Blog

Certificate Lifecycle Management Business Case

Certificate lifecycle management pays for itself before post-quantum migration. Build the case on renewal volume, outage cost and the 47-day certificate.

Building the investment case for certificate lifecycle management

The case for certificate lifecycle management no longer rests on post-quantum migration. Public TLS certificate lifetimes fall to 47 days by 2029, multiplying renewal volume more than eightfold against a fixed headcount. Automation becomes an operational necessity first and a post-quantum enabler second.

Why certificate lifecycle management is now a funding question

Two independent pressures have converged, and either one alone would justify the investment.

The first is certificate lifetime reduction. CA/Browser Forum ballot SC-081v3, passed in April 2025, sets a staged reduction in the maximum validity of publicly trusted TLS certificates: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029, with domain validation reuse periods tightening in parallel. This is not guidance. It is enforced by browser root programmes, and non-compliant certificates will not be issued.

The second is post-quantum migration. An algorithm change propagates through an estate at the speed of certificate renewal. Where issuance is automated and lifetimes are short, reconfiguring the issuing authority pushes the change across the estate within weeks. Where renewal is manual, the same change requires individual intervention on every endpoint and takes years.

The financial argument is that the first pressure funds the platform and the second is delivered as a consequence.

What drives the cost of manual certificate management

The last row is the one usually omitted, and it is where post-quantum migration enters the model. A manual estate pays the reissuance cost once per algorithm change, and there will be more than one.

How shorter certificate lifetimes change the arithmetic

The reduction schedule converts a manageable annual task into a continuous operation. The table below shows renewal events for an illustrative estate of 5,000 public TLS certificates, calculated from maximum validity alone.

Multiply the right-hand column by your own measured handling time per renewal to produce the labour position. At any handling time, the 2029 figure is roughly eight times the pre-2026 figure, and the table assumes no growth in certificate count, which is rarely the direction of travel.

This is the arithmetic that makes the case, and it does not depend on any view about quantum computing.

How to build the certificate lifecycle management business case

Establish the denominator

Count the certificates. Discovery routinely finds certificates that no register holds, because internal certificate authorities, cloud-native issuance, appliances and self-signed certificates rarely appear in a single place. Where the number is unknown, the first figure in the business case is the discovery finding itself.

Model the labour position across the reduction schedule

Project renewal volume across 2026, 2027 and 2029 using the maximum validity figures above, and multiply by observed handling time. Use your own handling time rather than a benchmark, measured from a sample of recent renewals including the installation and validation steps rather than issuance alone.

Quantify outage exposure

Take actual incidents from the past two to three years where certificate expiry caused disruption. Use the organisation's existing cost-of-downtime figure if one exists for service continuity planning, since it will already have been accepted internally, which avoids relitigating the number.

Add the migration avoidance

Estimate the cost of reissuing the estate manually during a hierarchy or algorithm change, then note that post-quantum migration requires at least one such change before 2031, and that algorithm transitions recur. This converts a one-off saving into a repeating one.

Present it as avoided cost, not new capability

Finance functions respond differently to a platform that prevents a cost increase than to one that adds capability. The reduction schedule is external, dated and non-negotiable, which makes the headcount increase the default outcome and the platform the alternative to it.

Where post-quantum migration enters the case

Post-quantum migration should be the second argument in the paper, not the first. It is less certain in timing, harder to cost and easier to defer, and leading with it invites the response that 2035 is a long way away.

Positioned second, it is straightforward. The NCSC expects highest-priority migration complete by 2031. Migration speed is determined by renewal speed. An estate with automated issuance and short lifetimes propagates an algorithm change through normal renewal; an estate without them cannot. The platform funded on renewal volume delivers post-quantum readiness as a by-product.

There is also a hard dependency worth stating. Microsoft's ML-DSA support in Active Directory Certificate Services, delivered in the May 2026 update for Windows Server 2025, offers no in-place migration path. A parallel hierarchy must be stood up and endpoints moved to it. Doing that manually across a large estate is a multi-year programme in itself, which is covered further in where PQC support has already shipped

What finance will ask

Three questions come up consistently.

