Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Is Your PKI Healthy?

Healthy PKI

In this discussion, we are trying to understand a few of the following questions: What is PKI? What are several components involved in Public Key Infrastructure (PKI)? Most importantly, what are the key factors that can be leveraged to perform a PKI health check? Health checks with appropriate deciding factors are critical for ensuring the health of a Public Key Infrastructure. Let’s dive into the topic:

Quick Answer: Is Your PKI Healthy?

A healthy PKI has six things in order: tracked certificate validity, verified certificate integrity, documented issuance policy, mapped certificate endpoints, adequate encryption key size, and a current encryption algorithm. If any of these six factors go untracked, certificates can expire, weaken, or be issued outside policy without anyone noticing until an outage or audit finding forces the issue.

Executive Summary

PKI health is not a one-time setup task; it requires ongoing monitoring of six factors: certificate validity, certificate integrity, certificate issuance policy, certificate endpoints, encryption key size, and encryption algorithm strength. Firms that skip regular PKI health checks risk expired or weak certificates going undetected until they cause an outage, a failed audit, or a security incident. This post covers the six key factors that decide PKI health, a risk matrix mapping each factor to likelihood, impact, and compliance controls, an audit evidence checklist, and a practical remediation checklist for closing gaps.

Who Should Care About PKI Health

PKI health checks are not just a PKI-team exercise; the six factors below touch security, compliance, and platform ownership. Here is what each role should do.

PKI Administrators

Maintain a current certificate inventory, track key sizes and hashing algorithms in use, and lead the annual CA audit and health check cycle.

Security Architects

Set minimum standards for key size and hashing algorithm, and design the architecture that keeps certificate issuance policy enforced consistently across every issuing CA.

Platform Teams

Maintain the certificate-to-endpoint mapping so no certificate renewal or revocation leaves an endpoint exposed or misconfigured.

Compliance Teams

Map each PKI health factor to the relevant compliance control, collect audit evidence on a defined cadence, and confirm the annual CA audit is completed and documented.

CISOs

Treat PKI health as a board-reportable risk metric, sponsor investment in certificate lifecycle automation, and ensure PKI health checks happen at least annually, not only after an incident.

Why This Matters: Data and Deadlines

According to DigiCert’s Trust Pulse Survey (July 2, 2025), nearly half of enterprises experienced a certificate-related outage in the past year, and 18.5% of affected organizations reported losses exceeding $250,000, with 37.5% of those incidents tied specifically to expired certificates. Every one of these outages traces back to at least one of the six PKI health factors going untracked.

The CA/Browser Forum’s Ballot SC-081v3, approved April 11, 2025, phases maximum public TLS certificate validity down to 200 days starting March 15, 2026, 100 days starting March 15, 2027, and 47 days starting March 15, 2029. Shorter validity periods make certificate validity tracking one of the six health factors substantially more urgent, since manual tracking that tolerated a one-year certificate lifecycle will not scale to a 47-day one.

NIST finalized its post-quantum cryptography standards FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) on August 13, 2024. Encryption algorithm health, another of the six factors, now also includes tracking whether current algorithms and key sizes have a viable migration path to PQC-ready alternatives.

What is Public Key Infrastructure – PKI?

PKI, or Public Key Infrastructure, is a cybersecurity technology framework that protects client – server communications. Certificates are used for authenticating the communication between client and server. PKI also uses X.509 certificates and Public keys for providing end-to-end encryption. In this way, both server and client can ensure trust in each other and check their authenticity to prove the integrity of the transaction. With the increase in digital transformation across the globe, it is highly critical to use Public Key Infrastructure for ensuring safe and secure transactions. PKI has vast use cases across several sectors and industries, including Medical and Finance.

What are important components in a Public Key Infrastructure?

There are three key components to a PKI: Digital Certificates, Certificate Authority, and Registration Authority. PKIs can protect the environment using these three critical components. These components play a crucial role in protecting and securing digital communications and electronic transactions.

