Opens in a new tab
vmblog logo 2024 wht (updated)

Keyfactor CSO Chris Hickman on Post-Quantum Readiness and 47-Day Certificates at RSAC 2025

Share: 

David Marshall | Published: April 23, 2025

The RSA Conference (RSAC), the premier cybersecurity industry event, returns to San Francisco’s Moscone Center April 28-May 1, 2025, bringing together thousands of security professionals, vendors, and thought leaders from across the globe. This annual gathering serves as the definitive forum for the latest cybersecurity innovations, trends, and best practices, featuring hundreds of educational sessions, keynotes from industry luminaries, and an expansive expo floor showcasing cutting-edge security solutions. For organizations navigating today’s complex threat landscape, RSAC provides unparalleled networking opportunities, hands-on training, and essential insights to help bolster defense strategies against evolving cyber threats.

As organizations face growing machine identity challenges, the cybersecurity landscape continues to evolve with shorter certificate lifespans and the looming threat of quantum computing.

In this exclusive VMblog pre-show Q&A, Chris Hickman, Chief Security Officer at Keyfactor, discusses how the company is helping businesses establish and maintain digital trust at scale through its PKI and certificate lifecycle management solutions.

Ahead of RSA Conference 2025, Hickman shares insights on recent PKI incidents, previews new PQC-ready product features, and explains why quantum-safe preparations can’t wait. Visit Keyfactor at Booth S-748 to learn how to navigate the post-quantum future and prevent costly certificate outages in an increasingly machine-driven world.

++

VMblog:  Give VMblog readers a quick overview of your company and its core mission in the cybersecurity space.

Chris Hickman:  Keyfactor prioritizes digital trust for every machine and human. By simplifying public key infrastructure (PKI), automating certificate lifecycle management, and securing every device, workload, and thing, Keyfactor helps organizations move fast to establish digital trust at scale – and then maintain it. Keyfactor’s mission is to create a hyper-connected world where every device, workload, and digital interaction is trusted and secure.

VMblog:  Where can attendees find you at RSA 2025? What’s your booth number, and what kind of experience can visitors expect when they stop by?

Hickman:  RSACTM Conference attendees can step into the future of digital trust with Keyfactor at Booth S-748. Each day, we will have multiple insightful presentations from Keyfactor experts and partners on everything from navigating 47-day TLS certificates to transitioning to post-quantum cryptography. Attendees can also learn more about how Keyfactor can help their organization modernize PKI to ensure quantum readiness, stop costly and disruptive certificate outages, securely sign code and containerized applications, and prepare for the post-quantum future with forward-thinking security solutions. At the booth, attendees have a chance to win a Nintendo Switch, Apple Watch, or Bose QuietComfort Headphones.

VMblog:  What were your key learnings from 2024’s security landscape, and how have those insights shaped your solutions for 2025?

Hickman:  In 2024, we saw that businesses are still struggling to properly manage and secure the machine identities across their organizations. The industry experienced several major PKI incidents, including Google’s move to distrust Entrust digital certificates, DigiCert’s revocation of improperly validated certificates, and significant certificate outages at the Bank of England and ServiceNow. These events have reinforced the critical importance of managing and securing digital certificates in today’s digital environment.

Looking ahead to 2025, it is essential to learn from these incidents while preparing for even greater shifts in identity management. The CA/Browser Forum recently voted to shorten certificate lifespans from 398 days to just 47 days by 2029. At the same time, the rise of post-quantum cryptography (PQC) is accelerating, with NIST’s published timeline calling for traditional certificates to be deprecated by 2030 and fully disallowed by 2035. To stay ahead, businesses will need to prioritize crypto-agility and adopt solutions built for the evolving machine identity landscape.

VMblog:  Can you share any exclusive previews or announcements that attendees can expect to see at your booth this year?

Hickman:  This year, to help businesses take actionable steps in their PQC transition and ensure crypto-agility, Keyfactor will introduce new features and updates to its industry-leading PKI and cryptographic solutions, including:

  • Keyfactor Command 25.1: Commandwill enable customers to inventory all PQC certificates, the critical first step in the PQC transition. Customers can also issue, enroll, and automate hybrid RSA/ML-DSA certificates, bringing full life cycle automation to PQC adoption.
  • Keyfactor EJBCA 9.3: EJBCA, which already supports NIST-standardized PQC algorithms, will soon enable hardware security module (HSM) support for secure testing of PQC technologies and issuance of SLH-DSA algorithm and PQC certificates.
  • Bouncy Castle 1.80 Java: As the cryptographic library that serves as the foundation for some of the world’s largest technology platforms, including Keyfactor’s solutions, Bouncy Castle continues to integrate new PQC algorithms as they are standardized, ensuring cryptographic agility.

Attendees will also have the opportunity to preview Command Risk Intelligence, the world’s first certificate risk management solution, which provides unmatched visibility into every certificate in use and helps teams proactively identify and mitigate certificate-related risks before they disrupt business operations.

VMblog:  What sets your solution apart in today’s crowded cybersecurity marketplace? Why should RSA attendees prioritize visiting your booth?

