- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
This blog was written by: Junior Silva
Targeting general availability in Q1 2027
Federal agencies depend on certificates and machine identities to keep mission-critical applications, devices and workloads trusted and available. But shrinking certificate lifespans, rapidly expanding machine identities and the transition to post-quantum cryptography are making that trust harder to maintain.
Agencies need to discover where certificates are used, understand where the cryptographic risk is active and automate certificate operations across environments. Connecting certificate lifecycle management with network visibility can help teams accelerate change management, reduce manual work, and prevent certificate-driven service disruptions.
This matters now. Publicly trusted TLS certificate lifespans are moving towards 100 days in 2027 and a maximum of 47 days by 2029, while agencies must begin replacing quantum-vulnerable cryptography without disrupting production systems. We call this convergence of certificate, machine identity and cryptographic change the Cryptographic Reset.
Navigating it requires crypto agility: the ability to change certificates, keys, algorithms, issuers, protocols and trust anchors safely and repeatedly.
Federal agencies face these pressures within strict compliance boundaries. An expired certificate, an unsupported algorithm, or a broken trust chain anywhere along an application's path can take a mission-critical service offline.
Yet certificate and machine-identity management often falls to a small team of PKI administrators, sometimes a single person, working through manual processes. As the number of identities grows and certificate lifespans shrink, that dependence on manual work becomes an operational risk.
We're bringing these capabilities to the Strata Cloud Manager (SCM) FedRAMP Moderate environment through Next-Generation Trust Security (NGTS). General availability is targeted for Q1 2027.
Extending SCM's FedRAMP Moderate boundary to include NGTS will soon help federal agencies benefit from the same market leading certificate lifecycle and machine identity capabilities that are available commercially today.
NGTS helps teams centralize visibility into certificates and machine identities, apply lifecycle policies, coordinate supported public and private certificate authorities, and automate certificate processes across supported environments. For supported integrations, that automation extends through provisioning, deployment, and post-deployment validation.
Bringing these capabilities into SCM connects certificate and trust operations with the network security management environment organizations already use to secure infrastructure and communications.
Network context and lifecycle automation serve complementary roles. Network context helps teams understand where cryptographic exposure is active and prioritize action. Lifecycle automation helps carry supported certificate and trust changes through governed deployment and validation. Together, they connect visibility with the operational work needed to address risk.
That work is continuous. As post-quantum cryptography matures and standards, algorithms, and trust requirements evolve, organizations will need to adapt repeatedly. NGTS is designed to support that ongoing change.
Read the Solving Complex CLM with NGTS whitepaper to learn more about how Palo Alto Networks helps customers discover and automate certificates.
This is an early look at what's planned. Share your questions or feedback in the comments, and follow this thread for updates as we move toward the targeted general availability window.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| Subject | Likes |
|---|---|
| 2 Likes | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

