During the past year, more than one-third of surveyed organisations experienced a service outage caused by an expired certificate. Nearly three-quarters reported at least five hours of certificate-related downtime, while one in five reported 25 hours or more. Long outages can disrupt critical services, stall employee productivity, and erode customer trust. As a result, securing certificates has become a top priority for modern organisations.
The scale and duration of these outages point to an enterprise resilience challenge that extends beyond the security team, with more than half of respondents classifying certificate outages as infrastructure issues. Automated certificate lifecycle management now ranks third among organisations’ cyber security priorities, ahead of simplifying compliance, standardising IoT security and expanding Zero Trust. Yet implementation has not kept pace, with only 10% reporting they “already have automation in place” when asked about barriers.
“An expired certificate can shut down a critical service just as quickly as any other infrastructure failure,” said Mike Nelson, Global Vice President, Field CTO at Digicert. “With certificate lifecycles shrinking to 47 days, spreadsheets and calendar reminders simply won’t scale. Organisations need to know every certificate they have, where it is, who owns it, and then automate the lifecycle before an overlooked expiration becomes a business outage.”
That pressure will grow as certificate volumes rise and lifecycles shrink. Nearly three-quarters of organisations expect volumes to increase over the next two years, while more than half already manage over 1,000 certificates. From 2029, industry rules will limit public TLS certificates to 47 days and domain validation reuse to 10 days, reducing security exposure by ensuring certificate information is refreshed more frequently. An enterprise managing 1,000 public TLS certificates could therefore face roughly 8,000 certificate issuances and 40,000 domain validations each year.

















