Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust What breaks when organisations rely on certificate managers…
Authentication, Authorisation & Trust

What breaks when organisations rely on certificate managers for post-quantum readiness?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 25, 2026 Domain: Authentication, Authorisation & Trust

They miss most of the cryptographic estate. Certificate managers usually track public TLS, but post-quantum readiness also depends on internal PKI, SSH keys, code signing, embedded algorithms, HSM-backed keys, and workload identity material. If those assets are invisible, the migration plan is built on partial data and the deadline will slip.

Why Certificate Managers Miss the Real Post-Quantum Risk

Certificate managers are useful for visibility into public TLS, but post-quantum readiness is broader than certificate expiration tracking. The real problem is cryptographic estate discovery: internal PKI, SSH keys, code signing, embedded algorithms, HSM-backed keys, and workload identity material all need inventory and migration planning. NIST’s Cybersecurity Framework 2.0 treats asset visibility and risk governance as core duties, not optional add-ons.

NHIMG research shows why narrow tooling creates false confidence. In the Ultimate Guide to NHIs, 96% of organisations store secrets outside secrets managers in vulnerable locations, and only 5.7% have full visibility into their service accounts. That same visibility gap appears in PQC planning when teams assume certificate inventory equals cryptographic inventory. It does not. Post-quantum migration touches every place identity and cryptography intersect, including non-certificate assets that may outlive the TLS estate by years.

In practice, many security teams discover the missing crypto estate only after audit pressure or a migration project has already slipped.

How Post-Quantum Readiness Breaks in Practice

Effective readiness starts with discovery, classification, and dependency mapping across all cryptographic uses, not just public-facing certificates. A certificate manager can tell you when a cert expires, but it rarely explains where a key is used, which application trusts it, or whether the algorithm is embedded in firmware, CI/CD, or an appliance. That is why the best current guidance suggests pairing certificate tooling with broader NHI governance and asset inventory, as described in NHI Lifecycle Management Guide and the Top 10 NHI Issues.

Operationally, teams need to answer four questions at runtime and during planning:

  • What cryptographic assets exist, including non-certificate keys and workload identities?
  • Where are they used, and which business services depend on them?
  • Which algorithms can be upgraded, replaced, or dual-stacked for transition?
  • Which systems cannot be changed quickly because of embedded hardware, vendor lock-in, or HSM dependencies?

This is where inventory gaps become migration blockers. If an HSM-backed signing key is outside the certificate manager, the PQC workstream misses code signing risk. If SSH keys and service account credentials are unmanaged, the organisation may preserve a quantum-safe TLS channel while leaving lateral movement paths untouched. NIST’s framework emphasises governance and continuous assessment, but the control only works when the asset model is complete. These controls tend to break down in heterogeneous environments with legacy appliances, embedded systems, and fragmented ownership because the cryptographic estate is distributed across teams and tools.

Where the Standard Answer Breaks Down

Tighter post-quantum controls often increase discovery and migration overhead, requiring organisations to balance speed against operational continuity. That tradeoff is especially visible in regulated environments, where certificate renewals are already under pressure. SailPoint’s Critical Gaps in Machine Identity Management report notes that only 38% have automated certificate lifecycle management in place, and 57% lack a complete inventory of their machine identities. Those figures matter because PQC readiness fails fastest where inventory is already partial.

There is no universal standard for exactly how to score post-quantum exposure across mixed cryptographic assets yet. Current guidance suggests prioritising high-value identities first: signing keys, internal CA chains, workload identity credentials, and anything that protects software supply chains or privileged access. Public TLS alone is usually not the critical path. A certificate manager can still be part of the solution, but only as one input to a larger crypto-agility program that includes ownership, algorithm mapping, rotation planning, and decommissioning. In high-change environments, the biggest risk is not missing a certificate expiry. It is assuming the tool already sees the whole trust surface when it does not.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Crypto estate gaps are really unmanaged NHIs and secrets outside inventory.
OWASP Agentic AI Top 10Autonomous systems often rely on machine credentials that certificate tools miss.
CSA MAESTROMAESTRO-03MAESTRO addresses securing agent and workload trust boundaries across tooling.
NIST AI RMFGOVERNPQC readiness needs governance over asset visibility, risk, and accountability.
NIST CSF 2.0ID.AM-1Asset management is the foundation for finding non-certificate cryptographic exposure.

Build a complete NHI inventory across keys, tokens, service accounts, and signing materials before planning PQC migration.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org