Blog

What is Certificate Lifecycle Management? A 2026 Guide

Certificate lifecycle management explained: the seven stages, why manual tracking fails, and what 47-day TLS certificates mean for your renewal volume.

Certificate lifecycle management (CLM) is the practice of managing digital certificates across their full lifespan — request, issuance, deployment, discovery, monitoring, renewal, revocation and retirement — at scale and, in most modern environments, through automation rather than manual tracking.

Every secure connection your organisation makes, from websites to APIs to internal applications, depends on a digital certificate. Those certificates authenticate identities, encrypt data and establish the trust that digital systems need to function. But they are not permanent. They expire, they get compromised, and they need replacing.

In a small environment that might be manageable with a spreadsheet. In an enterprise with tens of thousands of certificates issued across multiple PKI environments, cloud providers and business units, manual management is not just inefficient. It is a direct source of risk.

Key points

  • A certificate passes through seven distinct stages. Manual processes usually break down at discovery and renewal.
  • Most organisations cannot state how many certificates they hold. That gap is where outages come from.
  • Public TLS lifetimes are falling to 47 days by 2029, multiplying renewal volume roughly eightfold.
  • The rules apply to publicly trusted certificates only, but internal estates face the same operational pressure.

The certificate lifecycle: from issuance to retirement

A digital certificate passes through a series of defined stages. Understanding them matters because each one is a point where manual processes tend to fail.

1. Request and issuance

The lifecycle begins when a system, user or application generates a Certificate Signing Request (CSR) and submits it to a Certificate Authority. The CA validates the request and issues the certificate.

How that exchange happens depends on which certificate management protocols your environment supports — ACME, EST, CMP or SCEP. Each suits different use cases, from web servers to IoT devices to enterprise desktops.

2. Enrolment and deployment

Once issued, the certificate has to reach the right system: installed on a web server, pushed to endpoints via Group Policy, provisioned to a Kubernetes cluster, or distributed across a device fleet.

This is where automation most often falls short. A renewal is not complete when the certificate is issued. It is complete when the application is actually serving it, which usually requires a service restart or configuration reload.

3. Discovery and inventory

Organisations rarely have a complete picture of every certificate in their environment. They get issued by different teams, across different CAs, in different cloud environments, through different tools — and frequently by suppliers who embedded them in an appliance before delivery.

Discovery is the process of scanning infrastructure to find every certificate, including those created outside formal PKI processes. Building a cryptographic bill of materials provides the foundation for that visibility, and it is the prerequisite for everything else on this list.

4. Monitoring

Certificates have finite validity periods, and when they expire the services depending on them fail immediately. Effective monitoring tracks more than expiry dates — chain and trust store problems, weak algorithms and short key lengths all need surfacing before they reach production.

5. Renewal

Renewal replaces certificates before expiry, ideally through automated workflows requiring no manual intervention. As TLS lifetimes shorten, the window for catching an approaching expiry shrinks with them — and so does the time available to recover from a renewal that fails silently.

6. Revocation

Sometimes a certificate needs invalidating before its natural expiry, typically because a private key has been compromised or an employee has left. Revocation updates Certificate Revocation Lists or triggers OCSP responses so relying parties stop trusting the certificate.

Effective revocation depends entirely on knowing which certificates exist and where they are deployed. It is also worth testing: in segmented networks, revocation checking often behaves differently in production than it did in the lab.

7. Retirement

At end of life a certificate is removed from systems, its records archived for audit, and any residual dependencies cleared. Orphaned certificates — still deployed, no longer monitored — are a common and avoidable source of risk.

Why certificate lifecycle management matters

Outages

The consequences of poor certificate management are immediate and highly visible. Expired certificates disrupt services, break encrypted connections, trigger browser warnings and erode customer confidence. The Microsoft Teams global outage in 2020, caused by a single expired authentication certificate, remains the most widely cited example — but smaller versions of it happen constantly and never make the news.

