Fri, 11 Sep 2026

The next phase of certificate management

Certificate management was treated largely as a compliance and maintenance function for years.

For some organisations, the path was predictable: ensure certificates are issued by trusted authorities, renew them before they expire, and keep internet-facing services available.

However, two forces are converging to change certificate management's role: accelerating reduction in the validity period of publicly trusted TLS certificates, and the global transition toward post-quantum cryptography.

The shift turns certificate management from an annual administrative exercise into a continuous cybersecurity and business operations strategy.

Dennis Tee

Dennis Tee, director of Cybersecurity at TruVisor, explains why it has become such a critical part of an organisation's cybersecurity strategy and how to establish certificate operations as a permanent enterprise capability.

From annual renewal to continuous certificate operations

The security objective is to reduce the window during which compromised, incorrectly issued, or outdated certificates can remain trusted. Dennis Tee

According to CA/Browser Forum's SC-081v3 there will be a reduction in the maximum validity of publicly trusted TLS certificates, done in stages.

Certificates issued from March 15, 2026 may have a maximum validity period of 200 days. However, the maximum validity period can fall to as little as 47 days in 2029.

"This is not a regulation affecting only one country or industry; any organisation operating internet-facing systems will be affected. The security objective is to reduce the window during which compromised, incorrectly issued, or outdated certificates can remain trusted," Tee shared.

Shorter certificate lifetimes also mean a certificate that once required attention roughly once a year will eventually need to be replaced on a roughly 6-week cycle. For organisations with hundreds of certificates distributed across websites, APIs, cloud platforms, load balancers, containers, servers, and network infrastructure, manual coordination becomes increasingly difficult to sustain.

Tee added: "Certificate management has therefore moved beyond being a specialist PKI responsibility. It now affects business continuity, customer access, regulatory assurance and digital trust."

Common challenges

For Tee, the regulation doesn't create poor certificate-management practices, but exposes them.

Many organisations still lack a complete inventory of their certificates. Cybersecurity, infrastructure, DevOps, cloud, application, and network teams may manage certificates separately. Some may exist in public cloud environments while others reside in internal applications, appliances, private PKI systems or legacy infrastructure.

Related:  Robust cybersecurity urged amid rising healthcare data breaches

Tee said this creates three fundamental weaknesses: incomplete visibility, unclear ownership and fragmented renewal processes.

An organisation may know it has hundreds of certificates without knowing exactly where each certificate is deployed, who owns it, how it is renewed, which algorithm it uses, or how its private key is protected. That becomes a much bigger problem when certificate lifecycles accelerate.

Moreover, SC-081v3 directly governs public TLS certificates, but enterprises still rely on internal and private certificates for applications, APIs, devices, identities, and infrastructure.

"Organisations therefore face two connected challenges: managing certificates more frequently while preparing to replace the cryptography underneath them," posits Tee.

The benefits of automation

Manual certificate management typically depends on spreadsheets, calendar reminders, email chains and institutional memory. Such processes may appear inexpensive until an important certificate expires.

This can lead to inaccessible websites, failed API connections, disrupted applications, customer-facing outages and emergency remediation.

"Automation helps continuously discover certificates, maintain a central inventory, monitor expiries, initiate workflows, and preserve records for compliance," Tee said.

Automation, however, does not eliminate the need for governance. Organisations still need to enforce clear ownership, approval paths, exception handling and controls.

The five stages of certificate readiness

Tee said that a practical approach is to treat certificate management as a five-stage journey: Discover, Visualise, Operate, Secure and Govern.

Discover means identifying certificates across public and internal environments.

Visualise means creating a reliable inventory that includes location, issuing authority, expiration date, technical owner, renewal process, cryptographic algorithm, and private-key protection status.

Operate means establishing repeatable workflows for approval, issuance, deployment, validation, replacement and escalation.

Secure involves protecting private keys with appropriate controls. This includes hardware-backed security and ensuring key material stays within appropriate boundaries.

Govern means producing regular reporting on upcoming expirations, unowned certificates, policy exceptions, algorithm usage and remediation progress.

Related:  Notice to CISOs: Regulatory complexities, cybersecurity redefine boardroom strategies

According to Tee, the strategic test asks: Can the organisation identify the owner, location, renewal path, algorithm and key-protection status of every critical certificate without beginning a manual investigation?

If the answer is no, the organisation is not yet ready for the next stage of cryptographic change.

The post-quantum clock

The next phase of certificate management will be driven by two overlapping timelines. Dennis Tee

"The next phase of certificate management will be driven by two overlapping timelines," Tee noted.

As SC-081v3 reduces publicly trusted TLS certificate validity to 47 days by 2029, continuous discovery and lifecycle automation becomes necessary.

The second, Tee explained, is cryptographic.

"NIST's November 2024 initial draft of IR 8547 sets out a transition from quantum-vulnerable public-key algorithms. For digital signatures, RSA and ECDSA at approximately 112-bit security strength are proposed to be deprecated after 2030 and disallowed after 2035. Higher-strength RSA and ECDSA variants, together with EdDSA, are also proposed to be disallowed after 2035 because their mathematical foundations remain vulnerable to sufficiently capable quantum computing," Tee said.

This emphasises that organisations cannot treat certificate management and post-quantum migration as unrelated projects.

The strategic decision for business leaders

SC-081v3 makes automation necessary; cryptographic visibility is the foundation of post-quantum readiness. Dennis Tee

To prepare for the shifts, Tee encourages businesses to use SC-081v3 as the first stage of a broader crypto-agility programme.

"Discover certificates and algorithms, establish ownership, automate lifecycle operations, protect keys, and build the ability to replace cryptography repeatedly," he said.

For stronger certificate operations, TruVisor also recommends that organisations benchmark their current readiness, identify gaps in certificate visibility, governance and operations, and understand renewal risks.

The post-quantum era is not as distant as it seems and it is already being shaped by shorter certificate lifecycles and emerging cryptographic standards.

"SC-081v3 makes automation necessary; cryptographic visibility is the foundation of post-quantum readiness. Together, they establish certificate operations as a permanent enterprise capability," Tee concluded.

Related Stories

MORE STORIES