
GITNUXSOFTWARE ADVICE
General KnowledgeTop 10 Best Cd Software of 2026
Top 10 Cd Software ranking for certificate and key management, including Cloudflare Zero Trust, AWS Certificate Manager, and HashiCorp Vault picks.
How we ranked these tools
Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.
Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.
AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.
Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.
Score: Features 40% · Ease 30% · Value 30%
Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy
Editor’s top 3 picks
Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.
Cloudflare Zero Trust
Identity-aware ZTNA policies with device posture and context-based conditional access
Built for organizations standardizing identity-based access across SaaS and private apps.
AWS Certificate Manager
Editor pickACM automatic certificate renewal for ACM-managed public certificates
Built for aWS-first teams needing automated TLS and internal PKI management.
HashiCorp Vault
Editor pickDynamic secrets engines that generate short-lived credentials with automatic leasing
Built for teams needing short-lived credentials and auditable secret access in delivery pipelines.
Related reading
Comparison Table
The comparison table evaluates certificate and key management tools across integration depth, their data model and schema for identities and secrets, and the automation plus API surface used for issuance, rotation, and provisioning. It also compares admin and governance controls, including RBAC, audit log coverage, configuration boundaries, and extensibility for workflow and policy. The entries include Cloudflare Zero Trust, AWS Certificate Manager, HashiCorp Vault, CyberArk Identity, and Okta Workforce Identity to show how each platform handles certificate lifecycle and access control.
Cloudflare Zero Trust
zero-trustProvides Zero Trust access control for applications with identity-aware policies, secure tunnels, and device posture checks.
Identity-aware ZTNA policies with device posture and context-based conditional access
Cloudflare Zero Trust centralizes identity-aware access decisions for users, devices, and applications using ZTNA and conditional access rules. It combines authenticated session context with device posture checks so access can change when endpoint signals or risk factors change. Private application connectivity keeps internal apps reachable through authenticated flows instead of open inbound exposure.
The platform can require more operational work to keep policies, device posture signals, and application access paths aligned across users and apps. It fits organizations that already have app inventories and identity sources and need consistent enforcement across SaaS apps, private services, and web traffic. Teams using conditional access for location, device health, or session context typically benefit from the unified policy controls.
- +Granular ZTNA policies tie access to identity, device checks, and session context
- +Integrated secure web gateway controls protect browsing and enforce traffic policies
- +Private application connectivity limits exposure by keeping services behind Zero Trust
- –Policy design can become complex across users, apps, and device posture states
- –Initial integration effort is higher than simpler SASE and firewall bundles
IT security policy owners
Apply conditional access by device posture
Reduced unauthorized access paths
Network operations teams
Protect web traffic with secure proxy
Consistent traffic enforcement
Show 1 more scenario
Platform teams for internal apps
Expose services via private connectivity
Lower attack surface
Connect internal applications through authenticated, authorized routes without public inbound access.
Best for: Organizations standardizing identity-based access across SaaS and private apps
More related reading
AWS Certificate Manager
certificate-managementIssues and manages TLS certificates for AWS services and private endpoints with automated renewal and lifecycle controls.
ACM automatic certificate renewal for ACM-managed public certificates
AWS Certificate Manager stands out for fully integrating certificate issuance and lifecycle management with AWS services. It automates public certificate provisioning for TLS endpoints and ties renewals directly to AWS managed resources.
It also supports private certificate use cases through ACM Private CA for internal PKI needs and certificate-based trust. The core value comes from reducing manual certificate handling while maintaining strong controls through AWS identity and service integrations.
- +Automated public certificate renewals for AWS-hosted endpoints
- +Tight integration with ELB and API Gateway for easy TLS enablement
- +ACM Private CA supports internal issuance and certificate chaining
- +Centralized certificate inventory with strong AWS permission controls
- –Public ACM certificates require AWS-based service attachment for full benefit
- –Cross-account and custom trust setups can add operational complexity
- –Advanced custom key and certificate workflows may be harder than manual tooling
Platform engineers managing TLS at scale
Automate public certs for load balancers
Reduced certificate operational overhead
Cloud security teams running internal PKI
Issue private certs via ACM Private CA
Consistent internal certificate trust
Show 1 more scenario
DevOps teams deploying API gateways
Maintain TLS certificates for API endpoints
Fewer TLS misconfiguration incidents
Use ACM-managed certificates to keep API Gateway endpoints compliant and continuously encrypted.
