Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do organisations with growing certificate estates need…
Governance, Ownership & Risk

Why do organisations with growing certificate estates need more than basic CA functionality?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

Basic CA tooling can issue certificates, but it often fails at scale when organisations need governance, visibility, and renewal control across many trust domains. As certificate counts grow, unmanaged expiry, manual workflows, and inconsistent policy enforcement increase outage and security risk. Mature PKI needs lifecycle management, inventory, and automation to keep trust reliable.

Why This Matters for Security Teams

Basic CA functionality answers a narrow question: can a certificate be issued and signed correctly? It does not answer the operational questions that matter at scale, such as who owns the certificate, where it is deployed, when it expires, and whether policy is still being followed after issuance. That gap becomes expensive once certificates span applications, cloud accounts, CI/CD pipelines, appliances, and third-party trust domains. NIST’s control guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls makes clear that cryptographic trust is only one part of a broader governance problem.

NHIMG research shows why this is no longer a niche issue. In Ultimate Guide to NHIs — What are Non-Human Identities, the data shows that 71% of NHIs are not rotated within recommended time frames and only 5.7% of organisations have full visibility into their service accounts. Those are the conditions under which “working CA” becomes “failed trust program.” In practice, many security teams encounter certificate outages only after expiry has already broken production systems, rather than through intentional lifecycle control.

How It Works in Practice

Organisations with growing certificate estates need capability beyond issuance because the real risk sits in the lifecycle. Mature certificate management adds discovery, ownership mapping, policy enforcement, renewal orchestration, revocation handling, and audit evidence. That is the difference between a CA as a signing service and a certificate program as an operational control plane. For certificate-heavy environments, the control plane needs to know what exists, where it is deployed, which trust domain it belongs to, and whether it is still compliant with internal policy.

Practically, this usually means integrating the CA with inventory and automation systems rather than treating it as a standalone tool. Renewal should be event-driven and automated where possible. Expiry windows need alerting that is tied to service ownership, not just generic notifications. Policy should be enforced at issuance and during renewal, with different rules for public-facing TLS, internal service-to-service certificates, device identities, and partner-managed trust chains. NIST’s guidance on access control and system integrity supports this approach, but current guidance suggests organisations should adapt the workflow to their own trust boundaries instead of assuming one CA process fits every environment.

  • Discover certificates continuously across clouds, platforms, appliances, and embedded systems.
  • Assign ownership so every certificate has a named accountable team.
  • Automate renewal and revocation, especially for short-lived and high-volume certificates.
  • Apply policy consistently across trust domains rather than per-team exceptions.
  • Track certificate usage, expiry, and deployment drift as part of operational monitoring.

NHIMG’s Ultimate Guide to NHIs — What are Non-Human Identities highlights the broader NHI problem: secrets and machine credentials often outlive the systems they protect, and unmanaged validity windows become an attack path. These controls tend to break down when certificates are distributed across legacy platforms that cannot support automated renewal because manual exceptions reintroduce outage risk.

Common Variations and Edge Cases

Tighter certificate governance often increases operational overhead at first, requiring organisations to balance stronger control against legacy compatibility and deployment friction. That tradeoff is most visible in environments with mainframes, industrial systems, or third-party-managed services where automation is limited and renewal windows are hard to coordinate. Best practice is evolving, but there is no universal standard for this yet across all certificate estates.

Public TLS, internal mTLS, device certificates, and code-signing certificates do not behave the same way, so a single policy model can fail if it ignores those differences. For example, a short-lived certificate strategy may work well for service-to-service authentication but be inappropriate for a device that only connects intermittently. Similarly, a CA can be technically reliable while the broader trust program still fails because ownership is unclear or revocation is not operationalised. That is why basic CA features are necessary but not sufficient.

The clearest lesson from NHIMG research is that visibility and lifecycle control matter more than certificate count alone. The Sisense breach is a reminder that machine identity exposure can become a business issue when secrets and trust material are poorly governed. Security teams should treat certificate growth as a governance signal, not just a capacity issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Lifecycle and rotation failures are central to certificate estate risk.
NIST CSF 2.0PR.AC-1Certificate governance supports controlled access and trust validation.
NIST SP 800-53 Rev 5SC-12Cryptographic key establishment underpins certificate lifecycle security.
NIST AI RMFGovernance and accountability map to secure lifecycle management decisions.
NIST Zero Trust (SP 800-207)SC-7Zero trust depends on continuously verified machine trust and identity.

Inventory certificates, enforce rotation, and remove expired trust material before it becomes an outage.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org