PQC (Post-Quantum Cryptography) 04-23-2025

Preparing for Quantum and Shorter Certificate Lifespans

Kevin Hilscher
Quantum Blog Hero Image

Today’s organizations are staring down not one but two major disruptions to digital trust. The first: Quantum computing is advancing rapidly, threatening to break the cryptographic algorithms that secure our data and communications. The second: The impending shift to 47-day certificate lifetimes will reshape how companies manage their certificates.

Both of those changes are significant on their own. Together, they represent a defining moment for security and IT teams. Success will require not just awareness, but action—a strategic, integrated approach that builds crypto-agility and future-proofs your digital trust infrastructure.

The good news? The path to quantum readiness also prepares you for shortened certificate lifespans. These aren’t two completely disparate challenges; they’re converging forces—and they call for a single cohesive response.

Disruption #1: The quantum threat is real—and imminent

Quantum computing has moved well beyond theory. With recent announcements from Microsoft, Amazon, and Google, progress in areas like error correction, qubit stability, and hybrid computing models is accelerating. And with it, so is the threat to classical encryption.

When cryptographically relevant quantum computers (QRQC) arrive, foundational algorithms like RSA and ECC will be rendered obsolete. The impact could be devastating—breaking the encryption behind secure internet communications, financial transactions, and critical infrastructure protections.

And the threat isn’t limited to the future. The risk of “harvest now, decrypt later” attacks is already here. Malicious actors are capturing encrypted data today with the intent to decrypt it when quantum capabilities become available. For organizations safeguarding sensitive IP, personal data, or government communications, this isn’t a theoretical risk—it’s an immediate concern.

Disruption #2: Shorter certificate lifespans will reshape operations

In parallel, the TLS ecosystem is bracing for another major change: The industry will transition to 47-day certificate lifespans by 2029. This shift, driven by major browser vendors, is intended to improve security—but it will demand far greater automation, faster renewal cycles, and more agile certificate management.

For many organizations, particularly those with complex environments or legacy systems, this represents a major operational challenge. Manual processes and siloed certificate management simply won’t scale in a world where certificates expire every six weeks.

Two disruptions, one path forward

What may feel like two separate disruptions is actually a single inflection point. And the same foundational capabilities—crypto-agility, automated certificate lifecycle management, and a modernized PKI—will prepare organizations to meet both challenges head-on.

At , we’re helping customers take a proactive, integrated approach. That includes:

  • Preparing for PQC: Working with NIST, IETF, and industry leaders to implement quantum-safe certificates that support both today’s and tomorrow’s cryptographic standards.
  • Enabling crypto-agility: Helping organizations inventory their cryptographic assets, establish agile key and certificate management processes, and test PQC readiness.
  • Automating certificate management: Laying the groundwork now for high-volume, short-lifespan certificate renewal through modern, scalable automation tools.
  • Updating policies and infrastructure: Assisting teams in revising internal governance and infrastructure to handle rapid change with minimal disruption.

Tackling a tight timeline with a trusted partner

NIST has laid out a clear roadmap: Federal agencies and critical systems should fully transition to quantum-safe algorithms between 2030 and 2035. Gartner recommends enterprises be quantum-ready by 2029—a deadline that also aligns with the anticipated shift to 47-day certificate lifespans.

Meeting both milestones will require organizations to act now: upgrading to TLS 1.3, assessing their cryptographic inventory, testing PQC implementations, and building the infrastructure to support high-frequency certificate renewal. Waiting risks not only operational disruption but also exposure to real-world threats.

At , we’re working with customers across industries to meet these challenges head-on—helping them modernize their PKI, automate certificate lifecycle management, and implement quantum-safe and upgrade to TLS 1.3 certificates. It's more than just preparing for what's next: It's securing digital trust in a future that's already taking shape.

The latest developments in digital trust

Want to learn more about topics like quantum readiness, crypto-agility, and certificate management? Subscribe to the blog to ensure you never miss a story.

Subscribe to the blog