By NHI Mgmt Group Editorial TeamBased on DigiCert: “DigiCert Selected by Jisc to Advance Digital Trust Across UK Education and Research” (November 25, 2025)

TL;DR: UK education and research institutions now have streamlined access to PKI, TLS and certificate lifecycle management without separate procurement through a national framework selected by Jisc, according to DigiCert, but the practical issue is not the contract itself but whether shared procurement actually improves certificate governance, lifecycle control, and trust boundaries across large, federated environments.


At a glance

What this is: DigiCert and Jisc are using a national procurement framework to simplify access to PKI, TLS and certificate lifecycle management for UK education and research institutions.

Why it matters: For IAM and NHI teams, the key issue is whether shared procurement also translates into better certificate ownership, lifecycle discipline and trust boundary control in federated environments.


Context

This is a procurement and governance story about how UK education and research organisations buy and manage digital trust capabilities, not just how they deploy them. The core issue is certificate lifecycle control across large, federated environments where different institutions may share frameworks but still own separate risk.

PKI, TLS and certificate lifecycle management sit at the boundary between identity, infrastructure and trust. When procurement is centralised through a sector framework, the governance question becomes whether standardised access to tooling also standardises accountability for issuance, rotation, revocation and auditability.


Key questions

Q: How should institutions govern certificate lifecycle management in shared procurement models?

A: They should separate buying access from control ownership. A shared procurement framework can simplify acquisition, but each institution still needs explicit ownership for issuance, renewal, revocation and audit evidence. Without that separation, certificates can remain trusted long after the system, service or relationship they support has changed.

Q: Why can shared PKI procurement still leave governance gaps?

A: Because procurement reduces friction in buying access, but it does not resolve who approves trust, who rotates credentials, or who removes obsolete certificates when services change. If those operational decisions stay fragmented, the organisation may have easier access to tooling but weaker lifecycle control.

Q: What are the signs that certificate lifecycle processes are not working properly?

A: Common warning signs include delayed renewals, unnoticed expirations, inconsistent revocation, slow onboarding for new users or devices, and poor visibility into certificate status. If teams rely on spreadsheets or disconnected processes, they often discover problems only after downtime or access failures occur. Those symptoms usually indicate the lifecycle process is too manual to scale safely.

Q: What is the difference between shared procurement and shared trust governance?

A: Shared procurement is the commercial mechanism for buying a service through a common framework. Shared trust governance is the operational discipline for deciding who owns certificates, how they are issued, when they are revoked and how accountability is proven. The first reduces process overhead; the second reduces identity risk.


Technical breakdown

PKI and certificate lifecycle management in federated institutions

Public key infrastructure underpins authentication, encryption and trust verification for systems that need to prove identity or secure traffic. Certificate lifecycle management covers issuance, renewal, rotation and revocation, which are operationally critical when many teams own apps, services and endpoints but rely on a shared trust model. In federated education environments, the technical challenge is not simply buying certificates. It is maintaining consistent lifecycle policy across loosely coupled institutions, each with different renewal cadences, internal ownership models and exposure to expired or misissued certificates.

Practical implication: Map certificate issuance, renewal and revocation ownership before adopting shared procurement so lifecycle responsibility is explicit.

Shared procurement does not remove trust-boundary risk

A procurement framework can simplify commercial access, but it does not collapse the underlying trust boundaries between institutions, certificates, services and administrative domains. Shared access to PKI or TLS capabilities still requires separate control over identity proofing, approval, key protection, revocation triggers and asset inventory. Without that, a common buying path can create the illusion of governance while operational control remains fragmented. In practice, procurement efficiency and trust governance are related but not interchangeable concerns.

Practical implication: Treat framework access as a commercial enabler, then validate that each institution still owns its own trust boundaries and control evidence.

Certificate lifecycle control is an identity governance problem

Certificates are non-human credentials, so their governance belongs in the same lifecycle discipline used for accounts, tokens and other machine identities. That means ownership, expiry management, revocation, and service dependency mapping matter as much as the cryptographic strength of the certificate itself. In federated sectors, stale certificates can outlive the teams or systems that requested them, which turns old trust relationships into operational blind spots. Shared procurement can reduce friction, but only lifecycle governance prevents trust sprawl.

Practical implication: Bring certificates into the same governance model as other NHI assets, with inventory, owners and revocation paths tied to service change.


