← Knowledge areas
Knowledge area 05 · Trust infrastructure

PKI &
Certificates

Certificates are operational dependencies on identity, trust, cryptographic keys, issuing authorities and lifecycle processes.

PKI resilience means knowing where certificates are used, who owns them, what trust and key dependencies sit behind them, and how quickly trust can be changed safely when something goes wrong.

Last reviewed: August 2026

A small certificate can sit on a critical dependency path.

Certificates support websites, APIs, machine identities, VPNs, devices, code signing, user authentication and internal service trust. Failure can affect confidentiality, integrity, authentication and availability.

The risk question is therefore not only whether a certificate is valid today, but whether the organisation understands and controls the service, private key, CA, trust chain and lifecycle process behind it.

Follow the trust dependency across its lifecycle.

01Business serviceWhat relies on trusted identity, communication or signing?
02EndpointWhich server, client, device, workload or signing service consumes it?
03CertificateIdentity, public key, usage, issuer, validity and algorithm.
04Private keyHow is the corresponding sensitive key protected?
05CA & trust chainWhich issuers, roots and trust stores are required?
06Lifecycle processIssuance, deployment, renewal, revocation, replacement and retirement.
Risk lens

A certificate inventory is decision-useful when it shows not only what expires, but what fails, who owns it and how trust can be restored.

Expiry is only the most visible failure mode.

AVAILABILITY

Unexpected expiry

Renewal or deployment failure disrupts a critical dependency.

KEY

Private-key compromise

Trust may require rapid revocation and replacement.

VISIBILITY

Unknown certificates

Unmanaged issuance or forgotten systems evade monitoring and governance.

TRUST

CA dependency

Critical services depend on issuers or trust stores that may sit outside direct control.

CONFIGURATION

Weak profile

Purpose, algorithms, key protection or trust settings diverge from standards.

CHANGE

Difficult replacement

Legacy systems, pinning, embedded stores or manual processes make change risky.

Trust lifecycle is visible, owned and testable.

Inventory coverageCritical certificates link to purpose, owner, issuer, expiry and consuming services.
Lifecycle ownershipRequest, renewal, deployment, revocation and emergency replacement have accountable owners.
Renewal controlsMonitoring, lead times and automation are proportionate to scale and criticality.
Private-key protectionStorage and access reflect key sensitivity and compromise scenarios.
Trust-chain visibilityIssuers, roots, external providers and material trust-store dependencies are known.
Resilience testingCritical renewal, CA change, revocation and replacement processes are exercised.

Manage the trust dependency, not only the expiry date.

Prioritise critical certificatesConnect certificate inventory to services and business impact.
Validate ownershipMake renewal and emergency replacement responsibilities explicit.
Map trust chainsIdentify CA, root, key and external-provider dependencies.
Test changeExercise renewal, revocation and emergency replacement for critical services.
Prepare for algorithm transitionIdentify systems and suppliers that constrain certificate profile or key-type change.

PQC reaches PKI through signatures, keys, certificates and trust ecosystems.

Post-quantum transition affects public-key mechanisms used for signatures and key establishment and may require changes across credential formats, software, trust infrastructure and interoperability.

PKI readiness is therefore a migration and ecosystem question, not simply a new certificate algorithm.

Further reading

Previous knowledge area← Crypto-AgilityNext knowledge areaKey Management →