Hickman:  Keyfactor stands out as the only solution that delivers full lifecycle management for all types of digital certificates and can do so at enterprise scale.

What truly sets us apart in 2025 is our proactive approach to post-quantum readiness. As organizations prepare for a quantum-resilient future, early testing of PQC is essential to reduce risk and avoid last-minute security overhauls. Keyfactor has introduced significant PQC-focused updates in its offerings, including the latest versions of Keyfactor EJBCA (9.1) and SignServer (7.1), making them among the first open-source PKI and signing solutions to support NIST’s recommended PQC algorithms.

These enhancements make quantum-safe PKI and signing more accessible for engineers, developers, and partners-enabling real-world testing, seamless integration, and accelerated preparedness. That’s why RSACTM Conference attendees looking to future-proof their cryptography strategies should make Keyfactor a top priority.

VMblog:  How is your company addressing the growing concerns around supply chain security and third-party risk management?

Hickman:  Supply chain attacks surged in 2024, with more than 75% of software supply chains experiencing breaches. To combat this growing risk, organizations need to prioritize digital trust – securing the entire DevOps pipeline, verifying software authenticity, and protecting cryptographic assets at every stage.?

Keyfactor helps teams do just that with a centralized, secure, and developer-friendly platform for code signing. Our solution enables organizations to safeguard software without slowing innovation-giving security and development teams the tools they need to build and release confidently.

VMblog:  What role does zero trust play in your security strategy and solutions? How are you helping organizations implement zero trust effectively?

Hickman:  Zero Trust starts with identity-every device, workload, and user must be authenticated and verified with a trusted identity, whether they’re inside or outside the network. That’s where Keyfactor comes in.

We help organizations implement Zero Trust strategies by enabling PKI and machine identity automation at scale. Our platform issues trusted certificates for every device and workload, securing machine-to-machine transactions across complex environments. We also protect critical assets like SSH and code signing keys from theft or misuse, reducing the risk of impersonation and lateral movement by attackers.

VMblog:  Are you participating in any speaking sessions or panel discussions at RSA 2025? Can you tell us more about these presentations?

Hickman:  Yes. On Wednesday, April 30, at 1:20 p.m. PT, I’ll co-present the speaking session, “Fast-Track Your Path to Post-Quantum Cryptography,” alongside Vladimir Soukharev, VP of Cryptographic Research and Development at InfoSec Global. The session will take place in the North Expo Briefing Center at Booth N-6545.

Vladimir and I will explore how quantum computing is reshaping cybersecurity, share best practices for PQC testing and implementation, and outline how to build a long-term strategy for post-quantum readiness. Whether you’re just starting your PQC journey or already deep into planning, this session will give you actionable insights to move forward.

VMblog:  What’s your perspective on the most critical cybersecurity trends that will shape the industry in 2025-2026?

Hickman:  Three trends will dominate: the race toward PQC, the shift to shorter certificate lifespans, and the explosion of non-human identities due to AI.

Businesses that have not started their PQC transitions are already behind. Quantum computers may still be emerging, but attackers are already harvesting encrypted data today with the intent to decrypt it tomorrow-a “harvest now, decrypt later” strategy that threatens long-term data security by breaking the cryptographic algorithms that have protected sensitive data for decades. This creates a significant risk for any data that must remain secure over an extended period. That’s why starting the PQC transition now is critical.

At the same time, the CA/Browser Forum’s decision to shorten certificate validity to just 47 days will place immense operational pressure on security teams. Automation will be essential to stay ahead.

Finally, the rapid adoption of AI and AI agents means organizations are managing more non-human identities than ever before. This creates risks of blind spots in a business’s cryptography stack. Without visibility and automation, identity sprawl will also become a major risk, as cryptographic demands increase.

VMblog:  How does your solution help organizations address regulatory compliance and emerging privacy requirements?

Hickman:  New regulations-from PCI DSS to evolving global standards-now require full visibility into cryptographic assets and their lifecycle.

Keyfactor’s technology stack, specifically Keyfactor Command, helps organizations discover, inventory, and automate the management of machine identities across complex environments. With centralized visibility and control, teams can ensure compliance while strengthening the security posture of their crypto ecosystem.

VMblog:  How can security leaders better prepare their organizations for the evolving threat landscape in 2025 and beyond?

Hickman:  Security leaders need to prioritize two things: visibility and crypto-agility. You can’t protect what you can’t see-and you can’t adapt if your cryptographic infrastructure is rigid.

Start by gaining full visibility into every machine identity and cryptographic asset in your environment. Then, ensure your systems can quickly adapt to changes-whether it’s certificate rotation, key compromise, or new standards like PQC.

If you haven’t already started the PQC transition, now’s the time. NIST has set deadlines, but the real threat could arrive much sooner. Quantum breakthroughs aren’t required for attackers to act; data harvested today could be decrypted tomorrow, and valuable data will fall into the wrong hands. They don’t need a perfect quantum computer to compromise current cryptographic standards and encryption. Getting ahead of that curve is key to long-term resilience.

##