How will 47-day certificate policies transform critical infrastructure management?

"As systems become more connected and automated, the challenge is taking control of the growing complexity underpinning them."

Share
How will 47-day certificate policies transform critical infrastructure management?

The move towards 47-day TLS (Transport Layer Security) certificate lifecycles represents one of the most significant operational changes organisations have faced in years.

Today, many organisations renew certificates roughly once a year. Under the new rules, that window will shrink dramatically.

While the security benefits are clear, the operational implications are significant. Tasks that were previously performed a handful of times each year may soon need to happen every few weeks, often across thousands of systems and services.

Many organisations still rely on legacy technology and processes to perform these tasks. This legacy tech has become outdated, better suited for a time when systems were less interconnected and digital assets were easier to track. This is no longer the reality for organisations. 

The challenge is already visible and recent research has found that only 34% of organisations have a complete and current view of their digital certificates, while nearly three-quarters are concerned about outages caused by expired certificates. Without a clear understanding of critical digital assets and dependencies, reducing risk becomes significantly more difficult.

Critical considerations

This challenge becomes particularly important in critical environments, where digital certificates form part of a much wider network of dependencies supporting essential systems and services. As certificate lifecycles shorten, organisations will need to understand not only where certificates are deployed, but how the systems relying on them connect to the wider infrastructure.

When people think about critical infrastructure, they typically think about power grids or healthcare systems. But the resilience of these environments depends on digital infrastructure operating reliably behind the scenes. Every connected device, automated process and online service relies on a growing web of digital dependencies that most users never see.

When those systems operate as expected, they remain largely invisible. When they fail, the consequences can be immediate, affecting productivity and operational continuity, which directly impacts revenue.

As critical systems become more connected and automated, organisations are discovering that the challenge now is managing the growing complexity underpinning infrastructure.

Hidden dependencies create hidden risks

Operational risk often resides in hidden places organisations rarely think about.

DNS (Domain Name System) provides a good example. It is often viewed as a networking function, yet it sits behind much of the modern digital economy.

Every online transaction and connected service depends on users and systems being able to reliably find and connect to the resources they need.

READ MORE: The Gunra ransomware gang is targeting critical infrastructure worldwide, CISA warns

When DNS is unavailable, organisations can quickly lose access to business-critical applications. The same principle applies across many of the digital services that underpin critical operations.

When responsibilities are spread across multiple teams and systems, understanding dependencies becomes more difficult and operational complexity increases.

This has significant implications for wider business teams as well as security teams. The resulting complexity consumes resources and slows decision-making, increasing the likelihood of service disruption at precisely the moment organisations are becoming more dependent on digital systems.

The business case for modernisation

For many organisations, the challenge extends beyond operational efficiency. Operators of critical infrastructure are increasingly being asked to improve resilience, reduce operational burden and demonstrate greater control over how critical services and data are managed.

For example, data sovereignty is becoming a strategic consideration rather than a technical preference. Regulators are placing greater emphasis on accountability, while customers increasingly expect critical services and sensitive data to remain governed in line with local requirements.

At the same time, shorter certificate lifecycles are exposing the limitations of manual management.

READ MORE: "Savants in the network": Why AI agents don’t need to go rogue to become dangerous

Teams spend more time tracking assets, managing renewals and responding to avoidable issues, creating operational overhead that grows alongside the environment itself and leaving less time for innovation and strategic initiatives.

The organisations making the most progress are the ones actively reducing dependence on manual intervention by simplifying operations and improving consistency across critical systems.

The results are already being seen across the sector with fewer service disruptions and overall better use of resources, allowing for greater confidence and a sense of resiliency across critical services. 

Building resilience into the systems that matter most

The move to 47-day certificates is not creating a new challenge, but it is highlighting an existing one.

The reality is that too many organisations are depending upon digital infrastructure, which can no longer be managed through legacy processes and fragmented systems.  Therefore, organisations best positioned for the future will be those that reduce operational complexity, strengthen resilience and ensure critical systems can continue supporting the services, customers and revenue streams that depend on them.

In an increasingly connected world, resilience depends not only on the systems we can see, but also on our ability to manage the digital foundations behind them.

Paul Holt is Group Vice President, EMEA, at DigiCert

Follow Machine on LinkedIn