Certificate Governance & TLS Modernisation

Certificate Governance & TLS Modernisation.

Navigator doesn't issue, renew or discover certificates. It governs the transformation programme built around them — alongside PQC migration, weak crypto remediation and inventory uplift.

The same ownership, review-state and evidence mechanism used everywhere else in Navigator applies here too.

Governance review states, per asset
  1. 1
    Reviewed
  2. 2
    Remediation planned
  3. 3
    Risk accepted
  4. 4
    Exception granted
  5. 5
    Not reviewed
Eligible assets

Eligible is not the same as included.

Certificates and TLS configurations enter the programme as eligible assets. A named person then decides which are actually included — the same distinction Navigator applies across every transformation programme it governs, including:

  • PQC Migration
  • Weak Crypto Remediation
  • Inventory Uplift
Review states

Every certificate and TLS configuration carries a governance review state.

Each asset in scope is tracked as reviewed, remediation planned, risk accepted, exception granted, or not reviewed — so the state of the programme is visible at the level of a single certificate, not just as an aggregate figure.

  • Reviewed
  • Remediation planned
  • Risk accepted
  • Exception granted
  • Not reviewed
Closing an item

Closing requires evidence or a recorded exception.

A certificate or TLS item does not close on an assertion. It closes with evidence attached, or with a recorded exception and a written reason — the same mechanism used everywhere else in Navigator.

What Navigator does not replace

Governing the programme, not performing the work.

If the organisation already runs a certificate lifecycle management tool or a manual renewal process, Navigator does not replace it. It governs ownership, decisions and evidence on top — regardless of what system actually performs the renewal.

Performs the renewal
  • A certificate lifecycle management tool
  • A manual renewal process
  • An internal PKI team's own workflow
Navigator governs
  • Ownership of each certificate and TLS configuration
  • The governance review state per asset
  • Evidence or a recorded exception before an item closes
Talk to us

Govern certificate and TLS transformation, whatever performs the renewal.

Request a Navigator demo to see how certificate governance and TLS modernisation fit alongside your existing tooling.

Request a Navigator demo