# AWS Certificate Manager (ACM)

> AWS Certificate Manager (ACM) issues, stores and automatically renews free public TLS certificates for load balancers, CloudFront and API Gateway.

- Source: https://www.itwonderlab.com/aws-acm/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Certificate Manager (ACM)** provisions and manages SSL/TLS certificates for AWS services. Public certificates issued by ACM are **free** and are **renewed automatically**, which removes the manual work and the outages caused by expired certificates.

### Key concepts

- **Integrated services**: a certificate can be used with [Elastic Load Balancing](https://www.itwonderlab.com/aws-elastic-load-balancing/), [CloudFront](https://www.itwonderlab.com/amazon-cloudfront/), [API Gateway](https://www.itwonderlab.com/aws-api-gateway/), AppSync and others. Public certificates **cannot be exported** to install them on an [EC2](https://www.itwonderlab.com/aws-ec2/) instance.
- **Validation**: ACM checks that you own the domain by a **DNS record** (recommended, it also allows automatic renewal) or by e-mail. With [Route 53](https://www.itwonderlab.com/aws-route-53/), the DNS record can be created automatically.
- **Wildcard certificates** (`*.example.com`) and several names per certificate are supported.
- A certificate belongs to a **Region**. Certificates used with CloudFront must be requested in **us-east-1**.
- **ACM Private CA** is a separate, paid service to issue private certificates for internal use.

### Pricing

Public certificates are free. AWS Private CA has a monthly charge per CA and per certificate.

### With Terraform

The resources are `aws_acm_certificate`, `aws_route53_record` (for the validation records) and `aws_acm_certificate_validation`, which waits until the certificate is issued.

See tutorials:

-   [AWS with Terraform: The Essential Guide (16/21) – AWS Load Balancers](https://www.itwonderlab.com/aws-terraform-tutorial-aws-load-balancers/): HTTPS with ACM and Route 53 validation
