TL;DR: Ballot SC-090 would phase out legacy certificate validation methods that depend on email, phone, fax, or IP crossover checks and push the ecosystem toward fully automated domain and IP validation, according to DigiCert. Manual validation is becoming operational debt, and certificate lifecycle management now has to be built around automation rather than human intervention.
At a glance
What this is: This is DigiCert’s analysis of CA/Browser Forum Ballot SC-090, which would retire legacy certificate validation methods and push domain and IP validation toward full automation.
Why it matters: It matters because certificate lifecycle management, machine identity governance, and domain validation workflows will need to move off human-mediated checks and into automated control paths.
By the numbers:
- The reuse period for domain and IP address validation will continue to shorten over the next several years, ultimately landing at 10 days in 2029.
- Method 3.2.2.4.8 will be prohibited on or after March 15, 2026.
- The phone, fax and postal methods in Phase 2 will not be allowed on or after March 15, 2027.
- The remaining email-based validation methods will be disallowed on or after March 15, 2028.
Context
Certificate validation is the process a CA uses to confirm control over a domain or IP address before issuing a certificate. In this article, DigiCert argues that the current mix of email, phone, fax and crossover methods is being replaced by validation paths that can run without human intervention.
For IAM and machine identity teams, the shift matters because certificate issuance is not just a compliance task, it is part of the identity lifecycle. If validation still depends on people picking up a phone, checking mail, or forwarding an email, the operational model no longer matches where the ecosystem is headed.
The article frames SC-090 as a multi-year transition rather than an immediate cutover, which gives organisations time to move validation into DNS- or HTTP-based workflows. That transition pressure is typical for teams that still rely on manual checks and atypical for environments that already treat certificate validation as an automated control.
Key questions
Q: What breaks when certificate validation still depends on manual contact methods?
A: Manual validation breaks at scale because it introduces human availability, routing delays and inconsistent control execution into a process that needs to be repeatable. Once certificate issuance depends on people answering phones or handling mail, lifecycle management becomes fragile and harder to automate across large domain estates.
Q: Why do shorter validation reuse periods change certificate governance?
A: Shorter reuse periods force teams to prove domain control more frequently, which reduces the value of one-time approvals and stale validation state. That makes certificate governance dependent on accurate ownership records, fast renewal workflows and automated validation channels rather than archived evidence.
Q: How should security teams transition from email validation to automated validation?
A: They should inventory every workflow that uses email, phone, fax or crossover checks, then move those paths to DNS- or HTTP-based validation that certificate systems can run automatically. The goal is to make proof of control machine-executable, not manually mediated.
Q: What is the difference between certificate issuance validation and certificate renewal automation?
A: Issuance validation proves control before a certificate is issued, while renewal automation ensures that proof can be refreshed repeatedly as the certificate lifecycle continues. Teams need both, because a one-time check does not solve the operational burden of repeated validation under shorter reuse windows.
Technical breakdown
Why manual validation no longer scales for certificate lifecycle management
Legacy validation methods such as email, phone, fax and postal contact introduce human timing, routing and availability into a process that increasingly needs to be deterministic. Certificate issuance depends on proving control over a domain or IP address, and manual methods add delay, variability and weak repeatability. SC-090 pushes the ecosystem toward validation methods that a lifecycle platform can invoke programmatically, which aligns issuance with modern automation patterns rather than office-bound approval loops.
Practical implication: Treat manual domain and IP validation as a legacy exception that should be removed from certificate operations planning.
How DNS-based and HTTP-based validation change the control model
DNS-based and HTTP-based validation shift proof of control into channels that can be checked on demand by software. That matters because the control becomes an operational workflow rather than a one-time human action. In practice, the certificate management system can revalidate when needed, reducing dependence on reused approvals and making validation more compatible with automated issuance, renewal and revocation workflows.
Practical implication: Design validation workflows so certificate management platforms can re-check domain control automatically without human escalation.
Why shorter validation reuse periods matter to machine identity governance
Validation reuse windows define how long a previous proof of control can be relied on before it must be refreshed. As those windows shrink toward 10 days, teams lose the option of treating validation as a long-lived credential. That forces closer alignment between domain control, certificate issuance and inventory accuracy, because stale validation assumptions can no longer support extended operational drift.
Practical implication: Inventory certificate owners and renewal dependencies before shorter reuse periods expose gaps in validation freshness.