Best for: AWS-first teams needing automated TLS and internal PKI management
HashiCorp Vault
secrets-vaultCentralizes secrets storage and encryption with dynamic secrets, leasing, and strong access policies.
Dynamic secrets engines that generate short-lived credentials with automatic leasing
HashiCorp Vault stands out with a modular secrets and encryption system that can enforce dynamic access controls across many backends. It provides secure storage for secrets, offers automatic key management via its integrated crypto and leasing workflows, and supports multiple auth methods like AppRole and Kubernetes auth.
Vault integrates well into CI and delivery pipelines by issuing short-lived credentials that reduce static secret exposure and blast radius. It also supports auditing and fine-grained policies that help teams meet compliance requirements for secret access tracking.
- +Dynamic secrets and credential leasing reduce static secret exposure
- +Policy-based access control with strong auditing for secrets usage tracking
- +Multiple auth methods including AppRole and Kubernetes auth for automation
- +Transit and key management support encrypting and signing without app key handling
- –Setup and policy design require careful planning and operational expertise
- –Complex configuration across auth, engines, and policies can slow delivery teams
- –High availability and storage backend choices add operational overhead
Platform engineering teams
Issue short-lived database credentials via Vault policies
Reduced blast radius
Security and compliance teams
Audit secret access across multiple backends
Stronger access traceability
Show 2 more scenarios
CI and release engineering teams
Fetch secrets during builds using AppRole
Less static credential sprawl
Pipeline jobs authenticate once per run and request least-privilege secrets for deployments.
Cloud-native operations teams
Provide Kubernetes-native auth for services
Simplified workload access
Workloads authenticate with Kubernetes auth and receive scoped tokens for internal service dependencies.
Best for: Teams needing short-lived credentials and auditable secret access in delivery pipelines
More related reading
CyberArk Identity
identity-securityDelivers identity governance and secure access workflows that protect privileged operations using policy-driven controls.
Privileged access governance workflows using directory-integrated identity policies
CyberArk Identity centers on identity governance with strong support for user lifecycle and access governance workflows. The platform integrates with directory services, multi-factor authentication, and enterprise apps to enforce centralized authentication and policy controls. It also provides auditing and reporting hooks that help teams track identity-related events across systems.
- +Centralized identity lifecycle and access policy management across enterprise applications
- +Strong integrations with directory services and common authentication factors
- +Auditing and reporting for identity events tied to governance workflows
- –Identity governance workflows can require careful design to avoid policy friction
- –Admin setup complexity rises quickly with many apps and varied authentication paths
- –Deep reporting often depends on correct event mapping across connected systems
Best for: Enterprises standardizing authentication and identity governance across many apps
Okta Workforce Identity
identity-accessManages user identity and authentication with SSO, MFA, and app integrations backed by centralized policy controls.
Adaptive MFA and authentication policies that enforce risk-based access
Okta Workforce Identity stands out for centralized identity governance and strong enterprise authentication control across workforce and contractors. It supports SSO, MFA, lifecycle provisioning, and policy-based access that integrate with enterprise apps and directories.
The product also delivers workforce identity analytics and automated access workflows through role and group mappings. Admin tooling is mature for managing large user populations, with customization focused on security policies rather than developer-first workflow authoring.
- +Policy-based access controls across apps and networks
- +Automated user lifecycle with provisioning and deprovisioning
- +Robust MFA and adaptive authentication for workforce risk
- –Complex admin configuration for advanced workflows
- –Application onboarding can be heavy for large app catalogs
- –Integration tuning often requires identity architecture expertise
Best for: Enterprises standardizing workforce SSO, MFA, and lifecycle across many apps
Microsoft Entra ID
enterprise-identityProvides cloud identity services with authentication, authorization, and conditional access policies for applications.
Conditional Access
Microsoft Entra ID stands out with deep Microsoft ecosystem integration and broad identity coverage across enterprise directories. It provides centralized authentication, authorization, and identity lifecycle controls using features like conditional access and identity governance.
