The Audit That Exposed 3,000 Untracked Certificates
”Show Me Your Certificate Inventory.”
Four words from an ISO 27001 auditor that triggered a 6-month remediation project.
The IT team confidently handed over their certificate spreadsheet: 400 entries. Mostly public-facing certs, a few internal server certificates they’d manually tracked.
The auditor wasn’t satisfied. They ran an independent discovery scan.
Result: 3,200 active certificates.
The team was tracking 12.5% of their certificate landscape. The other 87.5% — machine certificates, auto-enrolled user certificates, internal server certs, code signing certs — existed with no inventory, no owner, no expiry tracking.
Finding issued. Non-conformity. 6-month remediation timeline.
This is how it happened, what it cost, and what the team learned.
The Audit Context
ISO 27001 Requirement
ISO 27001 Annex A, Control A.5.9 (formerly A.8.1): Inventory of information and other associated assets.
This means: you must maintain an inventory of all cryptographic assets, including certificates. Not just the ones you remember. All of them.
What the Auditor Expected
| Expectation | Why |
|---|---|
| Complete inventory of all certificates | Know what you have |
| Documented ownership for each certificate | Know who’s responsible |
| Defined lifecycles (expiry dates) | Know when they expire |
| Renewal/replacement procedures | Know how you’ll handle expiry |
| Evidence of regular review | Prove you’re actively managing them |
What the Team Provided
A spreadsheet with 400 certificates:
- All public-facing website certificates ✓
- A handful of internal server certificates ✓
- VPN gateway certificate ✓
- RADIUS server certificate ✓
- A few code signing certificates ✓
What was missing: Every machine certificate. Every auto-enrolled user certificate. Most internal server certificates. Intermediate CA certificates. CRL signing certificates.
The Discovery
The auditor requested a scan of the AD CS certificate database (certutil -view) and cross-referenced with network-level certificate discovery.
What They Found
| Certificate Type | Team’s Count | Actual Count | Gap |
|---|---|---|---|
| Public website certs | 45 | 45 | 0 |
| Internal server certs | 67 | 234 | 167 |
| Machine certificates | 0 tracked | 2,100 | 2,100 |
| User certificates | 0 tracked | 680 | 680 |
| Code signing | 12 | 38 | 26 |
| Infrastructure (CA, CRL, OCSP) | 8 | 14 | 6 |
| Expired but still in use | Unknown | 47 | 47 |
| Total | 400 | 3,200 | 2,800 |
The team was aware of 400 certificates. There were actually 3,200. 47 of them were already expired and still deployed on systems.
The Findings
Finding 1: Incomplete Asset Inventory (Major Non-Conformity)
Finding: “The organization does not maintain a complete inventory of cryptographic assets. Approximately 87% of internal certificates are not inventoried.”
Impact: Cannot demonstrate control over certificate lifecycle. Cannot prove awareness of what’s deployed in the environment.
Finding 2: No Defined Ownership (Minor Non-Conformity)
Finding: “For certificates that are inventoried, ownership and responsibility for renewal is not consistently documented.”
Impact: When a certificate approaches expiry, it’s unclear who is responsible for renewal or what system it supports.
Finding 3: Expired Certificates in Production (Observation)
Finding: “47 expired certificates were found deployed on production systems, indicating a gap in lifecycle management.”
Impact: Some of these expired certificates were on internal web servers causing browser warnings for employees. Others were on services that had failed silently.
The Remediation Project
Phase 1: Discovery (Month 1-2)
Objective: Build a complete certificate inventory.
| Activity | Effort |
|---|---|
| Export AD CS certificate database | 2 days |
| Scan all network endpoints for deployed certificates | 1 week |
| Cross-reference issued vs. deployed | 3 days |
| Identify certificate owners (detective work) | 3 weeks |
| Document certificate-to-system mappings | 2 weeks |
Challenge: Many certificates had been issued years ago by team members who had since left the company. Identifying current owners required tracing which systems used which certificates — often through trial and error.
