Certificate management just became a board-level problem

Certificates used to be background IT—renewed periodically and rarely discussed in the boardroom. That’s changing fast. With lifespans shrinking toward 47 days and machine identities multiplying across cloud, AI, and API environments, certificate management has become a continuous operational discipline, not a once-a-year task. Kevin Weiss, CEO of Sectigo, explains why manual processes and fragmented tools can no longer keep pace, and why certificate lifecycle management now belongs alongside compliance and business continuity on the board’s agenda. He also breaks down the biggest blind spots in enterprise certificate inventories, why organisations should treat automation as a security control rather than an efficiency play, and how organisations should prepare today for post-quantum cryptography and emerging approaches like Merkle Tree Certificates. Weiss addresses a fast-growing challenge: as autonomous AI agents multiply, can existing identity and PKI architectures scale to verify millions of machine identities without breaking down?

Kevin Weiss, CEO, Sectigo

CISO Forum: Certificate lifetimes are shrinking dramatically. What does the move toward shorter-lived certificates mean for enterprise security teams, and what risks does it introduce?

Kevin Weiss: The biggest change is that certificate management has become a continuous operational process rather than a long-standing background IT function. When certificates were valid for a year or longer, teams could manage renewals periodically. However, as certificate lifecycles become significantly shorter and eventually reach 47 days, renewals happen much more often, and this traditional approach is no longer sustainable. If organisations continue to rely on manual processes or fragmented tools and scripts, the risk of missed renewals, service disruptions, and outages will increase substantially. The biggest risk is assuming that certificate management can continue to operate as it has historically. With shorter certificate lifecycles, organisations need automated, centralised, and proactive certificate management practices to maintain security and compliance while ensuring operational continuity.

CISO Forum:  At what point does certificate lifecycle management (CLM) stop being an IT operations issue and become a board-level cybersecurity and business resilience concern

Kevin Weiss: For organisations, CLM becomes a board-level cybersecurity and business resilience concern when certificate failures can directly impact business continuity, customer trust, revenue, or critical operations. Today, certificates underpin websites, applications, APIs, cloud environments, and machine-to-machine communication, making them a fundamental part of the digital infrastructure that businesses rely on. As certificate lifetimes continue to shorten and the number of machine identities increases, certificate management also grows in scale and frequency. Organisations want simplicity as they scale, not complexity. For boards and business leaders, the focus should therefore shift from simply asking whether certificates are being renewed on time to understanding whether the organisation has the visibility, automation, governance, and resilience required to manage its expanding certificate and machine identity landscape. CLM should be viewed as an integral part of the organisation’s broader compliance, cybersecurity, and business continuity strategy.

CISO Forum:  What are the biggest blind spots you currently see in enterprises’ certificate inventories, and why do organisations continue to struggle with certificate visibility?

Kevin Weiss: One of the biggest challenges enterprises face is fragmentation. Certificates are often distributed across different environments, making it difficult for organisations to maintain a complete and accurate view of their certificate inventory. The challenge grows even more significant as machine identities proliferate with the rise of AI-driven workloads. Many organisations still rely on fragmented scripts and siloed tools to manage certificates, which can create visibility gaps, inconsistent processes, and overlooked certificates. This makes it increasingly difficult to understand where certificates are deployed, who is responsible for them, and when they need renewal. Fundamentally, organisations cannot effectively automate what they cannot see. Establishing centralised, real-time visibility across the entire certificate environment is therefore a critical first step towards effective certificate lifecycle management and stronger digital trust across the enterprise.

CISO Forum:  How should CISOs approach certificate automation — primarily as an efficiency initiative, or increasingly as a critical security control?

Kevin Weiss: CISOs should increasingly view certificate automation as a critical security control, not simply an efficiency initiative. While automation can significantly reduce the administrative burden associated with certificate management, its greater value lies in reducing security and operational risks across the organisation’s digital infrastructure. Orchestrated automation within certificate lifecycle management enables organisations to continuously discover, monitor, renew, and deploy certificates. It also helps enforce consistent security policies across diverse environments. For CISOs, the objective should therefore be to establish a certificate management framework that combines visibility, governance, and automation.

CISO Forum:  Where do you see enterprises today in their preparedness for post-quantum cryptography (PQC)? Are most organisations still assessing the risk, planning their migration, or beginning implementation?

