DigiCert Software Trust Manager & DigiCert KeyLocker: Technical Difference Explained

Code signing has quietly become one of the more scrutinized parts of the software release process. Every CA/Browser Forum policy change over the past few years has pushed private keys further away from a developer’s local machine and into managed, auditable storage. DigiCert built two products to answer that shift: KeyLocker and Software Trust Manager. Teams evaluating either one usually assume they are picking between two versions of the same thing. They aren’t. This piece breaks down what each product actually does, where the line between them sits, and how to decide which one fits your release process.

What Is DigiCert KeyLocker?

KeyLocker is DigiCert’s cloud-hosted key storage service for code signing certificates. It removes the need for a physical USB token or an on-premises hardware security module by keeping the private key inside DigiCert’s FIPS 140-2 Level 3 cloud HSM. Signing requests are sent to the key rather than the key being handed to the machine doing the signing.

For a lot of development teams, that alone solves the operational headache tokens create — no shipping hardware between machines, no losing a token before a release, no plugging a dongle into a build server that lives in a data center three time zones away.

Key Features of DigiCert KeyLocker

  • Cloud HSM key storage compliant with CA/Browser Forum baseline requirements for OV and EV code signing keys
  • Command-line signing via SMCTL, which plugs into most CI/CD pipelines without custom scripting
  • Batch signing for teams pushing multiple binaries per release cycle
  • Per-operation or per-unit pricing, purchased as an add-on to an existing code signing certificate rather than as a standalone platform

KeyLocker is deliberately narrow in scope. It stores the key and executes the signature. It does not tell you who is allowed to sign what, and it doesn’t keep a governance-grade record of every signing event across a distributed team.

What Is DigiCert Software Trust Manager?

Software Trust Manager starts from the same cloud HSM foundation but adds a governance layer on top of it. Where KeyLocker answers “where does the key live,” Software Trust Manager answers “who gets to use it, under what conditions, and how do we prove it afterward.”

Practically, that means role-based access controls, approval workflows before a signature is issued, and a full audit trail tying every signed artifact back to a person, a policy, and a timestamp. It’s built for organizations where code signing isn’t a single build server but a distributed set of teams, repos, and release pipelines that all need to follow the same rules.

Key Features of DigiCert Software Trust Manager

  • Policy-driven signing — define who can sign which artifacts, under which certificate, before a signature is ever issued
  • Centralized audit logging across every signing event, useful for SOC 2, ISO 27001, or internal security reviews
  • SBOM generation to document software components as part of the signing workflow
  • CI/CD plugin support across common pipelines, plus OpenSSL and Notation integrations for container image signing
  • Cross-platform coverage for Windows, Linux, and macOS build environments

The tradeoff is complexity. Software Trust Manager takes longer to configure because it’s built to enforce structure across teams that don’t all report to the same release manager.

DigiCert Software Trust Manager vs KeyLocker: Key Differences

DigiCert KeyLocker DigiCert Software Trust Manager
Core function Cloud HSM key storage and signing Key storage plus governance and policy enforcement
Access control Basic — tied to certificate ownership Role-based, approval-driven
Audit trail Limited signing logs Full, exportable audit history
SBOM support Not included Included
Best fit Single team, single pipeline Distributed teams, multiple pipelines, regulated environments
Setup effort Low — add-on to existing certificate Higher — policy and role configuration required
Purchase model Add-on to a code signing certificate Standalone enterprise platform

The gap between the two isn’t really about signing capability — both can sign a binary reliably. It’s about accountability at scale. A five-person team doesn’t need an approval workflow before every signature. A five-hundred-person org with three release pipelines does.

Which DigiCert Code Signing Solution Should You Choose?

The decision usually comes down to how many people can currently sign code without anyone else knowing about it. If that number is small and your pipeline is simple, KeyLocker covers the compliance requirement without adding process overhead. If that number makes you uneasy, Software Trust Manager is the one built to fix it.

