QCecuring - Enterprise Security Solutions

The Audit That Exposed 3,000 Untracked Certificates

Certificate Lifecycle Management 17 Jul, 2026 · 04 Mins read

An ISO 27001 auditor asked for the certificate inventory. The team handed over 400 entries. Discovery found 3,200. Finding issued.


The Audit That Exposed 3,000 Untracked Certificates

”Show Me Your Certificate Inventory.”

Four words from an ISO 27001 auditor that triggered a 6-month remediation project.

The IT team confidently handed over their certificate spreadsheet: 400 entries. Mostly public-facing certs, a few internal server certificates they’d manually tracked.

The auditor wasn’t satisfied. They ran an independent discovery scan.

Result: 3,200 active certificates.

The team was tracking 12.5% of their certificate landscape. The other 87.5% — machine certificates, auto-enrolled user certificates, internal server certs, code signing certs — existed with no inventory, no owner, no expiry tracking.

Finding issued. Non-conformity. 6-month remediation timeline.

This is how it happened, what it cost, and what the team learned.

The Audit Context

ISO 27001 Requirement

ISO 27001 Annex A, Control A.5.9 (formerly A.8.1): Inventory of information and other associated assets.

This means: you must maintain an inventory of all cryptographic assets, including certificates. Not just the ones you remember. All of them.

What the Auditor Expected

ExpectationWhy
Complete inventory of all certificatesKnow what you have
Documented ownership for each certificateKnow who’s responsible
Defined lifecycles (expiry dates)Know when they expire
Renewal/replacement proceduresKnow how you’ll handle expiry
Evidence of regular reviewProve you’re actively managing them

What the Team Provided

A spreadsheet with 400 certificates:

  • All public-facing website certificates ✓
  • A handful of internal server certificates ✓
  • VPN gateway certificate ✓
  • RADIUS server certificate ✓
  • A few code signing certificates ✓

What was missing: Every machine certificate. Every auto-enrolled user certificate. Most internal server certificates. Intermediate CA certificates. CRL signing certificates.

The Discovery

The auditor requested a scan of the AD CS certificate database (certutil -view) and cross-referenced with network-level certificate discovery.

What They Found

Certificate TypeTeam’s CountActual CountGap
Public website certs45450
Internal server certs67234167
Machine certificates0 tracked2,1002,100
User certificates0 tracked680680
Code signing123826
Infrastructure (CA, CRL, OCSP)8146
Expired but still in useUnknown4747
Total4003,2002,800

The team was aware of 400 certificates. There were actually 3,200. 47 of them were already expired and still deployed on systems.

The Findings

Finding 1: Incomplete Asset Inventory (Major Non-Conformity)

Finding: “The organization does not maintain a complete inventory of cryptographic assets. Approximately 87% of internal certificates are not inventoried.”

Impact: Cannot demonstrate control over certificate lifecycle. Cannot prove awareness of what’s deployed in the environment.

Finding 2: No Defined Ownership (Minor Non-Conformity)

Finding: “For certificates that are inventoried, ownership and responsibility for renewal is not consistently documented.”

Impact: When a certificate approaches expiry, it’s unclear who is responsible for renewal or what system it supports.

Finding 3: Expired Certificates in Production (Observation)

Finding: “47 expired certificates were found deployed on production systems, indicating a gap in lifecycle management.”

Impact: Some of these expired certificates were on internal web servers causing browser warnings for employees. Others were on services that had failed silently.

The Remediation Project

Phase 1: Discovery (Month 1-2)

Objective: Build a complete certificate inventory.

ActivityEffort
Export AD CS certificate database2 days
Scan all network endpoints for deployed certificates1 week
Cross-reference issued vs. deployed3 days
Identify certificate owners (detective work)3 weeks
Document certificate-to-system mappings2 weeks

Challenge: Many certificates had been issued years ago by team members who had since left the company. Identifying current owners required tracing which systems used which certificates — often through trial and error.

