AWS Certificate Manager Adds ACME Support for Automated TLS Certificates

Sébastien Stormacq· June 30, 2026 View original

▶ The 60-second brief

Summary

AWS Certificate Manager now supports the ACME protocol, allowing automated issuance and renewal of public TLS certificates using any ACMEv2-compatible client. This feature provides centralized governance, IAM-based access controls, and domain scoping, enhancing operational security.

AWS Certificate Manager (ACM) has introduced support for the Automatic Certificate Management Environment (ACME) protocol. This update enables organizations to automate the issuance and renewal of public Transport Layer Security (TLS) certificates across various workloads using any ACMEv2-compatible client. The integration aims to streamline certificate management processes, which is increasingly important as certificate lifetimes become shorter. The new functionality offers several benefits for administrators, including centralized governance over certificate lifecycles. It also provides robust access controls based on AWS Identity and Access Management (IAM) and allows for precise domain scoping. These features collectively help reduce operational risks associated with manual certificate management and ensure continuous security for web services.

Why it matters

Professionals can now automate a critical security task, reducing manual effort and human error in managing TLS certificates, especially with shorter certificate lifespans.

How to implement this in your domain

  1. 1Configure an ACMEv2-compatible client to interact with AWS Certificate Manager.
  2. 2Define IAM policies to control access for certificate issuance and renewal.
  3. 3Implement domain scoping to manage certificates for specific domains efficiently.
  4. 4Automate certificate renewal workflows to ensure continuous service availability.

Who benefits

Cloud ServicesCybersecurityE-commerceFinancial Services

Key takeaways

  • AWS ACM now supports ACME for automated public TLS certificate management.
  • This streamlines issuance and renewal, reducing manual overhead and risk.
  • Centralized governance and IAM controls enhance security posture.
  • It's crucial for maintaining continuous security with shorter certificate lifetimes.

Original post by Sébastien Stormacq

"AWS Certificate Manager now supports the ACME protocol for public TLS certificates, enabling automated issuance and renewal through any ACMEv2-compatible client on any workload. Administrators get centralized governance, IAM-based access controls, and domain scoping, reducing ope…"

View on X

Originally posted by Sébastien Stormacq on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses