They should do both, but inventory comes first when ownership and exposure are unclear. Automation without a reliable inventory can accelerate the wrong assets, while inventory without automation cannot sustain shorter certificate lifetimes. The sequence matters because the inventory tells teams what to automate and why.
Why the sequence matters for PQC readiness
pqc readiness is not just a crypto migration problem, it is an asset and control problem. If teams cannot identify where certificates, signing keys, trust chains, and dependent systems exist, automation will happily act on the wrong scope. A reliable inventory gives you the target set, the ownership map, and the exposure picture that automation needs to be safe and effective.
That sequencing also reflects the operational reality of shorter certificate lifetimes and crypto-agility work. Once lifetimes shrink, manual handling becomes a bottleneck, so the inventory has to define what should be automated, which systems are in scope, and which dependencies will break when algorithms or issuance processes change. For certificate-heavy environments, that usually means treating inventory and lifecycle automation as one programme rather than two disconnected tasks.
Teams that already maintain certificate and machine-identity visibility can move faster on algorithm replacement because they are not discovering assets at the same time as they are changing issuance paths. NHIMG’s Post-Quantum Readiness for Identity and PKI is useful here because it ties PQC migration to cryptographic inventory and crypto-agility, which is the practical bridge between knowing what exists and changing it safely.
What inventory has to capture before automation can help
For PQC readiness, inventory is more than counting certificates. It has to capture owner, environment, issuance path, expiry profile, dependency chains, external exposure, and whether the asset supports authentication, signing, transport, or internal trust. Without those fields, teams cannot decide which systems need replacement first, which can be renewed automatically, and which need human review because they carry business or interoperability risk.
In practice, the highest-value inventory is the one that can answer three questions quickly: what is deployed, who owns it, and what will fail if the cryptography changes. That is why discovery, classification, and ownership assignment come before mass automation. NHIMG’s Machine Identity, PKI and Certificate Lifecycle Guide is relevant because certificate lifecycle automation only works when the underlying inventory and renewal logic are already understood.
Inventory also needs to separate steady-state assets from ephemeral ones. A long-lived certificate on a customer-facing system, a code-signing chain, and a short-lived internal service certificate do not need the same migration path. The more precise the inventory, the less likely automation is to accelerate low-risk assets while missing the ones that matter most.
Where automation becomes the multiplier, not the starting point
Automation is the force multiplier once the asset set is known. It reduces renewal toil, shortens response time when algorithms or certificate policies change, and makes it possible to manage much shorter lifetimes without creating operational outages. It also reduces the chance that PQC work stalls after the first wave of manual replacements.
The right automation target is not “everything at once.” It is the repeatable subset of the estate where ownership is clear, dependencies are mapped, and renewal can be safely orchestrated end to end. That usually starts with high-volume, low-complexity certificates and expands only after the inventory shows stable coverage and reliable exception handling. NHIMG’s NHI Lifecycle Management Guide is useful for the lifecycle principle behind this approach, because the operational challenge is the same: visibility first, then rotation and offboarding at scale.
Automation should also be measured by failure prevention, not just speed. If it is renewing the wrong certificates, missing the right owners, or pushing changes without dependency awareness, it is amplifying risk. Good automation is narrow, observable, and tied to an authoritative inventory, not a generic renewal script applied across an unknown estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST SP 800-57 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | PQC readiness depends on knowing what cryptographic assets and dependent systems exist. |
| IA-5 — Authenticator Management | Certificate and key lifecycle automation directly affects authenticators and their rotation. | |
| SC-12 — Cryptographic Key Establishment and Management | PQC migration changes key and algorithm management across the estate. | |
| Recommendation — Maintain a complete component inventory before automating cryptographic migration. Automate authenticator rotation only after ownership and scope are established. Plan key and algorithm transitions from an authoritative inventory of cryptographic assets. | ||
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | PQC readiness starts with knowing which assets use vulnerable cryptography. |
| Recommendation — Inventory all assets using cryptography before automating renewal or migration. | ||
| NIST SP 800-57 | Key Management | The question concerns key and certificate lifecycle sequencing for PQC transition. |
| Recommendation — Apply key lifecycle governance before scaling automated certificate changes. | ||
Practitioner Guidance
What to prioritise: Start by building an inventory that records ownership, deployment context, expiry, and dependency for every certificate or cryptographic asset. Use that inventory to classify which assets are good candidates for automated renewal and which require staged migration or manual control.
Decision rule: If you cannot confidently answer who owns an asset or what breaks when its crypto changes, do not automate its migration yet. If ownership and exposure are known, automate the repeatable parts first, then use the inventory to extend coverage in waves.
What to verify: Before trusting automation, verify that the inventory is complete enough to support the renewal workflow, exception handling, and rollback path. The key test is whether the automation can act on authoritative data rather than discovery by failure.
Practitioner takeaway: PQC readiness succeeds when inventory defines the blast radius and automation executes the repeatable work. If you reverse that order, you risk scaling the wrong changes faster.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org