Certificate discovery is the process of finding and classifying what already exists across the environment, including certificates that use standardized or test post-quantum algorithms. Certificate enrollment is the process of issuing a new certificate through a defined request path. In a PQC programme, discovery supports visibility and planning, while enrollment supports controlled issuance and policy enforcement.
What discovery does in a PQC programme
Discovery answers the inventory question: what certificates already exist, where they live, who depends on them, and which ones are using algorithms that matter to the PQC transition. That visibility is what turns a broad migration plan into an ordered worklist. Without it, teams tend to focus on the obvious public-facing certificates and miss internal, short-lived, embedded, or hardcoded certificate use.
In practice, discovery should classify certificates by algorithm, ownership, expiry, environment, and business criticality. It also needs to surface where certificates are managed by platforms rather than by a central PKI team, because those are often the places where shadow issuance and renewal drift happen. NHIMG’s Ultimate Guide to NHIs is useful here because certificate visibility sits alongside broader lifecycle, inventory, and credential hygiene work.
Discovery is also the phase where you decide whether a certificate is merely present or actually in scope for migration. A certificate that already uses a standardized or test post-quantum algorithm still needs to be found and understood, because discovery is about state, not approval. For broader lifecycle context, see NHIMG’s NHI Lifecycle Management Guide and The State of Non-Human Identity Security, both of which reinforce why inventory and visibility are prerequisites for control.
What enrollment does in a PQC programme
Enrollment is the controlled issuance path. It is the mechanism that takes a new request, validates policy, and produces a certificate that should exist, with the right subject, algorithm, lifetimes, and approval logic. In a PQC programme, that is where the transition becomes operational, because new certificates can be issued against approved post-quantum or hybrid policy instead of relying on legacy defaults.
The main distinction from discovery is that enrollment is forward-looking and enforcement-oriented. Discovery tells you what is already there; enrollment determines what can be created next, under what rules, and by which request path. That makes enrollment the better place to enforce algorithm policy, issuance constraints, and trust-chain requirements, while discovery remains the better place to measure adoption progress and identify unsupported estates.
Good enrollment design also matters because PQC programmes often have mixed states for a long time. Teams may need to issue certificates for pilot systems, test environments, or dual-stack deployments while still supporting legacy consumers. That means the enrollment path should be explicit about algorithm selection, fallback handling, and any exceptions that are approved for a limited period. For policy and audit framing, Ultimate Guide to NHIs, Regulatory and Audit Perspectives is a practical companion because issuance controls and evidence retention usually become audit questions very quickly.
How to separate the two cleanly in transition planning
The simplest rule is that discovery informs the migration map, while enrollment enforces the target state. If a certificate already exists, it belongs in discovery even if it uses a PQC test algorithm. If a certificate is being newly created, renewed through a governed path, or reissued under a new policy, it belongs in enrollment. Mixing the two creates confusion about ownership and makes it harder to measure progress.
What to verify: Make sure your discovery process can see certificates across application stacks, endpoints, automation pipelines, and third-party-managed services, not just central PKI stores. Then verify that enrollment is the only path that can introduce new certificates into approved production trust chains. That separation is what lets you manage exceptions without losing oversight.
Decision rule: If the question is “what do we already have and what must change?”, use discovery. If the question is “what may we issue now, under which policy, and with what algorithm?”, use enrollment. Teams that blur the boundary usually end up with incomplete inventories and inconsistent issuance policy.
Practitioner takeaway: Treat discovery as a visibility and prioritisation function, and enrollment as a control enforcement function. The PQC programme is usually weakest when teams assume one can substitute for the other, because inventory quality and issuance policy solve different problems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 5 — Account Management | Certificate discovery and enrollment depend on knowing what identities and certificates exist. |
| 6 — Access Control Management | Enrollment is a controlled issuance path that must enforce policy and approved access to issuance. | |
| 12 — Network Infrastructure Management | Certificate visibility and controlled issuance support secure trust paths across environments. | |
| Recommendation — Inventory certificate-bearing accounts and assets before changing issuance policy. Restrict certificate enrollment to approved request paths and policy checks. Map certificate dependencies across systems so transition planning reflects real trust relationships. | ||
| NIST CSF 2.0 | ID.AM — Asset Management | Discovery is fundamentally an inventory and classification activity for certificates. |
| PR.AC — Identity Management, Authentication and Access Control | Enrollment enforces who or what may obtain a new certificate and under what conditions. | |
| GV.PO — Policy | PQC enrollment depends on explicit policy for algorithm choice, exceptions, and approved paths. | |
| Recommendation — Build a complete certificate inventory before attempting PQC migration decisions. Apply issuance policy controls so only approved requests can create new certificates. Define certificate policy to govern hybrid, test, and production issuance consistently. | ||
Related resources from NHI Mgmt Group
- What is the difference between asset discovery and vulnerability enumeration in a security programme?
- What is the difference between data privacy and data discovery in a consumer trust programme?
- What is the difference between SAML SSO and OIDC for enterprise authentication planning?
- What is the difference between SSH keys and passwords in privileged access management?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org