What happens if we do nothing. The answer is a headcount increase proportional to the reduction schedule, an increasing outage probability as renewal volume rises, and a post-quantum migration that cannot be completed by 2031.

Why not hire instead. Because the requirement scales with certificate count and renewal frequency, both of which increase, so headcount must increase again in 2027 and 2029. Automation cost does not scale in the same way.

What is the return period. In estates of a few thousand certificates or more, the labour arithmetic alone typically supports the investment within the reduction schedule. Outage avoidance and migration cost shorten it further but are less predictable, so they are better presented as additional rather than as the basis.

Licensing structure materially affects the answer and varies considerably between vendors, which is covered separately in how to evaluate CLM vendors and licensing models.

Common objections

We already have a register. A spreadsheet records what someone entered. It does not discover what exists, and it does not renew anything. The gap between the register and the estate is usually the finding that starts the programme.

Our certificate authority includes management tools. Native tooling generally covers certificates issued by that authority. Estates are rarely single-authority, and public, internal, cloud and appliance-issued certificates typically span several.

We will address it when we migrate to post-quantum. The reduction schedule arrives first, in 2026, 2027 and 2029, and the platform is a prerequisite for migrating efficiently rather than a consequence of it.

Our certificates rarely expire unexpectedly. That is a statement about the past at 398-day lifetimes. At 47 days the same processes produce eight times the opportunities for failure.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.

We produce the evidence a business case requires. Discovery through our PKI health check establishes the actual certificate population, including the certificates no register holds. We then model renewal volume against the reduction schedule, assess which platforms fit the estate, and deliver the certificate lifecycle management capability itself.

Because we are vendor-neutral and hold partnerships across the CLM landscape rather than reselling a single product, the platform recommendation follows the estate rather than a quota. If you are at the stage of building the paper, our CLM whitepaper sets out the evaluation criteria in more detail, and we are happy to review a draft business case.

Frequently asked questions

When do 47-day certificates take effect?

15 March 2029, under CA/Browser Forum ballot SC-081v3. The schedule is staged: maximum validity for publicly trusted TLS certificates falls to 200 days on 15 March 2026, 100 days on 15 March 2027 and 47 days on 15 March 2029, with domain validation data reuse periods tightening alongside.

Does certificate lifecycle management only apply to public certificates?

No, and the internal estate is usually larger. The reduction schedule applies to publicly trusted TLS certificates, but internal certificate authorities, device certificates, service accounts and cloud-issued certificates all require the same discovery, issuance and renewal management, and they are where unmanaged certificates concentrate.

How many certificates does a typical organisation have?

More than the register shows. Discovery routinely finds certificates that no central record holds, because internal authorities, appliance-generated certificates, cloud-native issuance and self-signed certificates are rarely captured in one place. The discovery finding itself is often the most persuasive figure in the business case.

How does CLM support post-quantum migration?

An algorithm change propagates at the speed of certificate renewal. With automated issuance and short lifetimes, reconfiguring the issuing authority moves the estate within weeks. Without them, every endpoint requires individual intervention, which is what makes the NCSC's 2031 milestone unachievable for manual estates.

Can we justify CLM without the quantum argument?

Yes, and it is usually the stronger paper. The certificate lifetime reduction schedule is external, dated and enforced by browser root programmes, and it multiplies renewal volume more than eightfold by 2029. That produces a labour and outage case that stands independently of any view on quantum timelines.

What should the business case include?

The actual certificate count from discovery, projected renewal volume across the reduction schedule, measured handling time per renewal, historic outage cost, the cost of manual reissuance during a hierarchy or algorithm change, and licensing structure. Presenting it as avoided cost rather than new capability tends to be more effective.
Author
Unsung Ltd
September 10, 2026
-