From my perspective:
– Discoverability ( unless you plan to add them one by one manually )
– Supported protocols and sources ( MS PKI, SCEP, Windows Linux and other Cert Stores )
– Reporting and Alerting mechanism
– Usability ( I do not like tools that still only offer MMCs )
– Accessible and best standardized API
– Price!
– Cloud / OnPrem ( certificates contain crucial security information, decide what fits better for your orga )
– Support Models ( there are companies which don’t corporate with global IT organizations )
After comparing all those aspects my favorite is ManageEngines software.
https://www.manageengine.com/key-manager/