PKI Management and certificate automation
Expired certificates stop systems without warning. You get design, operations and automation of your PKI, so certificates are renewed in time, even at 47-day lifetimes.

Preventing downtime
Avoid major outages. An expired certificate stops systems without warning.
Your PKI infrastructure needs to be effective, secure and up to date. Our consultants review the setup, close the weaknesses and keep it maintained, so certificates never expire unnoticed.

One supplier for your entire PKI. Design, security assessment, training, lifecycle, compliance and operations.
You decide how much we take on: a single design project or full operation of the entire infrastructure. This is what we cover:
PKI design and implementation
A PKI solution that fits your needs: from a basic infrastructure to an advanced setup. We design, implement and test that every component works together.
Security assessment and risk management
A detailed review of your current PKI setup finds the weaknesses before they are exploited. Afterwards we can follow up on an ongoing basis, so the infrastructure holds up against new threats.
Training and support
Your own team learns to administer and maintain the PKI system. Afterwards our specialists are on hand with support for everything from daily tasks to complex faults.
Certificate lifecycle management
Certificate management is an ongoing process. We handle the full lifecycle: issuance, renewal, revocation and expiry. Your certificates stay valid, and the risk of security gaps falls.
Compliance
Your PKI infrastructure must meet legal requirements and industry standards. We document that the setup complies with everything from GDPR to specific standards such as GxP and PCI.
Operations
Day-to-day operation of your PKI solution, including operation of Hardware Security Modules (HSM). You avoid keeping specialist knowledge in-house for tasks that only come up a few times a year.
Why companies choose us for PKI. Experience, fixed support and a level you choose yourself.
With PKI advisory from MI Support IT you get:
- Experience: The consultants have worked with PKI and information security for many years, with both ADCS and Venafi.
- You choose the level: From advisory on a single project to full operation of the entire certificate infrastructure.
- Fixed support: You get a named contact person with specialists who know your setup, when something needs changing or fails.
- Ongoing risk assessment: New threats and new browser requirements are assessed on an ongoing basis, and the setup is adjusted before they hit you.

Public certificates
Shorter lifetimes for public TLS certificates. From 398 days to 47 days in 2029, manual renewal will not keep up.
Browser and CA/Browser Forum requirements are tightening over the coming years. The maximum lifetime of public TLS certificates falls in stages towards 2029, when a certificate is valid for just 47 days. That requires automation, processes and visibility, as manual renewal becomes practically impossible. Certificates are typically issued via established issuers such as DigiCert, which browsers and customers already trust.
| Effective from | Maximum lifetime |
|---|---|
| Today to 14 March 2026 | 398 days |
| 15 March 2026 | 200 days |
| 15 March 2027 | 100 days |
| 15 March 2029 | 47 days |
Lifecycle management is no longer optional
When a certificate must be renewed every 47 days, issuance, installation, validation and revocation must run automatically. We introduce certificate lifecycle management together with you: discovery of every existing certificate in the environment, automation with ACME and monitoring with alerts. No certificate expires unnoticed.
How we help you
- Discovery and inventory of all public and internal certificates
- Automated issuance and renewal via ACME, API and SCEP with integration to your CA
- Monitoring, alerting and reporting on expiry and compliance
- Processes and ownership, so responsibility for every certificate is clear

Your certificate infrastructure in safe hands. Specialist PKI operations with Microsoft ADCS and Cyberark, formerly Venafi.
PKI management with us specialises in Microsoft Active Directory Certificate Services (ADCS) and Venafi solutions. Your certificates are managed and protected correctly throughout their lifecycle. Automation runs in Cyberark Zero Touch PKI (formerly Venafi) and Cyberark Certificate Manager (formerly Venafi TLS Protect). That combines automatic renewal with strong security.
Active Directory Certificate Services (ADCS)
Microsoft ADCS is a key component in many companies' PKI. Our team designs, implements and administers ADCS solutions, so your setup runs stably and meets your security requirements.
Cyberark Zero Touch PKI (formerly Venafi)
Cyberark Zero Touch PKI (formerly Venafi) fully automates certificate management. Fewer manual processes mean fewer errors, and your certificates are always correctly installed. We set up and operate the solution for you.
Cyberark Certificate Manager (formerly Venafi TLS Protect)
Cyberark Certificate Manager (formerly Venafi TLS Protect) protects your TLS certificates, keeping applications and networks closed to unauthorised access. We administer and secure every TLS certificate in your organisation with the solution.
Related glossary terms and guides
Secure your company's digital identity. Book a meeting, and we will review your PKI and point out what is urgent.
You get a concrete view of the gap between your certificate infrastructure and the new lifetime requirements, and of what the next step is.