NHI Mgmt Group analysis
SC-090 turns certificate validation into a lifecycle governance problem, not a point-in-time issuance step. The article shows that the industry is steadily removing validation paths that depend on people, paper and voice contact. That changes the governance question from whether a certificate was once approved to whether the validation process itself can be executed and repeated automatically.
Manual validation is becoming operational debt in machine identity programmes. Email, phone and fax methods were tolerable when issuance volumes were lower and review cycles were slower. As certificate operations scale across cloud, platform and service traffic, those methods create bottlenecks that do not map cleanly to automated certificate lifecycle management.
Shortening validation reuse periods exposes the gap between certificate governance and asset governance. If a domain owner cannot refresh proof of control quickly, the problem is not just certificate tooling, it is the underlying ownership and inventory model. The implication is that machine identity programmes need tighter coupling between DNS ownership, renewal state and operational accountability.
Automation is becoming the default assumption for certificate trust, and that assumption now reaches the identity layer. The key shift is not simply speed, but the expectation that trust checks can be executed continuously without manual intervention. Practitioners should read SC-090 as confirmation that certificate governance is converging with identity lifecycle governance across workloads, domains and services.
What this signals
Certificate validation is moving from approval evidence to executable control. That matters because IAM and machine identity teams can no longer treat validation as a clerical step sitting outside operations. The programme impact is a tighter loop between ownership, issuance and renewal, with less room for manually curated exceptions.
Validation reuse windows are now part of the governance design, not just a certificate policy detail. As reuse periods contract, stale domain ownership assumptions become visible faster. Practitioners should expect certificate lifecycle management to behave more like continuous identity control than periodic administrative review.
For practitioners
- Replace manual validation paths Map every certificate validation workflow that still depends on email, phone, fax or postal contact and queue it for retirement before the ballot dates take effect.
- Move validation into automated control paths Adopt DNS-based or HTTP-based validation where your certificate lifecycle platform can perform proof of control on demand without human intervention.
- Rework certificate ownership records Align domain ownership, certificate inventory and renewal responsibility so shorter validation reuse periods do not create hidden operational gaps.
- Test renewal workflows against shorter reuse windows Simulate certificate renewal under compressed validation reuse periods to find dependencies that still assume long-lived approval state.
Key takeaways
- SC-090 is a signal that certificate validation is being redefined as an automated control rather than a human-mediated approval process.
- The transition affects both validation methods and reuse timing, which means certificate operations must be rebuilt around faster, machine-executable proof of control.
- Teams that still rely on manual validation will need to align ownership records, renewal workflows and automation before the legacy methods are retired.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 — Long-Lived Secrets | Long-lived validation reuse is the core control change discussed in the article. |
| NHI-01 — Improper Offboarding | Deprecated validation methods linger when ownership and lifecycle transitions are not cleaned up. | |
| Recommendation — Reduce reliance on long-lived validation state and shorten certificate proof freshness wherever possible. Retire validation methods that outlive the ownership processes they depend on. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Certificate and validation lifecycle handling maps directly to authenticator management. |
| Recommendation — Apply IA-5 to govern validation renewal, rotation and revocation timing for certificate workflows. | ||
| CIS Controls v8 | CIS-5 — Account Management | Certificate ownership and validation responsibility depend on account and identity lifecycle control. |
| Recommendation — Use account management discipline to keep certificate ownership and renewal responsibility current. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Validation proves authorised control over a domain or IP address, which is an access assurance problem. |
| Recommendation — Align certificate validation with entitlement and authorisation governance so proof of control stays current. | ||
Key terms
- Certificate validation: Certificate validation is the process of checking that a TLS certificate chains to a trusted authority and matches the intended hostname. In practice, it is a core trust decision, because accepting invalid or mismatched certificates lets an attacker impersonate a legitimate endpoint and intercept secure traffic.
- Validation reuse period: A validation reuse period is the window during which a previous proof of domain or IP control can be reused for new issuance or renewal. Shorter reuse periods reduce reliance on stale evidence and force tighter alignment between ownership records, automation and certificate lifecycle governance.
- Machine identity lifecycle: Machine identity lifecycle is the full governance process for a non-human identity from creation to retirement. It includes provisioning, access scoping, rotation, renewal, offboarding, and auditability, and it fails when any one of those steps is handled manually or inconsistently.
- Automated Validation: A validation method that can be executed by systems using machine-readable proof paths such as DNS or HTTP rather than email or phone contact. It reduces operational delay and makes certificate approval more repeatable, but it also raises the importance of integration integrity and record ownership.
Deepen your knowledge
NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org