Its role-based access model, application registration, and SSO support cover common enterprise authentication patterns across cloud and on-premises systems. Strong auditability and policy enforcement help teams manage access consistently across many applications and user types.
- +Conditional Access policies enforce context-aware sign-in risk controls
- +Single sign-on and app registrations support modern authentication flows
- +Strong identity governance for joiner mover leaver lifecycle processes
- +Enterprise audit logs provide detailed tracking of authentication and changes
- –Policy complexity can slow setup for multi-app, multi-tenant environments
- –Advanced governance workflows require careful configuration and ongoing tuning
Best for: Enterprises standardizing SSO and access policies across many cloud and internal apps
More related reading
Google Identity Platform
auth-platformSupplies authentication and identity services for web and mobile apps with configurable sign-in methods and security policies.
Custom authentication with OAuth and OIDC session management
Google Identity Platform centers on identity federation at scale, combining Google sign-in and OAuth with enterprise SSO workflows. It provides configurable identity flows, including multi-factor authentication hooks and support for custom authentication using backend services. It also integrates tightly with Google Cloud for policies, session handling, and application-to-identity security patterns across web and mobile clients.
- +Strong OAuth and OIDC federation for web and mobile clients
- +Flexible authentication flows support custom backend-driven login logic
- +Enterprise-friendly SSO patterns with policy-driven identity management
- –Configuration complexity rises quickly for advanced custom authentication journeys
- –Debugging token and policy issues can take longer than expected
- –Setup depends on Google Cloud integration patterns for best results
Best for: Teams building enterprise SSO and federated authentication with custom login flows
Keycloak
open-source-iamRuns an open-source identity and access management server with SSO, OAuth, OIDC, and user federation support.
Authorization Services with policy evaluation for fine-grained access control
Keycloak stands out with a full identity and access management stack built around standards-based authentication and authorization. It delivers central user federation, identity brokering, and fine-grained authorization through roles and policies.
It also supports modern deployment patterns with Kubernetes and container-friendly operation, plus administrative automation via REST APIs and event streaming. For CD software contexts, it integrates cleanly with applications that need secure login, SSO, and API protection.
- +Supports SSO with OpenID Connect, OAuth 2.0, and SAML in one system
- +Provides user federation with LDAP and social identity providers
- +Delivers role-based and policy-based authorization for APIs and services
- +Offers a strong admin UI plus REST APIs for automation
- –Policy and client configuration complexity increases with enterprise setups
- –Operational tuning of sessions and caches can require deep expertise
- –Event handling and audit trails need additional setup for full coverage
- –Theme customization and advanced UX flows require nontrivial development
Best for: Enterprises standardizing authentication and authorization across many services
More related reading
Auth0
managed-authOffers managed identity and authentication with OAuth and OIDC flows, tenant configuration, and MFA options.
Actions for customizing login, token claims, and authentication flow logic
Auth0 distinguishes itself with a mature identity platform that supports OAuth 2.0, OpenID Connect, and SAML for enterprise sign-in. Core capabilities include customer and workforce authentication, social identity federation, and extensible login flows.
It also provides rules-like extensibility through Actions and robust management tooling for tenants, users, roles, and tokens. Strong integration options cover SDKs, managed connections, and webhook-driven workflows for authentication events.
- +Comprehensive OAuth, OIDC, and SAML support for diverse authentication needs
- +Actions extensibility enables custom logic in the authentication pipeline
- +Strong token handling with configurable claims and scopes for applications
- +Managed connections for social and enterprise identity providers
- –Advanced tenant configuration can require expertise in identity and security
- –Complex authorization setups often need careful testing across apps and redirects
Best for: Teams standardizing login across apps and enterprise SSO without building auth from scratch
DigitalOcean App Platform
app-deploymentDeploys and scales web applications with managed builds, networking controls, and HTTPS provisioning.
App Platform automated deployments from git with build and release pipeline management
DigitalOcean App Platform stands out with a managed application workflow that connects git-based deployments to build, runtime, and operations in a single control plane. It supports container-based apps, easy-to-configure app services, and automated HTTPS for public endpoints. The platform also offers managed databases, environment variables, health checks, and scaling policies to keep releases steady.
