Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Certificate Register
Governance, Ownership & Risk

Certificate Register

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

A living inventory of certificates and certificate-storing devices that support critical or important functions. It is used to track ownership, expiry, renewal, and operational dependencies. Under DORA, the register is evidence that certificate governance is active, current, and able to prevent avoidable outages caused by expired or unmanaged certificates.

Expanded Definition

A certificate register is the authoritative living inventory for digital certificates and the devices or services that store them. In NHI operations, it is more than a spreadsheet of expiry dates. It ties each certificate to an owner, business service, issuer, renewal path, and the operational dependency that will fail if the certificate is not renewed on time. For DORA-aligned environments, that makes the register evidence of active governance rather than passive recordkeeping.

Its scope often overlaps with certificate lifecycle management, but the register is the control plane that records what exists, where it is deployed, and who is accountable. Definitions vary across vendors on whether private keys, trust chains, and certificate-storing hardware must also be included, so organisations should define scope explicitly. The register is most useful when paired with policy, automation, and review cadence informed by the NIST Cybersecurity Framework 2.0 and NHI governance practices discussed in the Ultimate Guide to NHIs — What are Non-Human Identities.

The most common misapplication is treating the register as a static compliance artifact, which occurs when teams update it only during audits instead of maintaining it continuously.

Examples and Use Cases

Implementing a certificate register rigorously often introduces operational overhead, requiring organisations to balance visibility and assurance against the cost of discovery, normalization, and ongoing updates.

  • Tracking TLS certificates for customer-facing applications so renewal owners can be alerted before an outage window.
  • Recording certificates on load balancers, API gateways, and service mesh components where a missed expiry can break authentication paths.
  • Maintaining inventory for certificates embedded in HSMs, appliances, or industrial devices that cannot be discovered by standard scanners.
  • Linking certificates to service accounts, deployment pipelines, and workload identities so ownership is clear when teams change.
  • Documenting certificate-storing devices that support critical or important functions, which is especially relevant when auditors need proof of controlled lifecycle management.

NHIMG research shows why this matters in practice: in The Critical Gaps in Machine Identity Management report, only 38% of organisations reported automated certificate lifecycle management, and certificate expiry was the leading cause of outages for 45% of organisations. That gap is also visible in breach analysis such as the Sisense breach, where unmanaged machine identity exposure compounded downstream risk. In mature programs, the register feeds review workflows, renewal automation, and exception handling rather than serving as a passive archive.

Why It Matters in NHI Security

Certificate registers matter because certificates are machine identities with expiry, trust, and dependency risk. When the register is incomplete, teams lose visibility into which systems depend on which credentials, and that creates silent failure modes that are harder to detect than human identity issues. A missing or stale register also weakens auditability, because ownership, renewal responsibility, and control evidence cannot be proven quickly when regulators or incident responders ask.

This becomes even more important in environments with sprawling workload identities, third-party integrations, and legacy infrastructure. NHIMG data from the Critical Gaps in Machine Identity Management report shows that 57% of organisations lack a complete inventory of their machine identities, while 53% have experienced a security incident directly related to machine identity management failures. Those findings reinforce the operational reality that weak certificate governance is not a theoretical problem. It becomes a continuity problem, a compliance problem, and an access problem at once.

Organisations typically encounter the impact only after an expired certificate breaks a critical service or an audit exposes missing ownership, at which point the certificate register becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the technical controls, and DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORADORA expects ICT asset and credential governance supporting operational resilience.
NIST CSF 2.0ID.AM-1Asset inventories support identification of systems and dependencies that certificates protect.
NIST Zero Trust (SP 800-207)PR.AC-1Zero Trust relies on trustworthy machine identity and credential visibility.
OWASP Non-Human Identity Top 10NHI-02Certificate sprawl and weak lifecycle control align with improper NHI secret and credential management risks.
NIST AI RMFAI systems also depend on certificates for service trust and secure model operations.

Keep an accurate certificate register to prove ownership, renewal control, and outage prevention for critical services.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org