Sectigo
Commercial digital certificate authority
Sectigo is a commercial certificate authority that issues SSL/TLS certificates and other digital trust products used to secure websites, software, and enterprise infrastructure. Formerly known as Comodo CA before being spun off and…
Definition
Sectigo is a commercial certificate authority that issues SSL/TLS certificates and other digital trust products used to secure websites, software, and enterprise infrastructure. Formerly known as Comodo CA before being spun off and rebranded, it is one of the largest volume certificate issuers globally, offering certificates across the standard domain, organization, and extended validation tiers alongside code signing and enterprise PKI management tools.
Overview
Sectigo addresses the same core trust problem every certificate authority exists to solve: establishing that a website, piece of software, or device is who it claims to be, so that browsers, operating systems, and users can extend cryptographic trust to it. Before Sectigo can issue a certificate binding a public key to an identity, it must first validate that identity, and its root certificates must already be embedded in the trust stores that browsers and operating systems consult, a status it inherited and maintained through its history as Comodo CA, historically one of the highest-volume certificate issuers in the world. Mechanically, Sectigo operates within the standard public key infrastructure model shared by all commercial certificate authorities: a certificate signing request is submitted along with proof of domain control or, for higher assurance tiers, organizational identity documentation, Sectigo's validation systems verify the claim, and a signed certificate is issued that chains back to a Sectigo root trusted by browsers. Sectigo issues across the domain validation, organization validation, and extended validation tiers, and also runs a large reseller and channel partner network, meaning many Sectigo certificates reach end customers through hosting providers and other resellers rather than direct purchase, which partly explains its high issuance volume relative to brand recognition among end users. Sectigo competes directly with DigiCert, GlobalSign, and Entrust in the commercial certificate authority market, and has historically positioned itself at a lower price point with broader reseller distribution, while DigiCert has leaned more toward enterprise support and premium positioning. All of these paid authorities contrast with Let's Encrypt's free, automated, domain-validation-only model. In practice, web hosting companies, resellers, and small-to-midsize businesses obtain Sectigo certificates, often bundled through a hosting provider's control panel rather than purchased directly from Sectigo, while enterprises use Sectigo's direct enterprise certificate manager platform for organization and extended validation certificates and centralized lifecycle management across large certificate inventories. Sectigo also issues code signing certificates used by software vendors to sign released applications. The main trade-offs mirror those of any paid commercial CA relative to free alternatives: cost and, for higher validation tiers, a manual vetting process that takes longer than automated issuance. Sectigo's extensive reseller network is also a double-edged aspect of its business, since certificate purchasers do not always know they are buying a Sectigo-issued certificate, which can create confusion during renewal or support compared to purchasing directly from a named authority. Buyers evaluating Sectigo against direct competitors should weigh its channel-driven distribution and pricing against the more direct support relationship offered by authorities selling primarily under their own brand.
Key Features
- SSL/TLS certificate issuance across domain, organization, and extended validation tiers
- Large reseller and channel partner network including hosting providers
- Enterprise certificate manager platform for centralized lifecycle management
- Code signing certificates for software publisher verification
- Root certificates trusted across major browsers and operating systems
- Private PKI services for internal enterprise certificate needs
- High issuance volume inherited from its history as Comodo CA
- Support for wildcard and multi-domain certificates