Phase 2: Establish Lifecycle Management (Month 3-4)
| Activity | Effort |
|---|---|
| Define certificate lifecycle policy | 1 week |
| Set up expiry monitoring | 2 weeks |
| Define renewal procedures per cert type | 1 week |
| Document ownership and responsibilities | 2 weeks |
| Create runbooks for common cert operations | 1 week |
Phase 3: Remediate and Verify (Month 5-6)
| Activity | Effort |
|---|---|
| Replace 47 expired certificates | 3 weeks |
| Verify auto-enrollment health across device fleet | 2 weeks |
| Review and clean up certificate templates | 1 week |
| Establish regular review cadence (quarterly) | 1 week |
| Prepare evidence for follow-up audit | 1 week |
The Cost
Direct Costs
| Cost Item | Estimate |
|---|---|
| Security engineer time (6 months, ~40%) | $60,000 |
| Infrastructure engineer time (6 months, ~25%) | $35,000 |
| Discovery tooling / scanning | $5,000 |
| Monitoring solution implementation | $15,000 |
| Process documentation | $5,000 |
| Follow-up audit fees | $8,000 |
| Total direct cost | ~$128,000 |
Indirect Costs
| Cost Item | Impact |
|---|---|
| Delayed other security projects | 6-month roadmap shift |
| Audit finding on record | Reputational (internal) |
| Management attention diverted | Strategic distraction |
| Staff frustration / burnout | Morale impact |
What It Would Have Cost Proactively
| Proactive Approach | Estimated Cost |
|---|---|
| Certificate monitoring solution | $10,000-$20,000/year |
| Initial inventory effort (before audit) | $15,000 one-time |
| Quarterly review process | $5,000/year |
| Total first-year proactive cost | ~$30,000-$40,000 |
Proactive management: ~$35,000. Reactive remediation after audit finding: ~$128,000.
4x the cost when done reactively.
What the Team Learned
Lesson 1: Auto-Enrollment Creates Certificates Nobody Tracks
Machine certificates and user certificates are issued automatically. That’s the point — no manual work. But the flip side is that nobody thinks about them. They exist in the thousands with no visibility.
Lesson 2: “Certificate Management” Must Include Internal PKI
The team genuinely believed they were managing certificates. They were — but only the public-facing ones. Internal certificates (the vast majority) were invisible.
Lesson 3: Certificate Ownership Is Hard to Establish After the Fact
Trying to determine who “owns” a 3-year-old certificate issued to a server that was set up by someone who left the company is genuinely difficult detective work.
Lesson 4: The Spreadsheet Doesn’t Scale
A spreadsheet works for 50-100 certificates. It doesn’t work for 3,000. And it certainly doesn’t auto-update when new certificates are issued or old ones expire.
Lesson 5: Prevention Is 4x Cheaper Than Remediation
The math is simple. Setting up monitoring and maintaining inventory proactively costs a fraction of the fire-drill remediation after an audit finding.
For Teams Facing an Upcoming Audit
If you have an ISO 27001, SOC 2, or similar audit approaching, here’s what the auditor will expect regarding certificates:
| Question They’ll Ask | What You Need |
|---|---|
| ”Show me your certificate inventory” | Complete list: all CAs, all issued certs, types, expiry dates |
| ”Who owns each certificate?” | Documented owner per certificate or certificate group |
| ”How do you handle expiry?” | Monitoring + alerting + documented renewal process |
| ”How do you handle revocation?” | CRL/OCSP infrastructure, documented revocation procedure |
| ”Show me evidence of regular review” | Quarterly review meeting notes, dashboard screenshots |
The Bottom Line
The audit didn’t find a security breach. It found a visibility gap. But that gap — 2,800 untracked certificates — represented unmanaged risk. Any one of those certificates could expire and cause an outage. Some already had.
The lesson: know what you have before someone asks you to prove it.
Don’t let an auditor be the first person to count your certificates. QCecuring provides complete internal certificate inventory and lifecycle monitoring for AD CS environments. Get ahead of your next audit →