Opens in a new tab
vmblog logo 2024 wht (updated)

DigiCert Research Finds Certificate Failures Are a Six-Figure Infrastructure Risk

Share: 

David Marshall | Published: September 9, 2026

DigiCert released findings from its global Certificate Management Outlook, showing that certificate incidents are becoming more costly for enterprises. Nearly one in four organizations said their most significant certificate incident cost more than $250,000, up by 5% since last year. 

During the past year, more than one-third of surveyed organizations experienced a service outage caused by an expired certificate. Nearly three-quarters reported at least five hours of certificate-related downtime, while one in five reported 25 hours or more. Long outages can disrupt critical services, stall employee productivity, and erode customer trust. As a result, securing certificates has become a top priority for modern organizations. 

The scale and duration of these outages point to an enterprise resilience challenge that extends beyond the security team, with more than half of respondents classifying certificate outages as infrastructure issues. Automated certificate lifecycle management now ranks third among organizations’ cybersecurity priorities, ahead of simplifying compliance, standardizing IoT security and expanding Zero Trust. Yet implementation has not kept pace, with only 10% reporting they “already have automation in place” when asked about barriers. 

“An expired certificate can shut down a critical service just as quickly as any other infrastructure failure,” said Mike Nelson, Global Vice President, Field CTO at DigiCert. “With certificate lifecycles shrinking to 47 days, spreadsheets and calendar reminders simply won’t scale. Organizations need to know every certificate they have, where it is, who owns it, and then automate the lifecycle before an overlooked expiration becomes a business outage.” 

That pressure will grow as certificate volumes rise and lifecycles shrink. Nearly three-quarters of organizations expect volumes to increase over the next two years, while more than half already manage over 1,000 certificates. From 2029, industry rules will limit public TLS certificates to 47 days and domain validation reuse to 10 days, reducing security exposure by ensuring certificate information is refreshed more frequently. An enterprise managing 1,000 public TLS certificates could therefore face roughly 8,000 certificate issuances and 40,000 domain validations each year. 

Additional findings include: 

  • Thirty percent are still not actively preparing for shorter certificate lifecycles.  
  • Preparation varies by market: 74% of U.S. organizations are actively preparing, compared with 71% in the U.K. and 62% in Australia. 
  • Incompatibility with enterprise legacy technology systems is the leading barrier to automation at 25%, followed by budget constraints at 21%. 
  • 40% experienced service downtime due to certificate mismanagement, and over half are very or extremely concerned about certificate expiration.