The cost is not theoretical. ITIC's 2024 research found that more than 90% of mid-size and large enterprises put the cost of a single hour of downtime above $300,000, with 41% placing it between $1 million and over $5 million. Those figures exclude litigation and regulatory penalties. We have covered the real cost of expired certificates in more detail separately.

Security exposure

Unmanaged certificates create risk beyond availability. Weak algorithms, excessive validity periods and inadequate key protection all expand the attack surface. Certificates created outside governed PKI processes — sometimes called shadow certificates — sit unmonitored in production.

Without a complete inventory, an organisation also cannot assess its exposure to post-quantum cryptography requirements, because it does not know which algorithms and key lengths are in use.

Compliance and audit

Regulatory pressure is increasing. GDPR, PCI DSS, HIPAA and eIDAS either explicitly require or implicitly depend on effective certificate governance. Audit findings related to expired, unknown or non-compliant certificates are becoming more common, particularly in financial services and healthcare — and an organisation without an inventory cannot produce evidence without a manual scramble.

The impact of shorter certificate lifetimes

In April 2025 the CA/Browser Forum voted unanimously to reduce the maximum validity of public TLS certificates on a phased schedule:

  • March 2026 — maximum lifetime reduces to 200 days
  • March 2027 — maximum lifetime reduces to 100 days
  • March 2029 — maximum lifetime reduces to 47 days

By 2029, the same set of certificates that currently requires annual renewal will need renewing roughly eight times a year. For an organisation managing 10,000 public TLS certificates, that is a move from 10,000 renewal events annually to approximately 80,000.

Manual processes will not survive that transition. Organisations that have not implemented automated CLM before the deadlines take effect face a choice between continuous firefighting and systematic certificate-related outages. This is the single largest driver of CLM adoption in 2026, and we have written separately on what the reduction in TLS certificate lifetimes means in practice.

These rules apply to publicly trusted TLS certificates only. Internal PKI certificates are not subject to CA/Browser Forum rules, though many organisations are choosing to align internal practice with external standards for consistency and reduced operational risk.

The four pillars of CLM

Effective certificate lifecycle management rests on four capabilities, covered in full in our article on the four pillars of CLM.

  • Visibility provides a complete, current picture of every certificate in the environment. Without it you cannot monitor expiry, enforce policy or identify what you do not know about. This one comes first — the others operate on the inventory it produces.
  • Applicability ensures the platform matches your actual requirements: hybrid infrastructure, multiple CAs, and both legacy and cloud-native environments.
  • Availability maintains continuous certificate validity through proactive monitoring, automated renewal and rapid revocation and replacement.
  • Automation orchestrates issuance, renewal, deployment and revocation at scale, reducing human error and enforcing consistent policy.

Why manual certificate management fails

Manual management usually means tracking certificates in spreadsheets, relying on calendar reminders, and handling each issuance as a standalone task. It fails at scale for three reasons.

Spreadsheets go stale

The moment a certificate is issued outside the tracked process, the inventory is incomplete. Teams issue certificates independently, and without automated discovery those certificates remain invisible until they expire and take something down.

Manual renewals are error-prone

A single missed renewal can take down a production service. When renewal volumes increase eightfold, the probability of human error moves from likely to certain.

Policy enforcement is inconsistent

Without automation there is no mechanism ensuring every certificate meets organisational standards for key length, algorithm, validity period and permitted use. Standards drift, and the drift is only discovered during an audit or an incident.

Modern CLM platforms address this through automated discovery across hybrid environments, automated renewal and deployment workflows, centralised policy enforcement, integration with SIEM, secrets management and ITSM tooling, and real-time alerting and compliance reporting.

Resistance to automation is common and usually practical rather than technical — teams have been burned before by automation that broke something. Our guide to overcoming resistance to automation covers how to work through it.

Certificate management protocols

CLM platforms interact with Certificate Authorities through standardised protocols, each suited to different environments. Our protocol comparison guide covers these in detail.

