TL;DR: UK education and research institutions now have streamlined access to PKI, TLS and certificate lifecycle management without separate procurement through a national framework selected by Jisc, according to DigiCert, but the practical issue is not the contract itself but whether shared procurement actually improves certificate governance, lifecycle control, and trust boundaries across large, federated environments.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “DigiCert Selected by Jisc to Advance Digital Trust Across UK Education and Research”.
Key questions
Q: How should institutions govern certificate lifecycle management in shared procurement models?
A: They should separate buying access from control ownership.
Q: Why can shared PKI procurement still leave governance gaps?
A: Because procurement reduces friction in buying access, but it does not resolve who approves trust, who rotates credentials, or who removes obsolete certificates when services change.
Q: What are the signs that certificate lifecycle processes are not working properly?
A: Common warning signs include delayed renewals, unnoticed expirations, inconsistent revocation, slow onboarding for new users or devices, and poor visibility into certificate status.
Practitioner guidance
- Define certificate ownership before adopting the framework Assign a named owner for issuance, renewal, revocation and audit evidence for every certificate class used by each institution.
- Inventory certificates and dependent services Build and maintain a current inventory of certificates, the applications that depend on them and the teams responsible for them.
- Align renewal and revocation processes to service change Tie certificate renewal, replacement and revocation to system change workflows so stale credentials do not outlive the service they protect.
Bottom line: Shared procurement can lower the friction of buying PKI and certificate services, but it does not automatically improve governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shared procurement improves access, but not governance by default: A national framework can remove purchasing friction, yet it does not automatically solve who owns issuance, renewal, revocation or evidence of control. That distinction matters because procurement and governance are often conflated in identity programmes. The practitioner lesson is to separate commercial simplification from operational accountability.
A question worth separating out:
Q: What is the difference between shared procurement and shared trust governance?
A: Shared procurement is the commercial mechanism for buying a service through a common framework. Shared trust governance is the operational discipline for deciding who owns certificates, how they are issued, when they are revoked and how accountability is proven. The first reduces process overhead; the second reduces identity risk.
👉 Read our full editorial: Digital trust procurement in UK education shifts toward shared PKI