- +Visual app service configuration with git-based deployment triggers
- +Managed HTTPS and domains setup for production-ready endpoints
- +Environment variables and secrets management for safer deployments
- +Integrated build and runtime for container and framework workloads
- –Limited advanced CI orchestration compared with full CI platforms
- –Less granular infrastructure control than Kubernetes-first setups
- –Monitoring and debugging depth can lag behind dedicated observability stacks
Best for: Teams deploying web APIs quickly with managed scaling and HTTPS
Conclusion
After evaluating 10 general knowledge, Cloudflare Zero Trust stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.
Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.
How to Choose the Right Cd Software
This buyer’s guide covers certificate and key management control surfaces across Cloudflare Zero Trust, AWS Certificate Manager, HashiCorp Vault, CyberArk Identity, Okta Workforce Identity, Microsoft Entra ID, Google Identity Platform, Keycloak, Auth0, and DigitalOcean App Platform.
It focuses on integration depth, the certificate and key data model, automation and API surface, and admin and governance controls that affect operational control. Each section explains how to evaluate how policies and credentials move through identity, TLS, secrets, and deployment workflows.
CD software for certificate and key control across identity, TLS, and secrets
Certificate and key management in CD software means automating certificate issuance and renewal, controlling private key usage, and wiring trust into delivery and access paths. AWS Certificate Manager covers automated public TLS certificate renewals for AWS-hosted endpoints and lifecycle controls tied to AWS services.
HashiCorp Vault extends the same automation mindset to secrets and keys by generating short-lived credentials via dynamic secrets engines with automatic leasing. These tools are used by teams that need controlled certificate inventory, auditable access to secrets or keys, and consistent policy enforcement across users, devices, applications, and private services.
Integration, data model, automation, and governance checks for certificate and key management
The integration depth across certificate services, identity providers, and runtime environments determines whether certificate trust and key material stays consistent across deployments. Cloudflare Zero Trust connects identity-aware access decisions to ZTNA policies and device posture signals so application access changes based on session context.
The data model and API surface determine how certificate and key state is represented and automated. HashiCorp Vault pairs dynamic secrets with leasing workflows and multiple auth methods like AppRole and Kubernetes auth so short-lived credentials can flow through pipelines.
Identity-aware access policy wiring for private app connectivity
Cloudflare Zero Trust supports identity-aware ZTNA policies using device posture checks and conditional access signals. This matters because certificate-backed application endpoints remain reachable through authenticated flows without open inbound exposure.
Certificate lifecycle automation with cloud-native attachment
AWS Certificate Manager automates public certificate renewals for ACM-managed public certificates and ties certificate usage to AWS managed resources. This matters because TLS enablement depends on correct resource attachment to services like ELB and API Gateway.
Private PKI support with certificate chaining for internal trust
ACM Private CA supports internal issuance and certificate chaining for private certificate use cases. This matters because CD workflows often need internal trust chains that differ from public CA paths.
Dynamic secrets and automatic leasing for short-lived key access
HashiCorp Vault generates short-lived credentials via dynamic secrets engines with automatic leasing. This matters because it reduces static secret exposure and limits blast radius when certificates or keys are consumed by automation.
Auditability paired with policy-based access control
HashiCorp Vault includes auditing and fine-grained policies for secrets usage tracking. CyberArk Identity provides auditing and reporting hooks for identity events tied to governance workflows, which matters when certificate access is triggered by privileged operations.
Admin governance controls over access and authentication state
Microsoft Entra ID provides Conditional Access and identity governance for joiner mover leaver lifecycle processes with enterprise audit logs. Okta Workforce Identity adds adaptive MFA and policy-based access controls across applications, which matters when key usage should be gated on risk-based sign-in outcomes.
Decision framework for selecting a certificate and key management tool with enforceable automation
Start with the integration endpoints that must be controlled in the CD path. Cloudflare Zero Trust is a fit when private applications must enforce identity-aware ZTNA policies with device posture and conditional access context.
Then map the credential lifecycle to the data model and API automation surface. AWS Certificate Manager fits when TLS endpoints are AWS-managed and certificate renewals must be attached to AWS services, while HashiCorp Vault fits when keys and secrets must be issued as short-lived credentials with leasing and auditable access.
