A PKI health check is a structured review of your certificates, certificate authorities, keys and processes that finds outage and security risks before they reach production. The 10 checks below cover inventory, expiry, ownership, weak algorithms, key protection, CA hierarchy, revocation, automation, policy and incident readiness.
Use the checklist to run the review yourself, score the results, and decide what to fix first.
Why run a PKI health check now
One expired certificate can take down a login page, an API or a whole service. As the DictaLabs PKI Risk Assessment page puts it: “One expired certificate can bring down your entire system.”
The pressure is rising. Public TLS certificates issued since 15 March 2026 can be valid for at most 200 days, and under CA/Browser Forum Ballot SC-081 that falls to 47 days from 15 March 2029. Our guide to 47-day TLS certificates explains the full timeline.
Most teams do not know how many certificates they have until something breaks. A health check gives you that picture before an outage does.
The 10 checks
1. Complete inventory
Do you have one list of every certificate across public CAs, internal CAs, cloud services, Kubernetes and devices?
Quick wins: search public Certificate Transparency logs (for example crt.sh) for your domains, and scan your networks (for example with nmap --script ssl-cert). A CLM platform such as Certinium CLM can keep that inventory current, with discovery across enterprise, cloud, network, application and device environments.
2. Expiry horizon
How many certificates expire in the next 30, 60 and 90 days? Include root and intermediate CA certificates, and certificates built into applications and devices. A CA certificate that expires breaks every certificate below it.
3. Ownership
Does every certificate have a named, current owner and a team contact? Watch for owners who have changed roles or left the company, and for shared mailboxes that nobody reads.
4. Weak or outdated cryptography
Look for RSA keys shorter than 2048 bits, SHA-1 signatures, and servers that still allow TLS 1.0 or 1.1. Record the algorithm of every key now, because that is also the first step of a post-quantum migration plan.
5. Private key protection
Are CA keys in an HSM? Are any private keys sitting in code repositories, shared drives or support tickets? Is the same wildcard key copied to many servers?
6. CA hierarchy health
Is the root CA offline? Do issuing CA certificates outlive the certificates they sign? Are key ceremonies documented, and are the CA certificates’ own expiry dates tracked? If the hierarchy needs rework, DictaLabs CA supports multi-tier hierarchies with an offline root CA.
7. Revocation works
Are CRLs published before their “next update” time? Is the OCSP responder up, and is its signing certificate valid? Can clients actually reach the CRL and OCSP addresses written in your certificates?
8. Automation coverage
What share of certificates renew with no human step, through ACME, SCEP, EST or an API? Which systems can never be automated, and what is the plan for them? Our comparison of ACME, SCEP and EST helps you pick the right protocol for each system.
9. Policy and documentation
Is there a current certificate policy or CP/CPS, and do the certificates you issue actually match it? Are administrator access, separation of duties and audit logs in place? Our list of common CP/CPS audit gaps shows what to look for.
10. Incident readiness
Is there a runbook for an expired certificate, a leaked key and a CA compromise? Could you replace a large group of certificates within 24 hours if a CA had to revoke them? Has anyone tested it?
Score your results
| Check | Green | Amber | Red |
|---|---|---|---|
| 1. Inventory | One complete, current list | Partial list or several lists | No list |
| 2. Expiry horizon | Nothing unplanned in the next 90 days | Some expiries without a plan | Expiries within 30 days without a plan |
| 3. Ownership | Every certificate has a current owner | Most certificates have owners | Owners unknown |
| 4. Cryptography | No weak keys or protocols | A few exceptions with a plan | Weak keys or SHA-1 in use |
| 5. Key protection | CA keys in HSMs, no stray keys | Some important keys in software | Keys in repositories or tickets |
| 6. CA hierarchy | Offline root, CA expiry tracked | Gaps in documentation | CA expiry not tracked |
| 7. Revocation | CRL and OCSP monitored | Working but not monitored | Stale CRLs or OCSP failures |
| 8. Automation | Most renewals automatic | Some automation | Mostly manual |
| 9. Policy | Current CP/CPS that matches practice | Outdated documents | No policy |
| 10. Incident readiness | Tested runbooks | Runbooks not tested | No runbooks |
Aim to fix every red within 30 days, starting with inventory and expiry.
Do it yourself in a week
- Days 1 and 2: build the inventory from Certificate Transparency logs, network scans, cloud certificate services and CA databases.
- Day 3: check expiry dates and owners.
- Day 4: review cryptography, key protection and the CA hierarchy.
- Day 5: test revocation, measure automation, review policy and the incident runbook, then write up the reds.
To check a single server, this OpenSSL command prints the subject, issuer and validity dates of the certificate it presents. Replace example.com with your host name:
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates
When to ask for help
If the inventory is large, spread across several clouds, or nobody owns PKI full time, an outside review can save time. According to its page, the DictaLabs free PKI risk assessment is done by PKI engineers rather than automated tools, and works across cloud, on-premises and hybrid environments, including companies using AWS, Azure and Kubernetes. You get a detailed report in 48 hours, followed by a walkthrough call.
The report covers certificate visibility gaps, expiry risks, automation opportunities, and security and compliance risks. DictaLabs takes on a limited number of assessments each month. After the report, you can automate renewals with Certinium CLM or strengthen your CA with DictaLabs CA.
Next step
Request your free assessment on the PKI Risk Assessment page, or contact our PKI team if you have questions first.






