Security & Compliance / Certificate Lifecycle Management
Certificate Lifecycle Management — Discovery, Automation & Short-Lifetime Readiness
Public TLS certificate lifetimes are contracting on a fixed industry schedule, falling to 100 days in March 2027 and 47 days in March 2029. Any estate still renewing certificates by hand, by calendar reminder, or by tribal knowledge is heading for an outage that will not announce itself in advance.
Renewal has to become a process, not an act of heroism.
Shorter lifetimes multiply renewal events several times over. The fix is not a bigger spreadsheet: it is knowing every certificate you hold, automating issuance and renewal where the platform allows it, and giving each certificate a named owner and a tested failure path. We design that operating model and the engineering underneath it, then hand it to the team that has to run it.
Discovery and ownership
Build a complete certificate inventory across public and internal estates, including load balancers, appliances, service accounts, and the certificates embedded in applications nobody owns any more.
Issuance and renewal automation
Automate issuance and renewal using ACME, auto-enrolment, SCEP and NDES, or platform-native integrations, with the same infrastructure-as-code discipline applied to the rest of the estate.
Monitoring and handover
Wire expiry monitoring and alerting into the tooling your operations team already uses, with runbooks, escalation paths, and a tested response for the renewal that fails at three in the morning.
Anonymised delivery evidence.
- For an NHS body, expedited the build of a Windows Server 2022 two-node certificate authority ahead of imminent root authority expiry, then documented renewal planning and certificate lifecycle handover for internal teams.
- For a global availability and disaster-recovery services provider, automated Windows and Linux patching across a managed estate spanning 22 datacentres, achieving 96% patching success — the same automation discipline that short certificate lifetimes now demand.
- Within a NATO-classified environment, resolved blocking certificate-services issues on a major messaging platform upgrade, then documented the implementation and trained internal support teams to run it.
Best fit.
This service suits any organisation with more TLS certificates than it can confidently list: NHS trusts, central government and arm’s-length bodies, financial services, and MSPs managing certificates on behalf of customers. It pairs naturally with PKI and certificate services, post-quantum cryptography readiness, and monitoring and observability.