Identify where TLS trust must land in the deployment path
If TLS certificates need to be attached to AWS endpoints such as ELB and API Gateway, AWS Certificate Manager is the most direct control plane because it automates ACM-managed public certificate renewals for AWS resources. If trust decisions must change based on user session context and device posture, Cloudflare Zero Trust should be evaluated for identity-aware ZTNA policy enforcement.
Choose a data model that matches certificate and key lifecycles
For certificate inventory and automated renewal tied to AWS resource attachments, AWS Certificate Manager represents lifecycle at the certificate and resource binding level. For secret and key usage that must be short-lived, HashiCorp Vault represents lifecycle through dynamic secrets engines and leasing workflows.
Verify automation and API surface for pipeline-driven provisioning
HashiCorp Vault is built for CI and delivery pipelines by issuing short-lived credentials that reduce static secret exposure. For identity-driven access gates that affect certificate-backed service access, Cloudflare Zero Trust enforces access based on conditional access rules and device posture signals that can be aligned with identity sources.
Lock down governance with RBAC and audit log coverage
HashiCorp Vault pairs policy-based access control with auditing for secrets usage tracking, which matters for compliance reporting. Microsoft Entra ID and Okta Workforce Identity add governance through Conditional Access and adaptive authentication policies with enterprise audit logs tied to sign-in and policy changes.
Stress-test multi-app policy complexity before committing
Cloudflare Zero Trust can require operational work to keep ZTNA policies, device posture signals, and application access paths aligned across users and apps. Okta Workforce Identity and Microsoft Entra ID can also slow setup when advanced workflows expand across large app catalogs or multi-tenant environments.
Select identity-first tools that match the platform boundary
CyberArk Identity is a strong match for privileged access governance workflows that depend on directory-integrated identity policies and identity lifecycle governance. Auth0 and Google Identity Platform are more relevant when custom authentication flows must feed downstream OAuth and OIDC tokens that gate access to CD-managed services.
Which teams should prioritize certificate and key management control
Different CD stacks need certificate and key controls at different layers. Some teams need TLS issuance and renewal control tied to runtime endpoints, while others need secret issuance and key access that changes per request.
The best-fit selection depends on whether policy enforcement happens at the identity access layer or at the certificate and secrets lifecycle layer. Cloudflare Zero Trust and AWS Certificate Manager cover two different enforcement planes with distinct data models.
AWS-first teams that need automated TLS certificate lifecycle for endpoints
AWS Certificate Manager fits teams that require automated public certificate renewals for AWS-hosted endpoints and tight integration with ELB and API Gateway. It also supports internal PKI via ACM Private CA when internal certificate chaining is required.
Delivery and platform teams that must issue short-lived key and secret credentials
HashiCorp Vault fits teams that want dynamic secrets engines to generate short-lived credentials with automatic leasing. It reduces static secret exposure in CI and supports policy-based access with auditing.
Enterprises that must gate private app access using identity and device posture context
Cloudflare Zero Trust fits organizations standardizing identity-based access across SaaS and private apps. Its identity-aware ZTNA policies tie access to device posture and session context so certificate-backed services remain protected.
Organizations standardizing enterprise identity governance for access and privileged operations
CyberArk Identity fits enterprises standardizing authentication and identity governance across many apps with privileged access governance workflows. Microsoft Entra ID and Okta Workforce Identity fit teams that standardize Conditional Access or adaptive MFA across large app catalogs.
Teams building federated or standards-based auth that gates CD-managed services
Google Identity Platform fits teams building enterprise SSO and federated authentication with custom OAuth and OIDC session management. Auth0 and Keycloak fit teams that need Actions-based pipeline customization or policy evaluation with OpenID Connect and OAuth across services.
Operational pitfalls that break certificate and key management in CD pipelines
Certificate and key management failures often come from mismatched policy layers or from automation surfaces that do not cover the credential lifecycle. Cloudflare Zero Trust and CyberArk Identity can both require careful alignment of policies with connected systems.
Other failures come from choosing tools that cover certificate renewal but not short-lived key usage or from identity governance that is too complex to sustain across many apps. These issues appear as policy friction, debugging overhead, or misaligned access paths during onboarding.
