As certificate volumes mushroom, so do their risks and the potential for outages 

Blog· 4min August 13, 2026

Form3’s new Trust Fabric offering supports firms to manage their certificate estate, maintain visibility, automate renewals and mitigate the risk of expired or unknown certificates bringing down a whole service. 

Expired TLS certificates have long been a frustrating cause of IT outages. And with the growing use of cloud-native architectures, the number of certificates any one organisation needs to manage has mushroomed. 

Large organisations routinely operate tens or even hundreds of thousands of certificates across distributed environments. Recent Keyfactor research found that 86% of organisations experienced at least one outage or disruption caused by expired or mismanaged certificates during the previous year. 

The certificate challenge is shifting 

That statistic is striking because it comes at a time when public certificate management has never been more automated. This suggests that the industry's centre of gravity has shifted. The remaining challenges are increasingly associated with incomplete certificate discovery, internal PKI, service-to-service mutual TLS, fragmented ownership and automation gaps rather than internet-facing web certificates. 

In other words, organisations have become much better at issuing certificates than they have at understanding them, and the industry needs to prioritise certificate visibility to avoid unknown risks. 

Shorter certificate lifespans increase the pressure 

Coupled with the fact that certificate lifespans are getting shorter, managing a certificate estate manually has become increasingly difficult. 

The CA/Browser Forum has approved a roadmap that progressively reduces the maximum lifetime of publicly trusted TLS certificates. The previous 398-day maximum fell to 200 days on 15 March 2026, will fall to 100 days in March 2027 and ultimately to just 47 days in March 2029.  

Of course, shorter lifespans have security benefits, but they create a growing operational burden. Relying on spreadsheets and calendar reminders just isn’t enough anymore. Left unmanaged, an organisation can lose track of how many certificates it has, as well as which ones need to be renewed and when, resulting in outages that are not only frustrating but can have a lasting impact on reputation. 

Preparing for the quantum era 

On top of all of this, the cryptographic landscape is evolving as quantum computing progresses. Many of the cryptographic algorithms in use today are not considered quantum-safe. Although quantum computers are not currently capable of breaking widely deployed public-key cryptography at scale, organisations are increasingly preparing for the risk that encrypted data captured today could potentially be decrypted in the future as quantum capabilities advance. 

This creates an even greater need for visibility across certificate estates, helping IT teams understand which cryptographic algorithms are in use and where certificates may need to be updated as organisations transition towards post-quantum cryptography. 

Visibility is the foundation of certificate management 

This visibility is the foundation of automated certificate management. Organisations first need comprehensive visibility across their certificates and dependencies so that they can automate their upkeep with confidence. 

Trust Fabric was built to address exactly this challenge. 

By continuously discovering certificates across hybrid and cloud-native environments, analysing dependencies and identifying lifecycle risks, it supports organisations to move beyond reactive certificate renewal towards proactive machine identity management.  

Getting ahead of mounting certificate risks is the best way for organisations to confidently tackle them and future-proof their operations. 

Written by

github-icon
Gareth Hobson Sales Director, Trust Fabric