Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust What do organisations often get wrong when buying…
Authentication, Authorisation & Trust

What do organisations often get wrong when buying SSL certificates for multiple domains or subdomains?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Authentication, Authorisation & Trust

A common mistake is treating all certificates as interchangeable. Multi-domain and subdomain coverage changes the price and the administrative burden, so teams should evaluate where certificates will be deployed before purchasing. Hidden costs can also appear in renewal or support, so procurement should assess the full lifecycle rather than the initial quote alone.

Why This Matters for Security Teams

Buying SSL certificates is often treated as a procurement task, but for security teams it is really an inventory and lifecycle problem. The wrong certificate choice can create avoidable sprawl, missed renewals, and weak operational ownership across domains, subdomains, and environments. NHI Management Group’s Ultimate Guide to NHIs — What are Non-Human Identities is useful here because certificates are part of the broader machine identity estate, not a standalone purchase.

The common mistake is assuming a low initial quote means lower total cost. In practice, wildcard, multi-domain, and single-name certificates each create different renewal, validation, and change-management overhead. That matters when teams later split services across domains or move applications between clusters, because certificate portability and coverage limits can become hidden operational constraints. The NIST Cybersecurity Framework 2.0 places this squarely inside asset management and protection outcomes, not just procurement.

In practice, many security teams discover certificate complexity only after an outage, a rushed renewal, or a failed deployment has already exposed the gap.

How It Works in Practice

The right certificate model depends on where the certificate will be deployed, who will manage it, and how often the covered names change. A single-domain certificate may be cheapest upfront, but it becomes inefficient if every new subdomain requires another purchase, validation step, and renewal workflow. A multi-domain certificate can reduce sprawl, but it may also centralise failure if one certificate expiry affects several business-critical services at once.

Practitioners should evaluate three things before purchase:

  • Coverage scope: exact hostnames, SAN limits, wildcard use, and whether future subdomains are predictable.

  • Lifecycle burden: renewal cadence, validation effort, support responsiveness, and whether automation is possible.

  • Operational fit: whether the certificate will sit on a public website, internal service, load balancer, or application gateway.

This is where inventory discipline matters. NHIMG research on machine identity management shows that 57% of organisations lack a complete inventory of their machine identities, and only 38% have automated certificate lifecycle management in place. That gap makes it easy to buy the wrong certificate type because the real deployment footprint is unknown. The broader breach pattern is also visible in NHIMG’s Sisense breach coverage, where exposed credentials and operational weaknesses show how machine identity issues compound quickly.

Best practice is to map certificate purchases to the actual service topology, then automate renewal where possible using policy-based controls and certificate inventory tooling. These controls tend to break down in fast-moving cloud environments where subdomains are created dynamically and no one owns the full certificate estate.

Common Variations and Edge Cases

Tighter certificate standardisation often increases administrative overhead, requiring organisations to balance simpler procurement against the need for flexible coverage. That tradeoff becomes sharper in environments with customer-facing portals, ephemeral test domains, or frequent replatforming.

There is no universal standard for this yet, but current guidance suggests matching the certificate type to the rate of hostname change. Wildcard certificates are convenient for many subdomains, yet they are not always appropriate when different services need isolated trust boundaries. Multi-domain certificates can reduce the number of purchases, but teams should avoid using them as a shortcut for poor asset management, because one renewal miss can affect several applications at once.

Edge cases also arise when legal or compliance teams expect separate certificates for separate business units, or when public-facing and internal services require different trust policies. In those situations, buying the cheapest certificate is the wrong optimisation. Teams should decide whether they need naming flexibility, stronger segmentation, or simpler renewal operations, then buy accordingly. For identity context, the NHIMG explanation of DeepSeek breach reinforces how quickly exposed secrets and mismanaged machine identities can escalate once operational controls are weak.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Certificate sprawl is a lifecycle weakness in machine identity management.
NIST CSF 2.0ID.AM-1Certificate buying depends on accurate asset inventory and ownership.
NIST AI RMFGOVERNAI systems also rely on machine identities and benefit from clear governance.
NIST Zero Trust (SP 800-207)SC-12Certificate misuse weakens trust boundaries in zero trust environments.

Use short-lived, inventory-backed certificates to support trusted service authentication.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org