Skip to main content
resource · aws

AWS Certificate Manager Certificate

live rule families
1
schedulable
no
category
security-services

Does ZopNight manage AWS Certificate Manager Certificate?

ACM issues public TLS certificates at no charge and renews them automatically, so the meter here is zero; the risk is operational. ZopNight discovers every certificate on its 6-hour cycle and raises hygiene findings for expired, expiring, and unattached certificates, which map the account's exposed endpoints and their renewal gaps.

Rules that fire on AWS Certificate Manager Certificate

At a glance

AWS Certificate Manager Certificate coverage facts.
Field Value
Scheduling notesdiscovery and hygiene recommendations only.

AWS Certificate Manager (ACM) issues and manages TLS certificates. Public ACM certificates are free, but they map which endpoints are exposed and expiring, and unattached or expired certificates signal hygiene gaps.

Certificates without a price tag

Public certificates requested through ACM cost nothing to issue, hold, or renew, and there is no per-certificate meter at any volume. The paid neighbours are easy to confuse with this: certificates issued through AWS Private CA carry that service’s own charges, and certificates imported from external CAs cost whatever the external CA charged. For the ACM-issued public certificate itself, the account pays only through the resources terminating TLS with it: the load balancers, CloudFront distributions, and API Gateway stages it attaches to.

What ZopNight reads off the certificate list

A dedicated provider inventories certificates on the 6-hour discovery cycle, and the output is hygiene rather than spend. Three findings matter: expired certificates, which indicate an endpoint that either broke or quietly stopped mattering; expiring certificates that are not eligible for automatic renewal, usually because DNS validation records were deleted or the certificate is unused; and unattached certificates, which accumulate as endpoints get rebuilt and reveal how much of the TLS estate is dead inventory. Together they sketch the account’s exposed surface and its renewal health.

Renewal failure modes worth catching early

ACM renews automatically only while it can validate domain ownership and the certificate is in use. The traps: a validation CNAME removed during a DNS migration silently blocks the next renewal; a certificate detached from its last load balancer stops renewing, then surprises whoever re-attaches it a year later; and wildcard certificates shared across teams expire with much wider blast radius than anyone tracked. An expired certificate on a live endpoint is an outage with a countdown that was visible months in advance.

Reviewing the certificate inventory

The Certificate Manager console lists certificates per region with status, in-use state, and renewal eligibility. Sorting by expiry and filtering for not-in-use covers most of the hygiene ground; anything expired or ineligible for renewal deserves either a fix or a deletion.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·