 PAC: DigiCert acquires Valimail, why it matters and what to watch
“DigiCert issues VMCs (Verified Mark Certificates) and CMCs (Common Mark Certificates), while Valimail automates DMARC/SPF/DKIM management.”
research 2026-08-25
s20 SEC EDGAR: Zscaler, Inc. Form DEF 14A proxy statement
“Amit Sinha, Ph.D. has served as the chief executive officer and president, and as a board member of DigiCert, Inc., a global provider of digital trust solutions, since October 2022.”
regulatory 2026-08-25
s21 Wikipedia: DigiCert
“DigiCert was founded by Ken Bretschneider in 2003. [ 2 ] [ 3 ] [ 4 ] In 2005, DigiCert became a founding member of the CA/Browser Forum .”
research 2026-08-25
s22 PRNewswire: Crosspoint Capital Partners completes strategic investment in DigiCert
“today announced that Crosspoint Capital Partners, L.P. (together with its affiliates, "Crosspoint") has completed an investment in the Company. Crosspoint joins an ownership group that includes Clearlake Capital Group, L.P. (together with its affiliates, "Clearlake") and TA Associates ("TA").”
press 2026-08-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.