  • Digital Certificates: The most critical component in a Public Key Infrastructure (PKI) is Digital certificates. These certificates are used to validate and identify the connections between server and client. This way, the connections formed are very secure and can be trusted. Certificates can be created individually depending on the scale of operations. If the requirement is for a large firm, PKI digital certificates can be purchased from trusted third-party issuers. These are the reasons why PKI certificate management is so vital.
  • Certificate Authority: A Certificate Authority (CA) provides authentication and safeguards the certificates used by the users. Whether it is individual computer systems or servers, the Certificate Authority ensures the digital identities of the users are authenticated. Digital certificates issued through certificate authorities are trusted by devices.
  • Registration Authority: The Registration Authority (RA) is an approved component by the Certificate Authority for issuing certificates for authenticated user-based requests. RA certificate requests range from individual digital certificates to signed email messages to companies planning to set up their own private Certificate Authority. The RA sends all the approved requests to the CA for certificate processing.

Why should firms worry about PKI Health?

A Public Key Infrastructure is not a one-time setup-and-forget activity. Regular health monitoring is as important as the initial implementation of your PKI, as it plays a crucial and deciding role in the firm’s cybersecurity. PKI Health monitoring and checking activity will ensure that a steady state of operations is achieved. The majority of certificate policies state that an audit has to be performed on a regular basis to safeguard the compliance of the Certificate Authorities (CAs). It is highly advisable to perform a complete check once a year, at least. 

Public Key Infrastructure health checks involve multiple steps and factors. Out of all these, some of the important processes that are included in a standard PKI health check are:

  • Patch management and backup.
  • Certificate checks: Issuing and revoking of certificates.
  • Auditing of the Certificate Authority

Six Key Factors / Indicators that decide PKI Health

Public key infrastructures, or PKIs, have been around for a considerable amount of time. Most businesses are well aware of their benefits and capabilities by now. However, due to ever-growing cyber threats, it’s important to continually check for major signs of vulnerabilities. It’s important to do an analysis and fix the areas where a fix is needed. This early analysis is a proactive and vigilant measure that significantly reduces the risk of any cyber-attack. If it is passed over without giving it due attention, it may result in a loss of customer data or regulatory penalties.

To ensure PKI health, we have noted six factors that should be observed during the early stages.

  • Certificate Validity – All digital certificates have expiry dates. For security reasons, it is unwise to reuse the same digital certificate for a long duration of time without any oversight. If the expiry date is not documented and tracked in an orderly fashion, then the chance of a breach increases. An expired digital certificate provides no security at all.
    A good practice is to document the certificate lifecycle of each digital certificate in use and keep it updated. Along with this, ensuring you have strong PKI certificate management processes in place is also extremely important. This process can also be automated with the help of various certificate management tools. Early notification can also be configured; that way, all stakeholders are notified before the issuance or renewal of a certificate.
  • Certificate Integrity – To convince customers or potential customers to transact or share information over the Internet, trust must first be established. One way to do that technically is by using a proper Certificate Authority. These are entities that verify the authenticity of a web-based service or product. Certificate Authorities prevent phishing attempts since they verify SSL/TLS certificates. Digital certificates, which are verified by some known Certificate Authority, are considered safe, and many modern browsers and tools help identify that.
    All stakeholders who are associated with the issuance of digital certificates should ensure that the certificates have all the parameters that are required to get them verified by the CA. The process should also be documented, with a clear depiction of association and accountability. This helps in various situations such as seamless renewal of an expired certificate, replacing a corrupted certificate, tracking a compromised certificate in a security event, and taking required preventative actions.
  • Certificate Issuance Policy – A Certificate Authority can impose certain restrictions during the issuance of a certificate. There can be varied restrictions such as restricting or forcing allowed X.509 values, restricting allowed subject fields or allowed issuance modes, etc.
    If these are kept in check, then backtracking and troubleshooting become much easier. The stakeholders should be responsible for tracking all issuance policies associated with each certificate.
  • Certificate Endpoints – SSL certificates can be added to endpoints. Sometimes one digital certificate can be associated with multiple endpoints. In such cases, it is important to track it. Hence, each one is updated in scenarios. Like, if the certificate is expired and renewed. These endpoints can become vulnerable and exposed if not tracked appropriately.
  • Encryption Key Size – The size of the encryption key is correlated and proportional to key strength. Keys such as RSA 4096 provide high security and assurance because of their larger size, which makes brute force attacks very difficult.
    It is important to check for any key that is used that has a small bit size and is therefore weaker. For better PKI health, all existing weak keys should be replaced with stronger ones.
  • Encryption Algorithm – A healthy PKI should always contain a strong and robust hashing algorithm. Algorithms keep on getting updated over time to become stronger and swifter. For example, SHA256 is much more secure than, say, SHA1. Stakeholders should keep track of what algorithm is being used and if that is the industry standard or not. In the case that any stable update is available, it is better to replace the outdated algorithm.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