NHI Mgmt Group analysis

Shared procurement improves access, but not governance by default: A national framework can remove purchasing friction, yet it does not automatically solve who owns issuance, renewal, revocation or evidence of control. That distinction matters because procurement and governance are often conflated in identity programmes. The practitioner lesson is to separate commercial simplification from operational accountability.

Certificates are NHI assets, not just technical artefacts: In large education and research environments, certificates behave like machine credentials with owners, dependencies and expiry risk. Treating them as one-off infrastructure items leaves gaps in inventory, rotation and offboarding. The implication is that certificate governance belongs in the same lifecycle discipline as other non-human identities.

Federated trust requires local control points: Shared frameworks work only when each institution retains clear authority over its own service inventory, trust anchors and revocation decisions. Centralised buying can standardise supply, but trust still fails locally if ownership is vague. Practitioners should assume that every certificate has a local accountability boundary, even when procurement is shared.

Digital trust procurement is moving closer to identity governance: The market signal here is not just that education buyers want easier purchasing. It is that certificate management, trust services and identity governance are converging into one operational conversation. Certificate governance debt: when procurement is simplified faster than lifecycle discipline, organisations accumulate trust relationships they cannot reliably evidence or retire. The practical conclusion is to evaluate digital trust services as governance infrastructure, not just tooling.

What this signals

Certificate governance debt: when procurement is simplified faster than lifecycle discipline, organisations accumulate trust relationships they cannot reliably evidence or retire. That is the real risk in shared digital trust buying, because certificate controls still fail at the point of ownership, revocation and dependency tracking.

Shared frameworks can standardise supplier access, but they do not standardise the trust boundary inside each institution. For education and research teams, the programme question is whether certificate management now sits inside identity governance rather than as an infrastructure afterthought.


For practitioners

  • Define certificate ownership before adopting the framework Assign a named owner for issuance, renewal, revocation and audit evidence for every certificate class used by each institution.
  • Inventory certificates and dependent services Build and maintain a current inventory of certificates, the applications that depend on them and the teams responsible for them.
  • Align renewal and revocation processes to service change Tie certificate renewal, replacement and revocation to system change workflows so stale credentials do not outlive the service they protect.
  • Separate procurement approval from trust approval Treat buying access, technical validation and trust acceptance as distinct control points instead of one combined sign-off.

Key takeaways

  • Shared procurement can lower the friction of buying PKI and certificate services, but it does not automatically improve governance.
  • The underlying control problem is lifecycle discipline for non-human credentials, especially ownership, renewal and revocation.
  • Institutions should assess whether their certificate programmes have explicit accountability before assuming a common framework has solved the hard part.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsCertificates can become long-lived credentials when renewal and revocation are weak.
NHI-01 — Improper OffboardingStale certificates can survive service or team changes when offboarding is unclear.
Recommendation — Treat certificates as governed credentials and enforce rotation and revocation before expiry drift creates exposure. Revoke certificates when services, owners or institutional responsibilities change.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCertificate lifecycle management maps to authenticator handling and renewal discipline.
Recommendation — Apply IA-5 to manage issuance, renewal, revocation and replacement of certificate authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsShared trust still depends on explicit authorization and ownership of access paths.
Recommendation — Document certificate authorizations and verify that each trust path has a named owner.
MITRE ATT&CKTA0006 — Credential AccessCompromised or stale certificates function as credential material attackers seek to abuse.
Recommendation — Hunt for exposed or stale certificate material under TA0006 and prioritise revocation where needed.

Key terms

  • Public Key Infrastructure: Public Key Infrastructure is the trust system that issues, manages, and revokes digital certificates used to prove identity. In practice it binds keys to entities and policies, making authentication, encryption, and non-repudiation possible across users, devices, and services.
  • Certificate Lifecycle Management: The governance of digital certificates from issuance through renewal and revocation, ensuring certificates are valid, monitored, and rotated before expiry. Expired certificates are a leading cause of outages and unplanned security gaps.
  • Trust Boundary: A trust boundary is the point where one system’s authority should stop and another system’s authority should begin. For internal automation, weak trust boundaries let monitoring, remediation, and execution share privileges that should have remained separate.
  • Non-Human Credential: A non-human credential is a secret used by software, automation, or an AI agent to authenticate or act on a system’s behalf. Examples include API keys, tokens, certificates, and service account secrets. These credentials need lifecycle governance because they often persist beyond the human task that created them.

Deepen your knowledge

Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org