DigiCert’s 2026 Global PKI Research Report, independently conducted by Omdia, reveals a significant gap between awareness and operational readiness. Most security leaders understand the risks, but many organisations still lack the visibility, governance and automation required to manage Public Key Infrastructure (PKI) as a critical business capability.

In this article, we explore the report’s key findings and what they mean for organisations preparing for shorter certificate lifetimes, AI-driven trust requirements and the transition to post-quantum cryptography.

The Visibility Gap: You Cannot Protect What You Cannot See

One of the report’s most striking findings is that only 34% of organisations have a complete, up-to-date inventory of all digital certificates. Half report having only a partial inventory, while 16% are unsure how many certificates they have or where they are used.

This lack of visibility creates a serious operational challenge. A single expired certificate can disrupt a business-critical application, yet many organisations cannot confidently identify every certificate, its owner, its expiration date or the services that depend on it.

The concern is already widespread: 73% of respondents are very or extremely concerned about outages caused by expired certificates, while 74% express the same level of concern about certificate sprawl.

For businesses, this is not simply a certificate administration problem. It is a question of service availability, customer trust and operational resilience. Without a reliable inventory, security teams are forced to manage risk based on assumptions rather than evidence.

Certificate Sprawl Is Outgrowing Traditional Management

PKI has evolved far beyond securing public websites. Today, certificates support machine identities, user authentication, Zero Trust initiatives, software signing, connected devices and a growing range of internal services.

The report highlights how this expansion has created both technical and organisational complexity. Many enterprises use multiple certificate management methods simultaneously, including manual tracking, private CA solutions, lifecycle management platforms, custom scripts and IT service management tools.

On average, organisations use two to three different methods at the same time. This fragmented approach makes it difficult to establish consistent policies, assign ownership and maintain a complete view of the certificate landscape.

Spreadsheets may still be familiar and convenient, but they were not designed to manage thousands of certificates across rapidly changing environments. As renewal windows shrink, manual tracking becomes increasingly difficult to scale and more vulnerable to human error.

Shorter Certificate Lifetimes Make Automation Essential

The move towards shorter public TLS certificate lifetimes is accelerating the need for modernisation. The report identifies the industry’s phased transition towards a maximum validity period of 47 days in March 2029.

Shorter lifetimes do not necessarily mean that organisations will have more certificates. They do, however, mean that teams must perform certificate lifecycle tasks more frequently. Processes that were manageable with annual renewals may become unsustainable when certificates must be replaced every few weeks.

This is why automation must extend beyond renewal alone. A certificate that is renewed automatically but still requires manual installation can continue to create outage risk.

A modern certificate lifecycle process should cover discovery, issuance, renewal, deployment, monitoring and replacement. By automating the complete lifecycle, organisations can reduce repetitive work while improving consistency and reducing the likelihood of unexpected expiration.

Modernisation Is Already Delivering Measurable Benefits

The research shows that organisations further along in their PKI modernisation journey are seeing tangible improvements. Among modernised respondents, 64% report automated lifecycle management, 60% cite reduced outages, 44% report better support for regulatory compliance and 43% have gained increased visibility and control.

These findings demonstrate that PKI modernisation is not only about preparing for future threats. It can deliver immediate operational value through fewer disruptions, reduced administrative overhead and more consistent governance.

However, modernisation does not require replacing every system at once. The report recommends a phased approach that prioritises the highest-risk and highest-value certificate use cases first.

For many organisations, public TLS certificates provide a practical starting point because shorter lifetimes create an immediate and measurable need for automation.

AI and Quantum Computing Raise the Stakes

The report also identifies AI and quantum computing as two major forces reshaping digital trust.

As organisations introduce AI agents, models and generated content, they need stronger mechanisms to establish identity, integrity, provenance and authorisation. More than 73% of respondents believe PKI will play a critical role in establishing trust for AI use cases, yet many organisations remain in the initial stages of developing effective governance strategies.

Post-quantum readiness presents a similar challenge. Only 22% of respondents say they have fully assessed their cryptographic libraries and systems for vulnerabilities related to future quantum attacks. A further 36% have completed partial assessments, while 32% plan to do so within the next 12 months.

The transition to post-quantum cryptography will require more than replacing algorithms. Organisations must understand where cryptography is deployed, which systems depend on it and how changes can be introduced without disrupting critical services.

This is where crypto-agility becomes essential: the ability to discover, manage and update cryptographic assets efficiently as requirements evolve. The same foundations that improve certificate management today will also support future AI trust and post-quantum initiatives.

A Practical Roadmap for PKI Modernisation

The report’s findings point towards a clear sequence for organisations looking to strengthen their PKI operations:

  1. Discover and inventory cryptographic assets. Establish a reliable view of certificates across public and private environments, including ownership, expiration dates and business dependencies.
  2. Standardise governance and policies. Define approved certificate authorities, configuration standards, ownership responsibilities and compliance requirements across the organisation.
  3. Automate critical certificate lifecycles. Prioritise high-impact services and implement end-to-end automation for issuance, renewal, installation and monitoring.
  4. Consolidate fragmented management. Reduce unnecessary silos and establish centralised visibility across existing PKI environments.
  5. Build for cryptographic change. Extend inventory and governance to keys, algorithms and cryptographic libraries to support AI trust and post-quantum readiness.

The objective is not to achieve a perfect PKI environment overnight. It is to create a repeatable operating model that reduces risk today while making future change easier to manage.

From Certificate Management to Business Resilience

PKI is no longer infrastructure that can be left running quietly in the background. It is a foundation for secure communication, digital identity and the availability of critical services.

The 2026 research makes the direction clear: organisations that continue to rely on fragmented tools and manual processes will face increasing pressure as certificate lifetimes shorten and cryptographic requirements evolve. Those that invest in visibility, governance and automation will be better positioned to reduce outages, improve operational efficiency and prepare for the next generation of digital trust.

At Excedo, we believe PKI modernisation should begin with a clear understanding of your existing environment and a practical roadmap tailored to your organisation’s needs. Whether you are looking to improve certificate visibility, automate lifecycle management or prepare for crypto-agility, the first step is establishing control over the trust infrastructure your business depends on.

Ready to modernise your PKI? Contact Excedo to discuss how your organisation can reduce certificate-related risk and build a more resilient digital trust foundation.

Source

DigiCert, 2026 Global PKI Research Report: PKI Under Pressure – The Tipping Point for Modernization. Independent research conducted by Omdia in April 2026 among 423 senior IT and security decision-makers from organisations with at least 1,000 employees across North America, EMEA and Asia Pacific.