Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do certificate registers and key lifecycle controls…
Governance, Ownership & Risk

Why do certificate registers and key lifecycle controls matter so much under DORA?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

They matter because DORA treats cryptography as an operational control, not a theoretical one. A current register of certificates and certificate-storing devices helps prevent expiry outages, while formal key lifecycle management reduces loss, misuse, and unsupported recovery. Together, they give assessors proof that critical services can survive failure without uncontrolled access.

Why This Matters for Security Teams

Under DORA, certificate registers and key lifecycle controls are not paperwork exercises. They are evidence that critical services can keep operating when cryptographic trust fails, whether through expiry, compromise, or poor recovery. A complete register shows what exists, where it lives, who owns it, and when it must be renewed. Key lifecycle controls show how keys are generated, protected, rotated, revoked, and destroyed. That combination matters because auditors look for operational resilience, not just encryption intent.

Teams often miss that cryptography failures become service failures fast. A missed certificate renewal can take down customer-facing systems, while unmanaged private keys can make recovery impossible or unsafe. This is why DORA and the EU Digital Operational Resilience Act (DORA) push organisations toward traceable control, not informal ownership. NHIMG research on The Critical Gaps in Machine Identity Management report found that certificate expiry is the leading cause of outages for 45% of organisations, which is exactly why registers and lifecycle controls become board-level evidence under resilience testing.

In practice, many security teams encounter certificate failures only after a renewal window is missed and a critical service has already gone dark, rather than through intentional lifecycle governance.

How It Works in Practice

A certificate register should act as the operational source of truth for every certificate-storing device, workload, service, and owner. It needs enough detail to support continuous monitoring, not just annual review: subject, issuer, purpose, environment, expiry date, renewal path, dependency, and emergency contact. For regulated environments, the register should also show which certificates support critical or important functions, because DORA assessors care about business impact, not just technical inventory.

Key lifecycle controls extend that register into active governance. The practical baseline is: generate keys in approved systems, protect private keys with strong access controls, rotate them on schedule or on event, revoke them promptly when compromise is suspected, and destroy retired material so it cannot be reused. Best practice is evolving toward automation wherever possible, because manual tracking does not scale across distributed estates. NHIMG’s NHI Lifecycle Management Guide and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs both reinforce that lifecycle ownership must be explicit, not assumed.

  • Map each certificate and key to a named business service and technical owner.
  • Track expiry, renewal method, and revocation path in a live register.
  • Use automated renewal and rotation where systems support it.
  • Verify backup, recovery, and replacement procedures before an incident.
  • Retire unused keys and certificates to reduce exposure and audit noise.

This aligns with the operational direction of the OWASP Non-Human Identity Top 10, which treats machine identity lifecycle failures as a common source of compromise and outage. These controls tend to break down in highly decentralized environments where teams create certificates outside central tooling because ownership, inventory, and renewal responsibility become fragmented.

Common Variations and Edge Cases

Tighter certificate and key control often increases operational overhead, requiring organisations to balance resilience against deployment speed and local team autonomy. That tradeoff is real in containerized platforms, multi-cloud estates, and environments with many short-lived workloads, where static spreadsheets quickly become stale. Current guidance suggests that the answer is not more manual review, but better automation and clearer service ownership.

There is no universal standard for how much detail a register must contain, but for DORA purposes it should be complete enough to prove control during failure testing and audit review. Some organisations also separate certificates used for external trust from those used internally between services, because the risk and renewal cadence differ. The same is true for keys tied to signing, encryption, and authentication. A signing key breach, such as the risk illustrated by the Coupang Signing Key Breach, can create far broader trust damage than a routine TLS renewal issue.

For teams still early in maturity, Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a useful reminder that auditability is part of the control itself, not a separate reporting task. In complex legacy estates, these controls are hardest to sustain where certificates are issued ad hoc by application teams and private keys are embedded in unmanaged systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS-1Protecting data and cryptographic assets maps to key lifecycle and certificate governance.
OWASP Non-Human Identity Top 10NHI-03Covers lifecycle management failures that create expired or stale machine identities.
CSA MAESTROCovers agent and workload identity lifecycle governance across distributed environments.
NIST AI RMFGOVERNResilience governance requires accountability for cryptographic controls supporting AI systems.

Assign ownership and oversight for cryptographic lifecycle controls that underpin critical AI services.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org