TL;DR: The CA/Browser Forum’s phased move to 47-day TLS certificates turns machine identity management from a renewal task into an operational resilience problem, according to Thryam. Manual tracking, partial automation, and incomplete visibility cannot sustain the new cadence, which makes discovery, inventory, and end-to-end automation the real control plane.
At a glance
What this is: This is an analysis of how shortened TLS certificate lifetimes expose deeper machine identity governance gaps, especially around discovery, inventory, and renewal automation.
Why it matters: It matters because IAM, PAM, and infrastructure teams will need to manage machine identities as a continuous lifecycle problem, not a periodic certificate task.
By the numbers:
- By 2029, TLS certificates will last just 47 days under the CA/Browser Forum’s phased timeline.
- 1, team managing 1,000 certificates would need renewal work to scale from 2 people today to 16 by 2029.
- An annual renewal becomes roughly 8 renewals per year by 2029 for each certificate.
👉 Read Thryam’s analysis of the 47-day TLS certificate transition and machine identity risk
Context
Machine identity management is the discipline of discovering, governing, and rotating the credentials that systems use to authenticate and communicate. In this article, the primary pressure point is TLS certificate validity, but the governance problem is broader than certificates alone.
The primary failure mode is operational, not cryptographic. As certificate lifetimes shrink, manual inventories, partial automation, and undocumented exceptions stop being manageable and become outage risk. That is the core machine identity governance issue for IAM and infrastructure teams.
The article’s starting position is typical of many enterprises: there is some automation, some spreadsheet tracking, and some unknown inventory. That mix works only while renewal cycles are long enough to absorb human delay.
Key questions
Q: What breaks when machine identity lifecycle management is still partly manual?
A: Manual lifecycle management breaks first at scale. Expiry handling becomes inconsistent, revocation is slow, and ownership is unclear when credentials are embedded across many applications and environments. In practice, that means outages, unrevoked access and weak auditability when trust assumptions change.
Q: Why do shorter certificate lifetimes matter for workload identity governance?
A: Shorter lifetimes matter because they force teams to manage trust as a continuous identity lifecycle rather than a periodic admin task. That shifts attention from isolated certificate replacement to ownership, rotation, and inventory accuracy across workloads. The control problem is broader than expiration dates, because unmanaged certificates still create a visible attack and outage surface.
Q: How do you know if machine identity automation is actually working?
A: Automation is working when it reduces manual intervention, shortens renewal and revocation latency, and produces continuous evidence of control. If outages, exception handling, or audit gaps still depend on human scramble, the automation is only accelerating the old process.
Q: Who is accountable when an expired certificate causes a service outage?
A: Accountability sits with the team that owns certificate lifecycle governance, not only with infrastructure operations. The failure usually reflects missing ownership, weak inventory, and lack of automated renewal controls, which makes the issue a programme problem as much as a technical one.
Technical breakdown
Why 47-day TLS certificates break partial automation
A certificate lifecycle only works when discovery, issuance, renewal, deployment, and revocation are all connected. Partial automation handles known certificates, but it does not solve shadow certificates, ownership gaps, or dependency chains across load balancers, endpoints, and internal services. When validity drops from a year to 47 days, the buffer for manual intervention disappears. Teams that depend on ticket queues, calendar reminders, or ad hoc scripts will miss renewals more often because the operational cycle becomes too short for human handoffs to be reliable.
Practical implication: replace renewal-by-exception with a continuously discovered certificate lifecycle.
Machine identity inventory is the control that everything else depends on
Certificates, SSH keys, and cryptographic assets are all machine identities because they prove a non-human workload’s right to communicate or access a system. The article’s central point is that no renewal strategy can cover assets that are unknown, orphaned, or spread across multiple teams. Inventory is not a reporting exercise. It is the prerequisite for lifecycle control, because you cannot rotate, revoke, or audit what you cannot enumerate. In practice, the inventory problem gets worse in hybrid estates where ownership is distributed and systems outlive their original administrators.
Practical implication: establish authoritative machine identity discovery before setting stricter renewal policy.
Why certificate expiry becomes an outage problem, not just a compliance issue
Shorter validity periods change the cost of missed renewal. A single expired certificate used to be an isolated incident. Under a 47-day cycle, missing one renewal means repeated failure modes that can ripple across customer-facing apps, internal services, and partner integrations. The risk is magnified when certificates are reused across many endpoints or when legacy systems lack modern automation hooks. The article correctly treats expiry as an operational resilience issue because outage frequency becomes tied to how well the organisation can sustain machine identity operations at scale.
Practical implication: tie certificate monitoring to service availability controls, not just security audits.
Threat narrative
Attacker objective: The objective is to exploit stale machine credentials to preserve access or force operational failure across critical systems.
- Entry occurs through unmanaged machine identities such as forgotten certificates, orphaned SSH keys, or assets tracked only in spreadsheets.
- Escalation happens when those credentials remain valid after ownership changes, allowing unintended use across services and environments.
- Impact follows as expired or unrevoked machine identities trigger outages, audit findings, or persistent exposure across the infrastructure.
Breaches seen in the wild
- MongoBleed breach — MongoBleed exposed secrets across 87K MongoDB servers.
