By NHI Mgmt Group Editorial TeamBased on Keyfactor: “6 Brutal Truths Every Leader Must Face About Enterprise Cryptography” (January 22, 2026)

TL;DR: Enterprise cryptography is moving from quiet infrastructure to a governed trust system as certificate lifecycles, legacy cryptography, cloud sprawl, and quantum-safe planning converge, according to Keyfactor. Manual discovery, fragmented PKI, and weak lifecycle control are now operational risks, not background hygiene.


At a glance

What this is: This is a governance analysis of why enterprise cryptography is becoming harder to manage as certificate sprawl, legacy crypto, regulation, and quantum-safe transition planning collide.

Why it matters: It matters because IAM, PKI, and security teams now need to treat cryptographic assets as governed identities and controls, not static infrastructure that can be left on autopilot.


Context

Enterprise cryptography now behaves like a living governance domain rather than fixed infrastructure. As keys, certificates, algorithms, cloud systems, and software dependencies multiply, the question is no longer whether cryptography works, but whether organisations can still see, own, and renew it at scale.

For identity teams, the overlap with NHI governance is direct: certificates, keys, signing services, and workload authentication all sit inside the machine identity estate. The central issue is not just crypto strength, but lifecycle control, inventory accuracy, and the ability to prove who or what is trusted across hybrid environments.


Key questions

Q: What breaks when enterprise cryptography is managed manually?

A: Manual cryptography management breaks at the point where volume, dependency chains, and renewal cadence exceed what people can track reliably. The result is missed renewals, delayed rotations, inconsistent policy enforcement, and outages that appear operational but are really governance failures.

Q: Why do fragmented PKI environments create more risk over time?

A: Fragmented PKI creates hidden trust islands. Different certificate authorities, outdated libraries, and undocumented dependencies make it hard to see where legacy algorithms still live, so deprecation, audit, and migration work can fail in places no one planned for.

Q: How can teams reduce risk while adopting quantum-safe cryptography?

A: Use phased migration, test hybrid certificates in controlled environments, and validate entropy sources before scaling. The aim is to limit disruption while proving that policy, tooling, and operational processes can handle cryptographic change safely.

Q: Who should own cryptographic governance when trust spans identity and infrastructure?

A: Ownership should sit with the teams responsible for identity trust architecture, not only with platform or application owners. Cryptographic governance affects authentication, federation, workload access, and compliance, so it needs coordinated accountability across IAM, security engineering, and platform operations.


Technical breakdown

Why certificate lifecycle governance becomes the control plane

Certificates and keys are not passive assets. They authenticate workloads, containers, APIs, microservices, and IoT devices, so every issuance, renewal, rotation, and revocation event changes the trust surface. Once those assets are spread across hybrid environments, a manual request chain or spreadsheet cannot reliably preserve ownership, expiry awareness, or policy consistency. The technical problem is not only volume, but distributed dependency: one expired certificate can break an application path that no single team sees end to end.

Practical implication: treat certificate lifecycle state as an operational control plane, not a background admin task.

How fragmented PKI and legacy cryptography create hidden failure modes

Fragmented PKI means multiple trust anchors, outdated libraries, undocumented dependencies, and legacy algorithms can persist in parallel. Residual SHA-1, DES, outdated RSA, hard-coded keys, and custom certificate authorities create blind spots that surface only during audits, upgrades, or outages. In technical terms, the environment becomes difficult to model because the trust graph is incomplete. If you cannot inventory the cryptographic dependencies, you cannot predict where deprecation or compromise will cascade.

Practical implication: build a cryptographic bill of materials before deprecating algorithms or refactoring trust paths.

Why crypto-agility is now a runtime requirement

Quantum risk changes the timeline for cryptographic change management. The article frames a real-world transition problem: organisations must prepare for dual-stack cryptography, algorithm agility, and staged migration before standards and systems fully converge. That means cryptography has to be designed for replacement, not permanence. The technical challenge is less about selecting one future algorithm and more about ensuring systems can swap algorithms, trust chains, and signing workflows without breaking application delivery.

Practical implication: design crypto controls so algorithms and trust mechanisms can be replaced without rebuilding the service.


Threat narrative

Attacker objective: The objective is to exploit cryptographic blindness, whether that leads to service disruption, compromised signing trust, or future decryption exposure.

