Manage
Certificate management is an operating capability, not an annual project.
Eight stages run continuously. Each one has signals that prove it works — and an anti-pattern that lets it look healthy while it fails.
Practices
- Scan externally and internally, then reconcile against Certificate Transparency
- Query CA accounts, load balancers, cloud services and secret stores directly
- Treat every discovery run as a diff, not a snapshot
Signals it works
- Network scan coverage
- CT log matches for your domains
- Unclaimed certificates per month
Anti-pattern
A one-off spreadsheet audit that is stale the week it is finished.
Usually owned by: PKI
Sequencing
If you can only do one thing this quarter
No inventory yet
Do discovery and ownership. Everything downstream is guesswork until certificates have owners.
Inventory exists, renewals are manual
Automate issuance and deployment together. Half-automated renewal is the most common outage cause.
Automation is in place
Rehearse mass replacement and start crypto-agility work. Both are tested only under pressure otherwise.