Certificate Lifecycle Management Business Case
Building the investment case for certificate lifecycle management
The case for certificate lifecycle management no longer rests on post-quantum migration. Public TLS certificate lifetimes fall to 47 days by 2029, multiplying renewal volume more than eightfold against a fixed headcount. Automation becomes an operational necessity first and a post-quantum enabler second.
Why certificate lifecycle management is now a funding question
Two independent pressures have converged, and either one alone would justify the investment.
The first is certificate lifetime reduction. CA/Browser Forum ballot SC-081v3, passed in April 2025, sets a staged reduction in the maximum validity of publicly trusted TLS certificates: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029, with domain validation reuse periods tightening in parallel. This is not guidance. It is enforced by browser root programmes, and non-compliant certificates will not be issued.
The second is post-quantum migration. An algorithm change propagates through an estate at the speed of certificate renewal. Where issuance is automated and lifetimes are short, reconfiguring the issuing authority pushes the change across the estate within weeks. Where renewal is manual, the same change requires individual intervention on every endpoint and takes years.
The financial argument is that the first pressure funds the platform and the second is delivered as a consequence.
What drives the cost of manual certificate management

The last row is the one usually omitted, and it is where post-quantum migration enters the model. A manual estate pays the reissuance cost once per algorithm change, and there will be more than one.
How shorter certificate lifetimes change the arithmetic
The reduction schedule converts a manageable annual task into a continuous operation. The table below shows renewal events for an illustrative estate of 5,000 public TLS certificates, calculated from maximum validity alone.

Multiply the right-hand column by your own measured handling time per renewal to produce the labour position. At any handling time, the 2029 figure is roughly eight times the pre-2026 figure, and the table assumes no growth in certificate count, which is rarely the direction of travel.
This is the arithmetic that makes the case, and it does not depend on any view about quantum computing.
How to build the certificate lifecycle management business case
Establish the denominator
Count the certificates. Discovery routinely finds certificates that no register holds, because internal certificate authorities, cloud-native issuance, appliances and self-signed certificates rarely appear in a single place. Where the number is unknown, the first figure in the business case is the discovery finding itself.
Model the labour position across the reduction schedule
Project renewal volume across 2026, 2027 and 2029 using the maximum validity figures above, and multiply by observed handling time. Use your own handling time rather than a benchmark, measured from a sample of recent renewals including the installation and validation steps rather than issuance alone.
Quantify outage exposure
Take actual incidents from the past two to three years where certificate expiry caused disruption. Use the organisation's existing cost-of-downtime figure if one exists for service continuity planning, since it will already have been accepted internally, which avoids relitigating the number.
Add the migration avoidance
Estimate the cost of reissuing the estate manually during a hierarchy or algorithm change, then note that post-quantum migration requires at least one such change before 2031, and that algorithm transitions recur. This converts a one-off saving into a repeating one.
Present it as avoided cost, not new capability
Finance functions respond differently to a platform that prevents a cost increase than to one that adds capability. The reduction schedule is external, dated and non-negotiable, which makes the headcount increase the default outcome and the platform the alternative to it.
Where post-quantum migration enters the case
Post-quantum migration should be the second argument in the paper, not the first. It is less certain in timing, harder to cost and easier to defer, and leading with it invites the response that 2035 is a long way away.
Positioned second, it is straightforward. The NCSC expects highest-priority migration complete by 2031. Migration speed is determined by renewal speed. An estate with automated issuance and short lifetimes propagates an algorithm change through normal renewal; an estate without them cannot. The platform funded on renewal volume delivers post-quantum readiness as a by-product.
There is also a hard dependency worth stating. Microsoft's ML-DSA support in Active Directory Certificate Services, delivered in the May 2026 update for Windows Server 2025, offers no in-place migration path. A parallel hierarchy must be stood up and endpoints moved to it. Doing that manually across a large estate is a multi-year programme in itself, which is covered further in where PQC support has already shipped
What finance will ask
Three questions come up consistently.
What happens if we do nothing. The answer is a headcount increase proportional to the reduction schedule, an increasing outage probability as renewal volume rises, and a post-quantum migration that cannot be completed by 2031.
Why not hire instead. Because the requirement scales with certificate count and renewal frequency, both of which increase, so headcount must increase again in 2027 and 2029. Automation cost does not scale in the same way.
What is the return period. In estates of a few thousand certificates or more, the labour arithmetic alone typically supports the investment within the reduction schedule. Outage avoidance and migration cost shorten it further but are less predictable, so they are better presented as additional rather than as the basis.
Licensing structure materially affects the answer and varies considerably between vendors, which is covered separately in how to evaluate CLM vendors and licensing models.
Common objections
We already have a register. A spreadsheet records what someone entered. It does not discover what exists, and it does not renew anything. The gap between the register and the estate is usually the finding that starts the programme.
Our certificate authority includes management tools. Native tooling generally covers certificates issued by that authority. Estates are rarely single-authority, and public, internal, cloud and appliance-issued certificates typically span several.
We will address it when we migrate to post-quantum. The reduction schedule arrives first, in 2026, 2027 and 2029, and the platform is a prerequisite for migrating efficiently rather than a consequence of it.
Our certificates rarely expire unexpectedly. That is a statement about the past at 398-day lifetimes. At 47 days the same processes produce eight times the opportunities for failure.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.
We produce the evidence a business case requires. Discovery through our PKI health check establishes the actual certificate population, including the certificates no register holds. We then model renewal volume against the reduction schedule, assess which platforms fit the estate, and deliver the certificate lifecycle management capability itself.
Because we are vendor-neutral and hold partnerships across the CLM landscape rather than reselling a single product, the platform recommendation follows the estate rather than a quota. If you are at the stage of building the paper, our CLM whitepaper sets out the evaluation criteria in more detail, and we are happy to review a draft business case.
Frequently asked questions
When do 47-day certificates take effect?
Does certificate lifecycle management only apply to public certificates?
How many certificates does a typical organisation have?
How does CLM support post-quantum migration?
Can we justify CLM without the quantum argument?
What should the business case include?


