TL;DR: Post-quantum cryptography will move from roadmap item to deployed control, AI-driven phishing will surge, and manual certificate management is becoming unsustainable as shorter lifespans and automation pressures increase, according to DigiCert’s 2025 predictions. The governing issue is no longer awareness but whether identity and trust programmes can operationalise crypto-agility, provenance, and lifecycle control fast enough.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “10 ways AI, quantum and trust will shape the year ahead”.
By the numbers:
- Nearly 25% of enterprises manage their thousands and sometimes tens of thousands of certificates manually.
- 23.53% of respondents in the 2024 World Quantum Readiness Day survey said certificates are managed via manual effort.
Key questions
A: Start by inventorying the certificate and PKI landscape, then identify the workflows that can be automated first.
Q: Why do shorter certificate lifecycles increase operational risk?
A: Shorter lifecycles increase risk because they compress the time available for human coordination, which exposes weak inventory, unclear ownership, and inconsistent deployment paths.
A: Start with the links that carry long-lived sensitive data and high-value administrative traffic, then use hybrid cryptography where classical and post-quantum methods can coexist.
Practitioner guidance
- Automate certificate lifecycle controls Replace spreadsheet-driven renewal with governed issuance, rotation, revocation, and inventory tracking across all certificate estates.
- Build a crypto-agility migration plan Document where cryptographic dependencies live, which systems will break under algorithm change, and how policy updates will be rolled out safely.
- Add provenance checks to trust workflows Use tamper-evident content provenance and verification signals where digital content or signed artefacts influence decision-making.
Bottom line: Certificate governance is becoming a first-order identity control because manual lifecycle handling does not scale with shorter certificate validity periods.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Certificate governance has become an identity-control problem, not a back-office maintenance task. The article’s strongest operational signal is that certificate lifecycles are shortening while manual management still persists in many enterprises. That combination turns renewal, revocation, and inventory accuracy into governance dependencies rather than administrative chores. Practitioners should treat certificate operations as part of the identity programme, not as a separate tooling concern.
A question worth separating out:
Q: How should security teams respond to AI-generated phishing campaigns?
A: Security teams should assume the message quality will be good enough to fool users and focus on reducing what a successful click can do. That means phishing-resistant MFA, stronger mailbox recovery checks, tight privilege scopes, and rapid session revocation. If the attacker cannot convert a click into useful identity access, the campaign loses much of its value.
👉 Read our full editorial: AI, quantum and trust predictions expose certificate governance gaps