Australian organisations are facing growing certificate management risks, with 43.6 per cent experiencing a service outage caused by an expired certificate over the past year, according to DigiCert research.
The Certificate Management Outlook report found 31.6 per cent of Australian respondents experienced at least five hours of certificate-related downtime, while 12.4 per cent reported 25 hours or more.
DigitCert’s findings are based on a survey conducted by Propeller Insights. The study surveyed 1,001 IT and cyber security decision-makers in the United States, the United Kingdom, and Australia in May 2026.
Almost one in 10 (9.2 per cent) said their most significant certificate incident cost more than $250,000.
The outages are increasingly being treated as an enterprise resilience issue rather than solely a cyber security problem, with 51.2 per cent of Australian respondents classifying certificate outages as infrastructure issues.
Automated certificate life cycle management now ranks fourth among Australian organisations’ cyber security priorities, but only 8 per cent said they have automation in place.
“An expired certificate can shut down a critical service just as quickly as any other infrastructure failure,” Mike Nelson, global vice president and field CTO at DigiCert, said in a statement.
“With certificate life cycles shrinking to 47 days, spreadsheets and calendar reminders simply won’t scale. Organisations need to know every certificate they have, where it is, who owns it, and then automate the life cycle before an overlooked expiration becomes a business outage.”
The pressure is set to increase as certificate volumes rise and public TLS life cycles shrink. From 2029, industry rules will limit public TLS certificates to 47 days and domain validation reuse to 10 days.
DigiCert estimates an enterprise managing 1,000 public TLS certificates could face about 8,000 certificate issuances and 40,000 domain validations each year under the new rules.
Australian organisations are making progress, however, with 62.4 per cent actively preparing for shorter certificate life cycles. Unfortunately, that trails the UK at 71 per cent and the US at 74 per cent.
Budget constraints were the leading barrier to automation among Australian respondents at 24.4 per cent, followed by incompatibility with legacy technology at 22 per cent.
You can read the full report here.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.