Skip to main content
resource · aws

AWS Certificate Manager Certificate

live rule families
1
schedulable
no
category
security-services

Does ZopNight manage AWS Certificate Manager Certificate?

ACM issues public TLS certificates at no charge and renews them automatically, so the meter here is zero; the risk is operational. ZopNight discovers every certificate on its 6-hour cycle and raises a finding when a certificate has fewer than 30 days left before expiry (RC-198), which maps the account's renewal gaps before they become outages.

Rules that fire on AWS Certificate Manager Certificate

At a glance

AWS Certificate Manager Certificate coverage facts.
Field Value
Scheduling notesdiscovery and hygiene recommendations only.

AWS Certificate Manager (ACM) issues and manages TLS certificates. Public ACM certificates are free, but they map which endpoints are exposed and expiring, and unattached or expired certificates signal hygiene gaps.

Certificates without a price tag

Public certificates requested through ACM cost nothing to issue, hold, or renew, and there is no per-certificate meter at any volume. The paid neighbours are easy to confuse with this: certificates issued through AWS Private CA carry that service’s own charges, and certificates imported from external CAs cost whatever the external CA charged. For the ACM-issued public certificate itself, the account pays only through the resources terminating TLS with it: the load balancers, CloudFront distributions, and API Gateway stages it attaches to.

What ZopNight reads off the certificate list

A dedicated provider inventories certificates on the 6-hour discovery cycle, and the output is hygiene rather than spend. One finding comes out of it: RC-198 flags any certificate with fewer than 30 days left before expiry. Renewal eligibility and unattached certificates are not separate findings; the console’s in-use and renewal-eligibility columns cover those by hand. The expiry finding still sketches the account’s renewal health.

Renewal failure modes worth catching early

ACM renews automatically only while it can validate domain ownership and the certificate is in use. The traps: a validation CNAME removed during a DNS migration silently blocks the next renewal; a certificate detached from its last load balancer stops renewing, then surprises whoever re-attaches it a year later; and wildcard certificates shared across teams expire with much wider blast radius than anyone tracked. An expired certificate on a live endpoint is an outage with a countdown that was visible months in advance.

Reviewing the certificate inventory

The Certificate Manager console lists certificates per region with status, in-use state, and renewal eligibility. Sorting by expiry and filtering for not-in-use covers most of the hygiene ground; anything expired or ineligible for renewal deserves either a fix or a deletion.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·