They matter because DORA treats cryptography as an operational control, not a theoretical one. A current register of certificates and certificate-storing devices helps prevent expiry outages, while formal key lifecycle management reduces loss, misuse, and unsupported recovery. Together, they give assessors proof that critical services can survive failure without uncontrolled access.
Why This Matters for Security Teams
Under DORA, certificate registers and key lifecycle controls are not paperwork exercises. They are evidence that critical services can keep operating when cryptographic trust fails, whether through expiry, compromise, or poor recovery. A complete register shows what exists, where it lives, who owns it, and when it must be renewed. Key lifecycle controls show how keys are generated, protected, rotated, revoked, and destroyed. That combination matters because auditors look for operational resilience, not just encryption intent.
Teams often miss that cryptography failures become service failures fast. A missed certificate renewal can take down customer-facing systems, while unmanaged private keys can make recovery impossible or unsafe. This is why DORA and the EU Digital Operational Resilience Act (DORA) push organisations toward traceable control, not informal ownership. NHIMG research on The Critical Gaps in Machine Identity Management report found that certificate expiry is the leading cause of outages for 45% of organisations, which is exactly why registers and lifecycle controls become board-level evidence under resilience testing.
In practice, many security teams encounter certificate failures only after a renewal window is missed and a critical service has already gone dark, rather than through intentional lifecycle governance.
How It Works in Practice
A certificate register should act as the operational source of truth for every certificate-storing device, workload, service, and owner. It needs enough detail to support continuous monitoring, not just annual review: subject, issuer, purpose, environment, expiry date, renewal path, dependency, and emergency contact. For regulated environments, the register should also show which certificates support critical or important functions, because DORA assessors care about business impact, not just technical inventory.
Key lifecycle controls extend that register into active governance. The practical baseline is: generate keys in approved systems, protect private keys with strong access controls, rotate them on schedule or on event, revoke them promptly when compromise is suspected, and destroy retired material so it cannot be reused. Best practice is evolving toward automation wherever possible, because manual tracking does not scale across distributed estates. NHIMG’s NHI Lifecycle Management Guide and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs both reinforce that lifecycle ownership must be explicit, not assumed.
- Map each certificate and key to a named business service and technical owner.
- Track expiry, renewal method, and revocation path in a live register.
- Use automated renewal and rotation where systems support it.
- Verify backup, recovery, and replacement procedures before an incident.
- Retire unused keys and certificates to reduce exposure and audit noise.
This aligns with the operational direction of the OWASP Non-Human Identity Top 10, which treats machine identity lifecycle failures as a common source of compromise and outage. These controls tend to break down in highly decentralized environments where teams create certificates outside central tooling because ownership, inventory, and renewal responsibility become fragmented.
Common Variations and Edge Cases
Tighter certificate and key control often increases operational overhead, requiring organisations to balance resilience against deployment speed and local team autonomy. That tradeoff is real in containerized platforms, multi-cloud estates, and environments with many short-lived workloads, where static spreadsheets quickly become stale. Current guidance suggests that the answer is not more manual review, but better automation and clearer service ownership.
There is no universal standard for how much detail a register must contain, but for DORA purposes it should be complete enough to prove control during failure testing and audit review. Some organisations also separate certificates used for external trust from those used internally between services, because the risk and renewal cadence differ. The same is true for keys tied to signing, encryption, and authentication. A signing key breach, such as the risk illustrated by the Coupang Signing Key Breach, can create far broader trust damage than a routine TLS renewal issue.
For teams still early in maturity, Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a useful reminder that auditability is part of the control itself, not a separate reporting task. In complex legacy estates, these controls are hardest to sustain where certificates are issued ad hoc by application teams and private keys are embedded in unmanaged systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS-1 | Protecting data and cryptographic assets maps to key lifecycle and certificate governance. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Covers lifecycle management failures that create expired or stale machine identities. |
| CSA MAESTRO | Covers agent and workload identity lifecycle governance across distributed environments. | |
| NIST AI RMF | GOVERN | Resilience governance requires accountability for cryptographic controls supporting AI systems. |
Assign ownership and oversight for cryptographic lifecycle controls that underpin critical AI services.
Related resources from NHI Mgmt Group
- Why do identity and access management controls matter so much in regulated professional services environments?
- Why do identity and access controls matter so much for generative AI and AI tool integrations?
- Why do identity systems matter so much under DORA?
- Why do authentication logs matter so much under DORA?