  • ACME (Automatic Certificate Management Environment) is the protocol behind Let's Encrypt and now supported by most major CAs and CLM platforms. The default choice for automating public TLS issuance and renewal, and increasingly for private certificates too.
  • EST (Enrolment over Secure Transport) is designed for device and IoT enrolment, using TLS for transport security. Well suited to modern REST-based environments.
  • CMP (Certificate Management Protocol) is a mature, feature-rich protocol used in telecommunications, government and industrial PKI. Supports complex operations including key recovery and cross-certification.
  • SCEP (Simple Certificate Enrolment Protocol) is common in Microsoft and mobile device management environments. Straightforward to implement but lacking the security features of newer protocols.

Protocol support determines which parts of your estate a platform can actually manage. A platform supporting only ACME will not address SCEP-based device enrolment, and the gap usually surfaces after purchase rather than before.

How to choose a CLM platform

The platform will become foundational infrastructure for trust, compliance and operational continuity. Key considerations:

  • Multi-CA support. The platform should manage certificates from any CA rather than locking you to one vendor — public CAs, private enterprise CAs such as Microsoft AD CS or EJBCA, and cloud CA services.
  • Deployment flexibility. On-premises, SaaS or hybrid. Air-gapped support where defence and government requirements apply.
  • Discovery capability. Network scanning, agents, API integrations or a combination — and whether it reaches cloud providers, containers and legacy infrastructure.
  • Automation depth. Whether the full lifecycle is automated, including deployment and the service reload that follows, and whether it integrates with DevOps pipelines and CI/CD.
  • Integration ecosystem. Out-of-the-box connectors for SIEM, ITSM, PAM and HSM systems.
  • Post-quantum readiness. Support for PQC algorithms and cryptographic discovery to inform migration planning.
  • Licensing model. Per-certificate pricing behaves very differently at 47-day lifetimes than it does today. Stress-test any model against eight times your current renewal frequency before signing.

Our CLM vendor and licensing evaluation guide covers this in full, and inside an enterprise CLM deployment sets out the features that matter once you are live.

The CLM product landscape

The market has consolidated significantly. CyberArk's $1.54 billion acquisition of Venafi in 2024 reshaped the competitive landscape, while Keyfactor's acquisitions of InfoSec Global and CipherInsights in 2025 strengthened its cryptographic discovery and PQC capabilities.

  • Keyfactor Command — native EJBCA integration, leading post-quantum support, and on-premises, SaaS and air-gapped deployment. The strongest fit for most mid-size and large enterprises.
  • Venafi (CyberArk Certificate Manager) — the broadest integration ecosystem and the longest track record above one million certificates. Now being folded into CyberArk's identity security portfolio.
  • DigiCert Trust Lifecycle Manager — cloud-based and CA-agnostic, strongest where DigiCert is already the primary CA.
  • Sectigo Certificate Manager — cloud-native with strong ACME support and a dedicated SMB tier.
  • Entrust PKI Hub — a container-based virtual appliance bundling CA, CLM, enrolment and validation in one deployment.
  • Certdog by Krestfield — UK-developed CA and CLM platform, particularly strong in AD CS environments, with a free tier for smaller estates.

Other options include AppViewX CERT+, GlobalSign Atlas and LifeCycleX, Nexus Certificate Manager, HashiCorp Vault PKI for ephemeral certificates in DevOps environments, and AWS Private CA for cloud-native workloads.

Where CLM connects to everything else

CLM is rarely a standalone programme. It sits underneath two other initiatives most organisations are already running.

Zero Trust requires cryptographic proof of identity for every request. That proof comes from certificates, and it is only as reliable as the process managing them. Organisations frequently deploy Zero Trust tooling before their certificate estate can support it.

Crypto-agility and post-quantum migration depend on the same foundations: a complete inventory, and the ability to re-issue at scale without manual effort. Every capability the quantum transition will demand is a capability CLM builds first, which is why the two should be planned together rather than sequentially.

