Prioritise certification first when you do not yet know which identities are still needed, then rotate the high-risk credentials that remain. If you rotate blindly, you can increase operational risk without reducing access risk. The right sequence is evidence first, then remediation, then ongoing lifecycle control.
What comes first: proving what still exists, or changing it?
The decision is really about control order. Certification answers the inventory and ownership question, which is the prerequisite for safe remediation. Rotation changes credentials but does not tell you whether the identity is still valid, whether it is owned, or whether a dependent system still relies on it. Treat certification as the evidence-gathering step, then rotate only the remaining credentials that are both needed and high risk.
That sequencing matters because credential rotation can break integrations, jobs, and automation if you have not first identified the living set. For NHIs, the practical issue is not simply “change the secret”, it is “change the secret for the identities that remain legitimately in use and can be supported afterwards.”
A useful rule is that certification reduces uncertainty, while rotation reduces exposure. If you do the latter before the former, you may create outage risk without materially improving your access posture. That is why the strongest NHI lifecycle management programs treat discovery, ownership, and recertification as the front end of remediation, not an optional preliminary.
Why blind rotation can make NHI risk worse
Blind rotation assumes you already know which credentials are active, which are dormant, and which are embedded in applications, pipelines, or third-party workflows. When that assumption is wrong, a forced change can cause an outage, prompt emergency exceptions, or leave teams delaying future rotations because the last one was too disruptive. The result is often weaker long-term control, not stronger control.
There is also a governance problem. If an NHI has no current owner, no clear use case, or no verified dependency map, rotation may simply preserve an unknown identity in a new form. In that case, the underlying exposure is not solved until you can confirm the identity should still exist at all. The Top 10 NHI Issues and the NHI Ownership and Accountability Guide both reinforce that stale, orphaned, and overprivileged NHIs create risk precisely because teams act without full visibility.
That is why certification first is not a delay tactic. It is the mechanism that tells you whether the credential belongs to a current business process, whether the owner can accept the change, and whether the remediation target is still legitimate.
What a practical sequence looks like for real NHIs
Start with certification of the identity set, then segment the population by risk and dependency. High-confidence, low-risk identities can be reviewed and retired cleanly. High-risk identities that remain in use should then be rotated in a controlled order, ideally with dependency owners present and rollback ready.
After that, move into ongoing lifecycle control so the same problem does not recur. The strongest programs combine periodic certification with event-driven review, especially when access reviews and certification are used to close the loop on exceptions and reintroduce ownership discipline. For recurring operational identities, rotation should be tied to expiry, vaulting, and clear thresholds for when static secrets are no longer acceptable.
For many teams, the right answer is not “certification or rotation”, but “certification before rotation, then rotation only where the identity survives review.” The Guide to NHI Rotation Challenges is especially useful here because it highlights why dependency mapping, vaulting, and automation are what make rotation sustainable rather than brittle.
Risk and Threat Considerations
The main risk is operational self-inflicted harm: a credential change can break a production workflow, trigger emergency access exceptions, or leave teams afraid to rotate anything else. The security risk is the opposite failure, where unreviewed identities stay alive because rotation was used as a substitute for determining ownership and necessity.
Failure mechanism: Teams rotate secrets before confirming the identity set, so they either disrupt valid dependencies or preserve obsolete access paths because they never removed the underlying entitlement.
Impact: You can create outages, accumulate exception-driven access, and leave dormant or orphaned NHIs available for abuse even after a “successful” rotation campaign.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Certification first helps identify NHIs that should be removed before rotation. |
| NHI-05 — Overprivileged NHI | Reviewing first exposes excessive access so rotation targets the right high-risk identities. | |
| NHI-07 — Long-Lived Secrets | The question hinges on when to replace enduring secrets after validating need and ownership. | |
| Recommendation — Use certification to remove obsolete NHIs before rotating the credentials that remain. Certify access levels first, then rotate the highest-risk credentials tied to excessive privilege. Prioritise certification before replacing long-lived secrets that are still legitimately in use. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential rotation and lifecycle control are central to authenticator management. |
| AC-2 — Account Management | Certification is the step that validates whether accounts or NHIs should remain active. | |
| AC-6 — Least Privilege | The sequence aims to reduce standing access before rotating credentials. | |
| Recommendation — Manage authenticator lifecycle after confirming which authenticators are still required. Review account necessity first, then remediate only the accounts that should remain. Remove unnecessary privilege during certification before performing credential rotation. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity Management | The question is about ordering identity validation and remediation for NHIs. |
| A.5.18 — Access Rights | Certification is effectively a review of whether access rights should still exist. | |
| Recommendation — Confirm identity records first, then apply rotation to the remaining active NHIs. Review access rights before changing credentials so only justified access remains. | ||
| CIS Controls v8 | CIS-5 — Account Management | The issue is whether to review active accounts before changing credentials at scale. |
| CIS-6 — Access Control Management | The answer depends on validating and reducing access before remediation. | |
| Recommendation — Inventory and review accounts first, then rotate only the credentials that remain necessary. Use access control reviews to confirm necessity before credential rotation. | ||
Practitioner Guidance
What to prioritise: Certify the identity inventory first whenever you lack confidence in ownership, business purpose, or dependency mapping. Only then decide which remaining NHIs justify rotation based on exposure, privilege, and operational criticality.
Decision rule: If a secret authenticates a live workload, treat the change as a controlled remediation event, not a blanket hygiene task. If you cannot name the owner or dependency chain, stop and resolve that before rotating.
What to verify: Before trusting a rotation result, verify that the identity still exists for a documented business process, the owner can support the change, and the downstream system has a tested rollback path.
Practitioner takeaway: The safest sequence is evidence, then removal or rotation, then lifecycle control. In NHI programs, certainty about what should exist is usually more valuable than rapid credential churn.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org