Yes. Inventory gaps, orphaned certificates, and unclear ownership become harder to remediate as renewal cadence tightens. The 200-day phase is the best window to find unknown certificates, remove manual handoffs, and test automation before the shorter deadlines leave little margin for correction.
Why inventory cleanup belongs before the 100-day phase
Inventory cleanup should happen before the 100-day phase because the work becomes more expensive once renewal dates start closing in. Unknown certificates, stale ownership records, and manual exceptions are easiest to correct while there is still time to discover them, validate their purpose, and reassign responsibility without rushing.
That is especially true for certificate estates with mixed ownership, because the same gap that looks manageable in a relaxed window can become a renewal failure later. A clean inventory is not just bookkeeping, it is the prerequisite for reliable rotation, decommissioning, and exception handling.
When the inventory is incomplete, teams tend to discover problems only when a renewal or outage forces action. At that point, remediation is constrained by short deadlines, cross-team dependency chains, and the risk of breaking systems that no one clearly owns.
What gets harder if cleanup is delayed
Delaying cleanup usually turns a discovery problem into an operational risk problem. Orphaned certificates may still be active in production, but without ownership, asset context, or usage visibility, they are difficult to classify quickly enough for safe renewal or retirement.
The practical failure mode is not usually a single catastrophic event. It is accumulated uncertainty: more manual handoffs, more last-minute approvals, and more reliance on people remembering how a certificate was issued, where it is used, and what breaks if it is changed.
That uncertainty also weakens automation. If the underlying inventory is noisy, automation cannot reliably decide what to renew, what to revoke, what to migrate, and what to leave alone. Cleaning the inventory first improves the quality of every later control decision.
For teams standardising their certificate and identity hygiene, the NHI Lifecycle Management Guide is a useful reference because it ties inventory, ownership, rotation, and offboarding into one operating model. The Top 10 NHI Issues also reinforces why inventory gaps and ownership ambiguity tend to produce the same downstream control failures.
Why the 200-day window is the safest place to fix it
The 200-day phase is valuable because it gives teams room to find unknown certificates, test discovery methods, and correct ownership before shorter deadlines reduce the margin for error. This is the point where cleanup is still a controlled exercise rather than an emergency response.
It is also the right time to remove manual handoffs. Once the estate is known and scoped, teams can decide where automation should issue reminders, where it should renew safely, and where human review must remain in place because the certificate is tied to a fragile or high-impact dependency.
The strongest anchor for this work is a documented lifecycle process. NHIMG’s Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs provides that lifecycle view, while the Key Challenges and Risks section is a useful reminder that visibility gaps and unmanaged credentials are usually the root cause, not the symptom.
Risk and Threat Considerations
When cleanup is deferred, the risk is less about the certificate itself and more about the uncertainty surrounding it. Unknown ownership, stale usage records, and long-lived secrets can hide active exposure until renewal time, when there is little opportunity to investigate safely.
Failure mechanism: Incomplete inventory leaves orphaned or misclassified certificates in place, so renewal, revocation, and replacement decisions are made under time pressure with weak context.
Impact: Teams can miss renewals, break dependent services, or leave unnecessary credentials active for longer than intended, increasing operational and security exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Inventory cleanup must identify and remove obsolete or ownerless certificates before renewal pressure rises. |
| NHI-02 — Secret Leakage | Orphaned certificates and unclear ownership increase the chance that secret material remains exposed or unmanaged. | |
| NHI-07 — Long-Lived Secrets | The question is about avoiding long-lived certificate exposure before shorter deadlines make correction harder. | |
| Recommendation — Review and retire orphaned identities and credentials before renewal deadlines compress remediation time. Inventory and rotate exposed secret material before it becomes a renewal-time dependency. Shorten credential lifetimes and remove stale secrets from the active estate. | ||
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | The subject is explicitly about inventory cleanup and ownership completeness. |
| Recommendation — Maintain an accurate asset inventory so certificates can be attributed and remediated on time. | ||
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | Certificate cleanup depends on knowing what exists, who owns it, and where it is used. |
| Recommendation — Keep a current component inventory and use it to drive certificate cleanup and renewal planning. | ||
Practitioner Guidance
What to prioritise: Clean up ownership, usage, and expiry data before automating renewal. If you cannot confidently name the owner and business purpose of a certificate, treat it as an inventory exception rather than a routine renewal candidate.
What to verify: Confirm that discovery coverage includes unknown, dormant, and manually issued certificates, not just the assets already known to the platform team. The inventory is only trustworthy when it catches the strays.
Decision rule: If a certificate cannot be mapped to a clear owner, service, and replacement path, fix that mapping first. Renewal without attribution only preserves uncertainty.
Practitioner takeaway: The earlier phase is for finding and classifying, the later phase is for executing. Once deadlines tighten, ambiguity becomes the real risk, so inventory cleanup has to come first.
Related resources from NHI Mgmt Group
- Should organisations prioritise SaaS cleanup before expanding access controls?
- Should organisations prioritise DSPM before IAM cleanup in hybrid environments?
- Should organisations prioritise secrets rotation before access cleanup?
- Should organisations prioritise AI agent access controls before broader NHI cleanup?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org