Unsung's certificate lifecycle management services

Unsung provides specialist certificate lifecycle management consultancy and technical delivery. We are vendor-neutral, working with whichever platforms and CAs suit your environment.

  • Assessment and advisory — reviewing your current certificate inventory, PKI architecture and management processes to identify visibility gaps, governance weaknesses and efficiency improvements.
  • Design and implementation — CLM solutions aligned to your security objectives and compliance requirements, supporting both internal PKI and cloud-based deployments.
  • Automation integration — automated provisioning, renewal, revocation and policy enforcement, removing manual error and ensuring consistent governance.
  • Monitoring and alerting — certificate status tracked across the estate, unknown certificates identified, and teams alerted before expiry affects services.
  • Crypto-agility and PQC readiness — building the capability to change algorithms systematically rather than in a crisis.

Our consultants hold SC and DV security clearance and deliver across central government, defence, financial services, healthcare and transport. A PKI health check is usually the right starting point — it establishes what is actually deployed before any platform decision is made.

Frequently Asked Questions

What is the difference between PKI and CLM?

PKI represents the foundational framework creating digital certificates and cryptographic keys, while CLM manages those certificates throughout their operational lifecycle from issuance through retirement. The distinction: PKI establishes trust mechanisms; CLM maintains that trust continuously.

Why can't I manage certificates manually?

Manual approaches function adequately for minimal estates. However, as certificate volumes increase and validity periods shrink, manual procedures introduce substantial risk. By 2029, organizations managing 1,000 public certificates will face approximately 8,000 annual renewal events—exceeding spreadsheet and calendar reminder capabilities.

What is certificate discovery?

Discovery involves systematically scanning infrastructure to locate all deployed certificates, including those created outside formal governance processes. This foundational step precedes management activities. Modern platforms employ network scanning, agents, API connections, and CA log examination.

What happens when a certificate expires?

Services relying on expired certificates fail immediately. Websites become inaccessible, APIs cease functioning, encrypted communications break, and users encounter security warnings. Consequences span minor inconveniences to significant operational disruption.

What is a Certificate Authority (CA)?

A CA represents the trusted entity issuing digital certificates. Public CAs issue certificates for publicly accessible services; private CAs issue credentials for internal systems, users, and devices. Most enterprises leverage both categories.

What protocols do CLM platforms use?

CLM platforms interact with CAs via ACME, EST, CMP, and SCEP. ACME serves automated TLS management; EST facilitates device enrollment; CMP handles sophisticated enterprise operations; SCEP supports Microsoft and MDM environments.

Do the 47-day certificate rules apply to internal certificates?

CA/Browser Forum regulations apply exclusively to publicly trusted TLS certificates. Internal certificates from organizational Certificate Authorities remain exempt, though many enterprises voluntarily align internal practices with external standards.

How does CLM support zero trust?

Zero trust architectures demand cryptographic identity verification for every access request. CLM maintains certificate validity, correct configuration, and timely replacement when compromised—essential capabilities enabling zero trust frameworks.

What is crypto agility and why does it matter for CLM?

Crypto agility enables organizations to transition between cryptographic algorithms efficiently with minimal disruption. As post-quantum cryptography standards finalize, CLM platforms supporting this capability enable systematic algorithm migration rather than crisis-driven replacement.

What is the difference between CLM and a Certificate Authority?

CAs issue certificates; CLM platforms manage certificates across their complete lifecycle independent of issuing authority. Most enterprises use multiple CA sources, requiring CLM systems providing unified management visibility.

How do I know if my organisation needs CLM?

Organizations requiring CLM exhibit certificate-related outages, incomplete certificate inventories, fragmented management across teams, reliance on manual renewal processes, preparation for shorter lifetimes, or regulatory compliance obligations around certificate governance.

How long does a CLM implementation take?

