Nearly one in four organizations say their worst certificate-related outage cost more than 250,000 dollars, up 5 percentage points from a year earlier, according to DigiCert’s Certificate Management Outlook, based on a Propeller Insights survey of 1,001 IT and cybersecurity decision-makers across the US, UK, and Australia and published September 9. More than a third of respondents had a service outage caused by an expired certificate in the past year, nearly three-quarters logged at least five hours of certificate-related downtime, and one in five logged 25 hours or more.

The mismatch driving those numbers: more than half of surveyed organizations now manage over 1,000 certificates, and nearly three-quarters expect that volume to keep growing over the next two years, but only 10 percent have automated certificate management in place. “An expired certificate can shut down a critical service just as quickly as any other infrastructure failure,” said Mike Nelson, DigiCert’s global vice president and field CTO, in the report.

Why it matters for the security leader: certificates are the machine-identity layer zero trust depends on, every service-to-service connection and device authentication assumes the certificate presented is both valid and current. An expired or mismanaged certificate is not a cosmetic outage, it is an identity control silently failing open or closed. The report also flags that public TLS certificate lifespans are shortening toward 47 days by 2029, forcing renewals more than eight times as often as today, turning a problem only 10 percent have automated into one that surfaces eight times more often for everyone else.

The original insight sits in that timing gap: shorter lifecycles are a deliberate push toward better hygiene, reducing the window a compromised key stays valid. But this survey shows most organizations are not automation-ready for the certificate volume they already manage, let alone the faster cadence coming. That is the same patch-adoption gap CyberTech documented in this week’s CISA KEV coverage, applied to identity infrastructure instead of software patching, and reinforces why CyberTech has flagged identity-layer authentication as the recurring weak point attackers and outages alike keep finding.

Source: GlobeNewswire