Phase 2: Establish Lifecycle Management (Month 3-4)

ActivityEffort
Define certificate lifecycle policy1 week
Set up expiry monitoring2 weeks
Define renewal procedures per cert type1 week
Document ownership and responsibilities2 weeks
Create runbooks for common cert operations1 week

Phase 3: Remediate and Verify (Month 5-6)

ActivityEffort
Replace 47 expired certificates3 weeks
Verify auto-enrollment health across device fleet2 weeks
Review and clean up certificate templates1 week
Establish regular review cadence (quarterly)1 week
Prepare evidence for follow-up audit1 week

The Cost

Direct Costs

Cost ItemEstimate
Security engineer time (6 months, ~40%)$60,000
Infrastructure engineer time (6 months, ~25%)$35,000
Discovery tooling / scanning$5,000
Monitoring solution implementation$15,000
Process documentation$5,000
Follow-up audit fees$8,000
Total direct cost~$128,000

Indirect Costs

Cost ItemImpact
Delayed other security projects6-month roadmap shift
Audit finding on recordReputational (internal)
Management attention divertedStrategic distraction
Staff frustration / burnoutMorale impact

What It Would Have Cost Proactively

Proactive ApproachEstimated Cost
Certificate monitoring solution$10,000-$20,000/year
Initial inventory effort (before audit)$15,000 one-time
Quarterly review process$5,000/year
Total first-year proactive cost~$30,000-$40,000

Proactive management: ~$35,000. Reactive remediation after audit finding: ~$128,000.

4x the cost when done reactively.

What the Team Learned

Lesson 1: Auto-Enrollment Creates Certificates Nobody Tracks

Machine certificates and user certificates are issued automatically. That’s the point — no manual work. But the flip side is that nobody thinks about them. They exist in the thousands with no visibility.

Lesson 2: “Certificate Management” Must Include Internal PKI

The team genuinely believed they were managing certificates. They were — but only the public-facing ones. Internal certificates (the vast majority) were invisible.

Lesson 3: Certificate Ownership Is Hard to Establish After the Fact

Trying to determine who “owns” a 3-year-old certificate issued to a server that was set up by someone who left the company is genuinely difficult detective work.

Lesson 4: The Spreadsheet Doesn’t Scale

A spreadsheet works for 50-100 certificates. It doesn’t work for 3,000. And it certainly doesn’t auto-update when new certificates are issued or old ones expire.

Lesson 5: Prevention Is 4x Cheaper Than Remediation

The math is simple. Setting up monitoring and maintaining inventory proactively costs a fraction of the fire-drill remediation after an audit finding.

For Teams Facing an Upcoming Audit

If you have an ISO 27001, SOC 2, or similar audit approaching, here’s what the auditor will expect regarding certificates:

Question They’ll AskWhat You Need
”Show me your certificate inventory”Complete list: all CAs, all issued certs, types, expiry dates
”Who owns each certificate?”Documented owner per certificate or certificate group
”How do you handle expiry?”Monitoring + alerting + documented renewal process
”How do you handle revocation?”CRL/OCSP infrastructure, documented revocation procedure
”Show me evidence of regular review”Quarterly review meeting notes, dashboard screenshots

The Bottom Line

The audit didn’t find a security breach. It found a visibility gap. But that gap — 2,800 untracked certificates — represented unmanaged risk. Any one of those certificates could expire and cause an outage. Some already had.

The lesson: know what you have before someone asks you to prove it.


Don’t let an auditor be the first person to count your certificates. QCecuring provides complete internal certificate inventory and lifecycle monitoring for AD CS environments. Get ahead of your next audit →

Stay Ahead on Crypto & PKI

Monthly insights on certificate management, post-quantum readiness, and enterprise security.

Subscribe Free

Related Insights

Certificate Lifecycle Management

How Many Internal Certificates Does Your Company Actually Have?

Most teams think they manage hundreds of internal certificates. The real number is usually 3-5x higher. That gap is where risk hides.

By Mani sri kumar

17 Jul, 2026 · 03 Mins read

Certificate Lifecycle ManagementCertificate Discovery

Certificate Lifecycle Management

The Real Cost of a Certificate Outage (It's Not Just Downtime)

Certificate outages cost $22K per incident when you factor in engineer hours, lost productivity, helpdesk surge, and compliance findings. See the full cost breakdown.

By Mani sri kumar

17 Jul, 2026 · 04 Mins read

Certificate Lifecycle ManagementEnterprise Security

Certificate Lifecycle Management

Why 'We'll Know When It Breaks' Is Not a Certificate Strategy

Reactive certificate management costs 10x more than proactive. Compare MTTD, MTTR, and total cost between firefighting and planned maintenance approaches.

By Mani sri kumar

17 Jul, 2026 · 05 Mins read

Certificate Lifecycle ManagementEnterprise Security

Ready to Secure Your Enterprise?

Experience how our cryptographic solutions simplify, centralize, and automate identity management for your entire organization.

Stay ahead on cryptography & PKI

Get monthly insights on certificate management, post-quantum readiness, and enterprise security. No spam.

We respect your privacy. Unsubscribe anytime.