diff --git a/modules/acm/README.md b/modules/acm/README.md
index 24d15500d..55d0ab71a 100644
--- a/modules/acm/README.md
+++ b/modules/acm/README.md
@@ -68,7 +68,7 @@ components:
| Name | Source | Version |
|------|--------|---------|
-| [acm](#module\_acm) | cloudposse/acm-request-certificate/aws | 0.16.0 |
+| [acm](#module\_acm) | cloudposse/acm-request-certificate/aws | 0.16.3 |
| [dns\_delegated](#module\_dns\_delegated) | cloudposse/stack-config/yaml//modules/remote-state | 1.5.0 |
| [iam\_roles](#module\_iam\_roles) | ../account-map/modules/iam-roles | n/a |
| [private\_ca](#module\_private\_ca) | cloudposse/stack-config/yaml//modules/remote-state | 1.5.0 |
diff --git a/modules/acm/main.tf b/modules/acm/main.tf
index a2234c44d..1b1d1e67c 100644
--- a/modules/acm/main.tf
+++ b/modules/acm/main.tf
@@ -22,7 +22,7 @@ data "aws_route53_zone" "default" {
# https://github.com/cloudposse/terraform-aws-acm-request-certificate
module "acm" {
source = "cloudposse/acm-request-certificate/aws"
- version = "0.16.0"
+ version = "0.16.3"
certificate_authority_arn = local.private_ca_enabled ? module.private_ca[0].outputs.private_ca[var.certificate_authority_component_key].certificate_authority.arn : null
validation_method = local.private_ca_enabled ? null : var.validation_method
diff --git a/modules/dns-primary/README.md b/modules/dns-primary/README.md
index ad0a6475f..9c0023715 100644
--- a/modules/dns-primary/README.md
+++ b/modules/dns-primary/README.md
@@ -94,7 +94,7 @@ Use the [acm](/components/library/aws/acm) component for more advanced certific
| Name | Source | Version |
|------|--------|---------|
-| [acm](#module\_acm) | cloudposse/acm-request-certificate/aws | 0.16.2 |
+| [acm](#module\_acm) | cloudposse/acm-request-certificate/aws | 0.16.3 |
| [iam\_roles](#module\_iam\_roles) | ../account-map/modules/iam-roles | n/a |
| [this](#module\_this) | cloudposse/label/null | 0.25.0 |
diff --git a/modules/dns-primary/acm.tf b/modules/dns-primary/acm.tf
index a86be253a..88fd79a1e 100644
--- a/modules/dns-primary/acm.tf
+++ b/modules/dns-primary/acm.tf
@@ -13,7 +13,7 @@ module "acm" {
source = "cloudposse/acm-request-certificate/aws"
// Note: 0.17.0 is a 'preview' release, so we're using 0.16.2
- version = "0.16.2"
+ version = "0.16.3"
enabled = local.certificate_enabled