Designing access policies without accounting for device posture and session context
Cloudflare Zero Trust can require more operational work to keep ZTNA policies aligned across users, apps, and device posture states. A corrective step is to validate conditional access rules against how session context changes for the target client devices before scaling policy coverage.
Assuming certificate renewal alone covers private key usage control
AWS Certificate Manager automates certificate renewals for ACM-managed public certificates but it does not replace secrets delivery for short-lived key access. HashiCorp Vault addresses this gap with dynamic secrets engines and automatic leasing so pipeline jobs get short-lived credentials.
Underestimating policy and admin configuration complexity across many apps
Okta Workforce Identity can involve complex admin configuration for advanced workflows and heavy application onboarding for large app catalogs. Microsoft Entra ID can also slow setup in multi-app, multi-tenant environments, so policy templates and rollout sequencing must be designed up front.
Skipping audit and event mapping coverage for governance-driven access
HashiCorp Vault provides auditing and fine-grained policies for secrets usage tracking, while CyberArk Identity depends on correct event mapping across connected systems for deep reporting. A corrective step is to define which audit events are required for key or certificate access decisions and ensure connected systems map those events consistently.
Building custom auth flows that complicate debugging and token policy alignment
Google Identity Platform can increase configuration complexity for advanced custom authentication journeys and debugging token or policy issues can take longer than expected. Auth0 Actions and Keycloak authorization services also increase configuration surface area, so test coverage must cover redirects, claims, and policy evaluation paths.
How We Selected and Ranked These Tools
We evaluated Cloudflare Zero Trust, AWS Certificate Manager, HashiCorp Vault, CyberArk Identity, Okta Workforce Identity, Microsoft Entra ID, Google Identity Platform, Keycloak, Auth0, and DigitalOcean App Platform using a criteria-based scoring approach that emphasized features and then accounted for ease of use and value. Each tool received an editorial score across features, ease of use, and value, with features weighted most heavily because certificate and key management depend on concrete automation and control surfaces.
Cloudflare Zero Trust separated itself because identity-aware ZTNA policies tie access to device posture and conditional access context and because private application connectivity keeps services behind authenticated flows. That combination raised its features and ease-of-use outcomes by making policy enforcement more consistent across users and private apps.
Frequently Asked Questions About Cd Software
How do Cloudflare Zero Trust and Vault differ for certificate and key management automation?
Which tool best automates TLS certificate issuance for workloads running on AWS?
What’s the common API and integration pattern for RBAC and policy enforcement across tools like Keycloak and Auth0?
How do SSO and conditional access controls compare between Microsoft Entra ID and Okta Workforce Identity?
Which platform is better suited for identity federation with custom authentication flows using OAuth and OIDC?
How do Vault and CyberArk Identity handle auditing for access to secrets and identities?
What data migration work is typically required when adopting Keycloak or Auth0 for existing SSO integrations?
How do admin controls differ between Okta Workforce Identity and DigitalOcean App Platform in deployment operations?
Which tool is most appropriate for protecting private services with authenticated connectivity rather than open inbound exposure?
Tools reviewed
Primary sources checked during evaluation.
Referenced in the comparison table and product reviews above.
Keep exploring
Comparing two specific tools?
Software Alternatives
See head-to-head software comparisons with feature breakdowns, pricing, and our recommendation for each use case.
Explore software alternatives→In this category
General Knowledge alternatives
See side-by-side comparisons of general knowledge tools and pick the right one for your stack.
Compare general knowledge tools→FOR SOFTWARE VENDORS
Not on this list? Let’s fix that.
Our best-of pages are how many teams discover and compare tools in this space. If you think your product belongs in this lineup, we’d like to hear from you—we’ll walk you through fit and what an editorial entry looks like.
Apply for a ListingWHAT THIS INCLUDES
Where buyers compare
Readers come to these pages to shortlist software—your product shows up in that moment, not in a random sidebar.
Editorial write-up
We describe your product in our own words and check the facts before anything goes live.
On-page brand presence
You appear in the roundup the same way as other tools we cover: name, positioning, and a clear next step for readers who want to learn more.
Kept up to date
We refresh lists on a regular rhythm so the category page stays useful as products and pricing change.