Timelines vary based on platform and environmental complexity. Basic discovery-and-monitoring deployments become operational within weeks; comprehensive enterprise implementations with automation and security tool integration typically require two to six months.

What is the difference between PKI and CLM?

PKI Public Key Infrastructure is the framework that creates and manages digital certificates and cryptographic keys. CLM is the operational discipline of managing those certificates through their entire lifecycle, from issuance to retirement. PKI creates the trust; CLM ensures that trust is maintained continuously.

Why can't I manage certificates manually?

Manual management works for very small estates. As certificate volumes grow and validity periods shorten, manual processes create unacceptable risk. With 47-day TLS certificates arriving by 2029, an estate of even 1,000 public certificates will require approximately 8,000 renewal events per year. Spreadsheets and calendar reminders cannot sustain this.

What is certificate discovery?

Certificate discovery is the process of scanning your infrastructure to identify every deployed certificate, including those created outside formal PKI processes. Discovery is typically the first step in any CLM implementation, because you cannot manage what you cannot see. Modern CLM platforms use network scanning, agents, API integrations, and CA log analysis to build a complete inventory.

What happens when a certificate expires?

Services relying on the expired certificate fail immediately. Websites become inaccessible, APIs stop responding, encrypted communications break, and users see security warnings. The impact can range from minor inconvenience to major business disruption.

What is a Certificate Authority (CA)?

A Certificate Authority is the trusted entity that issues digital certificates. Public CAs (such as DigiCert, Sectigo, or Let's Encrypt) issue certificates for publicly facing services. Private CAs (such as Microsoft AD CS or EJBCA) issue certificates for internal systems, users, and devices. Most enterprises use both.

What protocols do CLM platforms use?

CLM platforms interact with CAs through protocols including ACME, EST, CMP, and SCEP. Each serves different environments. ACME is the default for automated TLS certificate management, EST suits device enrolment, CMP handles complex enterprise operations, and SCEP supports Microsoft and MDM environments.

Do the 47-day certificate rules apply to internal certificates?

No. The CA/Browser Forum rules apply only to publicly trusted TLS certificates. Internal PKI certificates issued by your own Certificate Authorities are not subject to these requirements. However, many organisations are choosing to align internal practices with external standards to improve consistency and reduce operational risk.

How does CLM support zero trust?

Zero trust architectures require cryptographic proof of identity for every access request. CLM ensures that the certificates providing this proof are always valid, correctly configured, and promptly replaced when compromised. Without effective CLM, zero trust implementations cannot maintain the certificate hygiene they depend on.

What is crypto agility and why does it matter for CLM?

Crypto agility is the organisational capability to transition between cryptographic algorithms quickly and with minimal disruption. As post-quantum cryptography standards mature, organisations will need to replace the algorithms their certificates currently use. CLM platforms that support crypto agility allow this transition to happen systematically rather than as a crisis response.

What is the difference between CLM and a Certificate Authority?

A Certificate Authority issues certificates. A CLM platform manages certificates across their entire lifecycle, regardless of which CA issued them. Most enterprise environments use certificates from multiple CAs, and a CLM platform provides a single pane of glass across all of them.

How do I know if my organisation needs CLM?

If any of the following apply, your organisation needs CLM: you have experienced certificate-related outages; you do not have a complete inventory of all certificates in your environment; certificates are managed by multiple teams with no central oversight; you rely on manual processes for renewal; you are preparing for shorter TLS certificate lifetimes; or you need to comply with regulatory requirements around certificate governance. A PKI health check is typically the best starting point for understanding your current position.

How long does a CLM implementation take?

Implementation timelines vary depending on the platform and the complexity of your environment. A basic deployment covering discovery and monitoring can be operational within weeks. A full enterprise implementation with automation, policy enforcement, and integration with existing security tools typically takes two to six months. Professional services from the vendor or from a specialist like Unsung significantly accelerate this timeline.
Author
Unsung Ltd
September 9, 2026
-
5 min Read