- IOS app secrets leakage report — iOS apps leaking hardcoded secrets and credentials endangering user privacy.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
47-day certificate validity is really a machine identity governance deadline: The reduction in TLS lifespan is not the central story. The real issue is that machine identity governance now has to operate at a cadence that exposes every ownership gap, every undocumented dependency, and every missed renewal path. That makes discovery and lifecycle control the decisive controls, not the certificate format itself.
Partial automation is a false comfort in machine identity management: A mixed state of ACME coverage, spreadsheet tracking, and hidden assets creates the illusion of control while leaving material gaps untouched. Once renewal cycles shrink into weeks rather than months, mixed-mode operations stop being a bridge and become an outage generator. Practitioners should treat any unresolved manual dependency as a governance defect, not a temporary exception.
Inventory is the named concept that now defines resilience: complete machine identity inventory is the foundation for every other control in this domain. Without it, compliance answers are speculative, post-quantum readiness is untestable, and renewal automation only covers the visible subset. The implication for practitioners is straightforward: lifecycle policy must begin with authoritative discovery, or the rest of the programme rests on guesswork.
Machine identity risk is converging with infrastructure resilience: certificate management, SSH key governance, and cryptographic discovery are not separate workstreams. They are different expressions of the same control problem, which is whether the organisation can see, classify, and act on non-human credentials before they become operational failures. Security teams should therefore align identity governance with service reliability, because the failure surface is shared.
The 47-day timeline exposes organisational accountability gaps as much as technical ones: teams that cannot name an owner for each machine identity cannot credibly claim they can rotate or revoke it on schedule. The article shows that the weakest point is often not the control itself but the absence of durable accountability across infrastructure, application, and platform teams. Practitioners should treat ownership as a hard requirement, not an administrative courtesy.
From our research:
- Only 38% have automated certificate lifecycle management in place, according to The Critical Gaps in Machine Identity Management report.
- Manual handling remains the norm for machine identity operations, which is why renewal pressure turns into outage risk instead of routine maintenance.
- For a broader lifecycle lens, review Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs to connect discovery, rotation, and offboarding.
What this signals
The 47-day timeline makes machine identity lifecycle management a board-level reliability issue, not an isolated infrastructure task. Teams that still depend on calendars, tickets, and tribal knowledge will find that renewal windows compress faster than their governance processes can adapt.
Inventory debt: hidden certificates and orphaned SSH keys will become the dominant failure mode in many environments. Once visibility is incomplete, shortening validity periods simply increases the frequency at which the same weaknesses surface.
For identity programmes, this is the moment to align machine identity governance with Zero Trust and continuous control thinking. The more the estate depends on short-lived credentials, the more the programme needs authoritative discovery and policy-driven lifecycle execution, as reflected in the Ultimate Guide to NHIs and NIST Cybersecurity Framework 2.0.
For practitioners
- Build a complete machine identity inventory Enumerate certificates, SSH keys, and other cryptographic assets across on-prem, cloud, containers, and edge systems, then assign durable ownership for each asset.
- Automate end-to-end certificate lifecycle operations Connect discovery, renewal, deployment, and revocation so that known certificates are handled without manual handoffs or spreadsheet tracking.
- Separate known assets from unknown exceptions Track orphaned certificates, wildcard reuse, and undocumented deployments as explicit remediation items with service owners and deadlines.
- Align machine identity governance with service resilience Add certificate expiry and key revocation failures to operational readiness reviews so identity issues are handled before they become outages.
Key takeaways
- The 47-day certificate timetable is a machine identity governance problem, not just a TLS policy change.
- Manual tracking and partial automation will not scale when renewal cycles shrink from months to weeks.
- Authoritative discovery and end-to-end lifecycle automation are now the controls that determine whether machine identity risk becomes an outage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Lifecycle gaps and missing renewal automation are central to the article's machine identity risk. |
| NIST CSF 2.0 | PR.AC-1 | The article centres on identity and credential governance across infrastructure assets. |
| NIST SP 800-53 Rev 5 | IA-5 | Certificate and key lifecycle management aligns directly to authenticator management. |
| NIST Zero Trust (SP 800-207) | 3.4 | The article links machine identity governance to continuous verification and trust reduction. |
Map machine identity renewal and revocation coverage to NHI-03 and close manual exceptions first.
Key terms
- Machine Identity: The digital identity of a machine, device, or workload — such as a server, container, or VM — used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Certificate Lifecycle Management: The governance of digital certificates from issuance through renewal and revocation, ensuring certificates are valid, monitored, and rotated before expiry. Expired certificates are a leading cause of outages and unplanned security gaps.
- Cryptographic Inventory: A cryptographic inventory is a continuously updated record of keys, certificates, algorithms, libraries and trust anchors across an organisation. It is not a spreadsheet or one-time audit output. In practice, it links each asset to ownership, usage, lifecycle state and risk so teams can make remediation decisions.
- Key Sprawl: The condition where keys are scattered across clouds, pipelines, applications, and local systems without central visibility. Sprawl makes it harder to know which keys are active, who owns them, and whether they are safe to keep in circulation.
What's in the full article
Thryam's full article covers the operational detail this post intentionally leaves for the source:
- The phased CA/Browser Forum timeline for March 2026, March 2027, and March 2029 certificate validity changes.
- The staffing math behind renewals at scale, including the 1,000-certificate example and manual effort growth.
- The distinction between TLS certificate risk, SSH key sprawl, and broader cryptographic discovery gaps.
- The article's practical guidance on end-to-end automation across discovery, monitoring, procurement, and deployment.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or governance maturity, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org