PKI Health Risk Matrix

RiskLikelihoodImpactDetection MethodMitigationControl MappingEvidence
Expired certificate goes undetectedMediumHighCertificate expiry monitoring dashboardAutomate renewal and expiry alertingSOC 2 CC6.1, ISO 27001 A.8.24Expiry monitoring logs, alert history
CA private key weak or compromisedLowCriticalHSM audit logs, key ceremony recordsStore CA keys in FIPS 140-2 Level 3 HSMNIST SP 800-57, PCI DSS Requirement 3HSM configuration and access audit trail
Outdated hashing algorithm still in useMediumHighCertificate algorithm inventory scanMigrate to SHA-256 or strongerCA/Browser Forum Baseline RequirementsAlgorithm inventory scan report
Untracked certificate-to-endpoint mappingHighMediumCertificate discovery scanMaintain a current endpoint-to-certificate inventoryISO 27001 A.8.9Discovery scan report
Missing or overdue CA auditMediumHighAnnual CA audit schedule reviewComplete WebTrust/ETSI audit on scheduleWebTrust for CAs, ETSI EN 319 411Signed audit report

Compliance Mapping

PKI Health FactorRelevant FrameworkRequirement
Certificate ValiditySOC 2 CC6.1Timely identification and remediation of expiring credentials
Certificate IntegrityISO 27001 A.8.24Use of cryptography to protect confidentiality and integrity
Certificate Issuance PolicyCA/Browser Forum Baseline RequirementsDocumented certificate policy and issuance controls
Encryption Key SizeNIST SP 800-57Minimum key length and algorithm strength guidance
Encryption AlgorithmPCI DSS Requirement 3Use of strong cryptography for stored and transmitted data

Audit Evidence Checklist

ControlEvidence to CollectFrequency
Certificate inventoryFull list of active certificates with owners and expiry datesContinuous, reviewed quarterly
CA key protectionHSM configuration and access logsAnnual
Algorithm complianceScan report of hashing and key algorithms in useQuarterly
CA auditWebTrust or ETSI audit reportAnnual
Endpoint mappingCertificate-to-endpoint inventoryQuarterly

Incident Examples

The most common PKI health failures share a pattern: a certificate expires unnoticed and takes down a customer-facing service or internal integration, a legacy system is found still using a deprecated hashing algorithm during an audit, or a certificate is discovered on an endpoint that no longer appears in any inventory. Per DigiCert’s Trust Pulse Survey (July 2, 2025), certificate-related outages are common enough that nearly half of enterprises reported experiencing one in the prior year, and over a third of those outages were specifically tied to expired certificates, underscoring that these are not edge cases but a recurring, measurable risk category.

Remediation Checklist

  1. Build a complete, current inventory of all certificates, including owner, expiry date, key size, and hashing algorithm.
  2. Automate expiry alerting so renewal happens before any certificate lapses.
  3. Confirm CA private keys are protected in a FIPS 140-2 Level 3 HSM, not software-based key storage.
  4. Scan for and replace any certificate using a deprecated hashing algorithm or undersized key.
  5. Map every certificate to its endpoints so renewals and revocations do not leave anything exposed.
  6. Schedule and complete the annual CA audit (WebTrust or ETSI), and retain the signed report as evidence.
  7. Review certificate issuance policy for consistency across every issuing CA in use.

How will PKI health checks benefit firms?

  • Performing regular PKI health checks will ensure a strong overall cybersecurity posture for the organization.
  • Operational effectiveness will be monitored on a regular basis by performing PKI health checking activity regularly.
  • Compliance with regulatory standards and frameworks will be ensured as there are periodic checks on certificate health.
  • Threat vectors of data loss will be reduced considerably with a reduction in risk.
    High availability of critical processes will ensure smooth running of the business.