Kevin Weiss: Organisations are currently at different stages of readiness. Many are still assessing their exposure and understanding what the transition to PQC will mean for their existing infrastructure. In contrast, others have already begun planning their migration strategies. The key consideration is that organisations should not wait until PQC becomes an immediate operational requirement. They need to clearly understand where cryptography is used across their environments and identify the systems, applications, and assets that will eventually need to be upgraded or replaced. This is why we emphasise the importance of crypto-agility. Organisations need the flexibility and adaptability required to respond effectively as cryptographic standards and technologies evolve. Preparing for the transition today will help organisations reduce future disruption, manage risk more effectively, and be better positioned to adopt new cryptographic standards when required.

CISO Forum: What does “crypto-agility” mean in practical terms for a CISO, and what should organisations be doing today to ensure they can transition to new cryptographic standards without major disruption?

Kevin Weiss: In practical terms, crypto-agility is an organisation’s ability to change cryptographic algorithms, certificates, and trust mechanisms without fundamentally redesigning its underlying infrastructure each time a change is needed. For a CISO, this begins with visibility. Organisations need to understand where cryptography is being used across their environment, which certificates are deployed, and which systems and applications depend on them. This visibility must then be supported by the automation and flexibility required to implement cryptographic changes efficiently and at scale. Organisations that begin preparing today will be better positioned to transition smoothly as new cryptographic standards and technologies emerge. Ultimately, crypto-agility makes cryptographic change manageable and scalable rather than letting it become a disruptive operational challenge.

CISO Forum:  With technologies such as Merkle Tree Certificates emerging, how do you see digital certificates and authentication evolving in the post-quantum era?

Kevin Weiss: Merkle Tree Certificates represent an emerging approach to making post-quantum authentication more practical for the public internet. They are a proposed certificate architecture that could let web servers present lighter certificates to browsers while supporting a more streamlined authentication handshake. While this remains an emerging area, it highlights that the transition to PQC is not simply a matter of replacing existing algorithms. It will also require organisations to rethink how they design and manage certificates, authentication mechanisms, and the broader digital trust infrastructure. By early 2027, we expect public MTCs to be available. At the same time, root store policies will require MTCs to operate on a monthly or shorter renewal cadence, strengthening the case for CLM.

Sectigo is contributing to research and industry working groups in this area because we believe that preparing for the post-quantum era requires collaboration and collective innovation across the broader cybersecurity and digital trust ecosystem.

CISO Forum: As enterprises increasingly deploy autonomous AI agents, are we creating a new category of machine identity that existing IAM and PKI architectures were not designed to handle?

Kevin Weiss: Non-human identities are evolving rapidly, and the growing adoption of AI agents is accelerating this trend. Autonomous AI agents may increasingly interact independently with applications, APIs, systems, and data. That raises a fundamental question: how can organisations establish trust in these interactions and reliably verify which machine or AI agent is making a request?

This is where digital trust becomes increasingly critical. Organisations will need to manage not only human identities, but potentially millions of dynamic machine and AI identities operating across increasingly complex digital environments. Existing identity and PKI architectures will therefore need to evolve to support this scale, while providing the security, authentication, and governance required for increasingly autonomous systems. As AI-driven environments continue to expand, establishing and maintaining trust across machine-to-machine and agent-to-machine interactions will become an increasingly important component of enterprise cybersecurity.

CISO Forum:  Looking ahead, what should CISOs prioritise over the next two to three years to build a resilient digital-trust infrastructure capable of handling shorter certificate lifecycles, post-quantum threats and the rapid growth of machine and AI identities?

Kevin Weiss: CISO’s should prioritise the following:

First, visibility. Organisations need a comprehensive understanding of their certificates, cryptographic assets, and machine identities across the enterprise. Without complete visibility, it becomes difficult to manage risk or establish effective governance.

Second, automation. As certificate lifetimes continue to shorten, manual certificate management is no longer sustainable. Organisations need automated processes to manage certificate lifecycles efficiently, reduce human error, and prevent service disruptions.

Third, crypto-agility. Organisations need to prepare today for the transition to post-quantum cryptography, ensuring they can adopt new cryptographic standards without significant operational disruption.

Fourth, readiness for the growth of machine and AI identities. As autonomous systems and machine identities proliferate, digital trust infrastructure will need to scale beyond traditional human identities while maintaining appropriate levels of security, authentication, and governance.

Ultimately, the organisations best positioned to navigate these changes will move away from fragmented tools and manual processes toward centralised visibility, control, and orchestrated automation. This is at the heart of what we mean by Simplicity at Scale, making digital trust simpler to manage as organisations and their digital environments become increasingly complex.

Author