Prevention remains necessary, but it is not sufficient. A resilient security architecture assumes that credentials, endpoints, dependencies, and controls can fail, then limits the blast radius and restores trustworthy operation. Current certificate schedules, zero-trust guidance, and recovery evidence make that principle operational.
Current as of 2026-08-15
CA/Browser Forum requirements now cap publicly trusted TLS subscriber certificates issued from March 15, 2026 through March 14, 2027 at 200 days. The 47-day maximum begins March 15, 2029.
Decision summary
- Automate certificate inventory and renewal for today’s 200-day maximum and the scheduled reductions.
- Use zero-trust principles to limit implicit trust; do not claim the perimeter has disappeared.
- Prepare cryptographic inventories before choosing post-quantum migration dates.
- Treat response timelines as tested playbooks, not universal benchmarks.
Build around trust decisions
CISA’s Zero Trust Maturity Model organizes progress across identity, devices, networks, applications and workloads, and data. The useful design question is where a trust decision is made, what evidence supports it, and what happens when that evidence is missing or wrong.
Make certificate operations measurable
- Inventory certificates, owners, dependencies, issuers, and renewal paths.
- Alert before the earliest operational renewal threshold.
- Test automation failure and emergency replacement.
- Track certificates embedded in appliances, applications, and vendor-managed services.
- Plan for the 100-day maximum in 2027 and 47-day maximum in 2029.
Prepare for post-quantum migration
NIST has finalized initial post-quantum cryptography standards, but migration depends on product support and the data’s required confidentiality lifetime. Start with cryptographic discovery: protocols, libraries, certificates, keys, data classes, vendors, and upgrade dependencies.
Contain and recover with evidence
Segment critical systems, maintain independent recovery credentials, protect backup control planes, centralize logs, and rehearse isolation decisions. Define a tested incident sequence for the organization; label illustrative timelines as exercises, not guarantees. Recovery is complete only when identity, configuration, data, and monitoring are trustworthy.
For related guidance from ITECS, see ITECS cybersecurity services.
Sources and update trigger
- CA/Browser Forum — Current Baseline Requirements
- CA/Browser Forum — Current TLS Baseline Requirements PDF
- NIST — Post-Quantum Cryptography
- CISA — Zero Trust Maturity Model
Review trigger: Review on each CA/Browser Forum schedule milestone, new NIST cryptographic guidance, or a material architecture change.