Encryption Consulting’s Managed PKI’s

Encryption Consulting LLC (EC) will completely offload the Public Key Infrastructure environment, which means EC will take care of building the PKI infrastructure to lead and manage the PKI environment (on-premises, PKI in the cloud, cloud-based hybrid PKI infrastructure) of your organization.

Encryption Consulting will deploy and support your PKI using a fully developed and tested set of procedures and audited processes. Admin rights to your Active Directory will not be required and control over your PKI and its associated business processes will always remain with you. Furthermore, for security reasons the CA keys will be held in FIPS 140-2 Level 3 HSMs hosted either in in your secure datacentre or in our Encryption Consulting datacentre in Dallas, Texas. 

Certificate Lifecycle Management and PKI Modernization

The six PKI health factors above are ultimately a certificate lifecycle management problem. CertSecure Manager automates certificate discovery, tracks validity, key size, and algorithm across the entire certificate inventory, and closes the gap between a manual annual health check and continuous PKI health monitoring.

Organizations without the internal resources to run a fully managed PKI can rely on PKI-as-a-Service for cloud-hosted PKI modernization with built-in health monitoring. Before the next health check cycle, it is worth building a complete machine identity inventory through CBOM Secure and completing a PQC readiness assessment, so certificate discovery for PKI health also builds crypto agility for the post-quantum transition. Encryption Consulting’s PQC Center of Excellence provides guidance on sequencing these initiatives together.

For more on why certificate automation matters across the environment, see our Education Center articles on the stages in a certificate’s lifecycle and how to avoid certificate outages.

Measuring Success and Ongoing Audits

Track the number of certificates with fewer than 30 days until expiry that lack a scheduled renewal, the count of certificates using deprecated algorithms or undersized keys, and whether the annual CA audit was completed on schedule. Audit the certificate inventory, HSM access logs, and endpoint mapping on a recurring basis, quarterly for policy and vendor-dependent factors, and continuously for certificate expiry to keep PKI health checks from becoming a once-a-year fire drill.

Frequently Asked Questions

What is the main takeaway from Is Your PKI Healthy?

PKI health depends on six ongoing factors: certificate validity, certificate integrity, issuance policy, endpoint mapping, key size, and algorithm strength. Firms that don’t monitor these continuously risk expired or weak certificates going undetected until they cause an outage or audit failure.

Why does this matter for enterprise PKI teams?

PKI teams are directly accountable for certificate inventory, CA key protection, and algorithm currency. A single untracked factor across any of the six can cause a service outage or a failed compliance audit.

What risks increase if this topic is handled manually?

Manual tracking of certificate validity, endpoints, and algorithms increases the risk of missed expirations, undetected weak keys, and incomplete endpoint mapping, especially as certificate validity periods shorten under the CA/Browser Forum’s phased schedule.

Which teams should own this change?

PKI administrators own the certificate inventory and audit cycle, security architects set key size and algorithm standards, platform teams maintain endpoint mapping, and compliance teams collect audit evidence against relevant frameworks.

How does this connect to certificate lifecycle management?

PKI health is essentially certificate lifecycle management measured continuously rather than checked once a year. Automating discovery, validity tracking, and algorithm scanning turns an annual health check into ongoing PKI health monitoring.

How should organizations measure success?

Track certificates nearing expiry without a scheduled renewal, certificates using deprecated algorithms or undersized keys, and whether the annual CA audit was completed on schedule.

What should be audited or monitored regularly?

Regularly audit the certificate inventory, HSM access and configuration logs, algorithm and key-size compliance scans, and the certificate-to-endpoint mapping.

How does this topic affect cloud, hybrid, or multi-CA PKI?

Organizations with hybrid or multi-CA PKI need the same six health factors tracked consistently across every issuing CA and environment, which requires centralized certificate discovery rather than per-CA manual tracking.

What common mistakes should teams avoid?

Common mistakes include treating PKI health checks as a one-time or annual-only exercise, failing to track certificates to their endpoints, and leaving deprecated hashing algorithms or undersized keys in place after they are identified.

What should be refreshed quarterly?

Review the certificate inventory for new or decommissioned certificates, re-scan for deprecated algorithms and undersized keys, and confirm certificate-to-endpoint mapping is still accurate.