  1. Entry begins when an organisation lacks a complete inventory of certificates, keys, and cryptographic dependencies, so hidden trust assets remain outside governance.
  2. Escalation occurs when expired certificates, legacy algorithms, or hard-coded keys persist long enough to create operational failure, compliance exposure, or supply chain weakness.
  3. Impact follows when unknown cryptographic dependencies trigger outages, audit failures, or post-quantum migration delays that widen the enterprise risk window.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
  • SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Cryptography has become an identity governance problem, not just a security engineering concern. When certificates and keys authenticate workloads, APIs, and services, their lifecycle determines who or what can be trusted. That means ownership, renewal, revocation, and inventory discipline now sit alongside traditional IAM and PAM governance. Practitioners should treat cryptographic control as part of the identity estate, not as an isolated infrastructure task.

Cryptographic bill of materials is the new minimum viable visibility layer. A CBOM is not just a reporting artifact. It is the operating map that shows where trust primitives live, what they depend on, and where legacy algorithms or hard-coded keys could break change programmes. Without that map, deprecation and quantum-safe migration become guesswork. Teams should assume that anything not inventoried will eventually become the place risk hides.

Manual certificate operations are now a governance failure mode. Spreadsheets, scripts, and email approvals do not scale to the volume and renewal cadence described in the article. They create delayed rotations, missed renewals, and inconsistent policy enforcement, which means the organisation is effectively betting availability on human memory. The practical conclusion is that renewal, rotation, and revocation must be policy-driven if the trust system is to remain stable.

Quantum-safe planning exposes an assumption collapse: cryptographic trust was designed for static algorithm lifetimes. That assumption fails when adversaries can harvest encrypted data now and decrypt it later, because trust windows must be governed across a multi-year migration rather than a single algorithm era. The implication is that modern cryptography programmes must be built around replaceability, not permanence.

Centralised cryptographic governance will increasingly define operational resilience. The article shows that outages, audits, and supply chain integrity are no longer separate issues when signing keys, certificates, and algorithm choices are all part of the same control surface. That pushes cryptography into the same governance conversation as machine identity, lifecycle enforcement, and resilience planning. Practitioners should align crypto operations with enterprise identity governance rather than treating them as a back-office utility.

From our research library:

What this signals

Cryptographic governance now behaves like machine identity governance with a longer tail. The same discipline that applies to workload identities also applies to certificates, keys, and signing services: inventory first, ownership second, lifecycle enforcement always. Organisations that separate crypto operations from identity governance will keep discovering risk only after expiry, audit, or outage events.

Quantum readiness changes the meaning of acceptable delay. “Harvest now, decrypt later” means the window for action starts before standards are finalised, not after. Teams need to assume that long-lived encrypted data and long-lived trust chains are already part of the exposure model.


For practitioners

  • Define a cryptographic inventory baseline Map certificates, keys, algorithms, trust anchors, and dependent systems across hybrid environments before any modernisation or deprecation work begins.
  • Replace manual renewal paths Move issuance, renewal, rotation, and revocation into policy-driven workflows so expiry, human error, and inconsistent approvals do not drive outages.
  • Build a cryptographic bill of materials Track legacy libraries, undocumented dependencies, and hard-coded cryptographic assets so algorithm changes can be planned against the real environment.
  • Sequence quantum-safe migration by business criticality Prioritise high-value and long-lived data paths first, then phase dual-stack readiness and algorithm agility into DevOps and cloud delivery.
  • Create governance ownership for machine trust Assign clear owners for certificates, signing services, and workload authentication so cryptographic control is treated as an accountable lifecycle domain.

Key takeaways

  • Enterprise cryptography is no longer background plumbing. It is a governed trust layer whose failures now affect availability, auditability, and future resilience.
  • The article links manual operations, fragmented PKI, and quantum transition pressure to the same control problem. Visibility and lifecycle discipline are the differentiators.
  • Enterprises should manage certificates, keys, and signing trust as part of identity governance, with inventory and policy-driven automation ahead of algorithm change.

Key terms

  • Cryptographic Bill of Materials: A cryptographic bill of materials lists the cryptographic capabilities built into software components, such as supported algorithms and libraries. It is useful for component visibility, but it does not show live configuration, deployment context or actual runtime usage. That makes it a partial input, not the full governance record.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Credential Lifecycle Governance: Credential lifecycle governance is the set of controls that manage creation, assignment, monitoring, rotation, and retirement of credentials. For machine identities, it prevents secrets from becoming permanent access artifacts and ensures every identity has a defined owner, purpose, and end state.
  • Quantum-Safe Transition: The quantum-safe transition is the planning and migration work required to move cryptographic systems toward algorithms and controls that can withstand future quantum computing threats. It involves identifying exposed assets, prioritising dependencies, and replacing vulnerable cryptography in a controlled sequence before risk becomes unmanageable.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org