When KeyLocker Is Enough

  • A single development team building one product line
  • One or two CI/CD pipelines, not a sprawl of them across business units
  • No internal requirement yet for signing approval workflows or SBOM generation
  • The main goal is meeting CA/Browser Forum key storage requirements without a physical token

When You Need Software Trust Manager

  • Multiple teams, geographies, or business units signing under the same organization
  • Regulatory or customer requirements around auditability and SBOM proof
  • A need to restrict who can sign production-bound artifacts versus test builds
  • Prior incidents — internal or industry-wide — that made key misuse a board-level concern rather than a theoretical risk

Important Update: Software Trust Manager’s Deprecation and Migration Path

Anyone researching this comparison right now should know DigiCert has scheduled Software Trust Manager for deprecation on May 1, 2026. The replacement is DigiCert Binary Signing, a rebuilt signing service inside the DigiCert ONE platform that carries forward the governance and policy features Software Trust Manager customers rely on.

If your organization is currently running Software Trust Manager, migration isn’t optional — it’s a matter of timing. DigiCert has indicated Binary Signing is meant to be a like-for-like upgrade rather than a scaled-back replacement, but any migration of this size warrants a review of your current policies, roles, and CI/CD integrations before the cutover rather than after it.

KeyLocker isn’t affected by this change. It continues to operate as DigiCert’s standalone cloud HSM offering independent of the Software Trust Manager to Binary Signing transition.

Frequently Asked Questions

What’s the difference between DigiCert Software Trust Manager and KeyLocker?

KeyLocker stores and uses your code signing key in a cloud HSM. Software Trust Manager does the same thing but adds role-based access, approval workflows, audit logging, and SBOM generation on top of it.

Should I use DigiCert KeyLocker or Software Trust Manager for code signing?

If one team manages your signing process end to end, KeyLocker is usually sufficient. If multiple teams or pipelines need shared but controlled access to signing, Software Trust Manager is the better fit.

Is DigiCert KeyLocker the same as Software Trust Manager?

No. They share the same underlying cloud HSM technology, but KeyLocker is a standalone key storage add-on while Software Trust Manager is a full governance platform built around that storage.

Which DigiCert product do I need for CI/CD code signing automation?

Both integrate with CI/CD pipelines through SMCTL and related plugins. The difference is what happens around the signing step — Software Trust Manager adds policy checks and logging that KeyLocker does not.

Does KeyLocker include governance and policy controls like Software Trust Manager?

No. KeyLocker handles key storage and signing execution. Access is tied to certificate ownership rather than configurable roles, approval chains, or centralized audit reporting.

Can small teams use DigiCert KeyLocker instead of Software Trust Manager?

Yes, and most do. KeyLocker meets the CA/Browser Forum key storage requirement without the configuration overhead of a governance platform that a small, single-pipeline team doesn’t need yet.

Is DigiCert Software Trust Manager being replaced or deprecated?

Yes. DigiCert has set May 1, 2026 as the deprecation date for Software Trust Manager, with DigiCert Binary Signing as the designated successor product within DigiCert ONE.

Do I need Software Trust Manager if I already have KeyLocker with my code signing certificate?

Not necessarily. KeyLocker satisfies the key storage requirement on its own. You’d add Software Trust Manager only if you need governance features KeyLocker doesn’t provide, like approval workflows or SBOM generation.

Conclusion

KeyLocker and Software Trust Manager solve two different problems that happen to share the same underlying HSM infrastructure. KeyLocker keeps a key safe and available. Software Trust Manager keeps an entire organization’s signing activity governed and provable. Neither is the “upgraded” version of the other — the right one depends on how many hands are near your signing keys and how much proof you need of what happened when they were used. With Software Trust Manager’s migration to Binary Signing now on the calendar, it’s worth confirming which category your organization falls into before that transition arrives.

Need a Code Signing Certificate?

Compare Comodo, Sectigo, and DigiCert code signing options starting at $226.10/yr.

Buy Cheap Code Signing Certificates

Leave a Reply

Your email address will not be published. Required fields are marked *