Certificate Governance & TLS Modernisation.
Navigator doesn't issue, renew or discover certificates. It governs the transformation programme built around them — alongside PQC migration, weak crypto remediation and inventory uplift.
The same ownership, review-state and evidence mechanism used everywhere else in Navigator applies here too.
- 1Reviewed
- 2Remediation planned
- 3Risk accepted
- 4Exception granted
- 5Not reviewed
Eligible is not the same as included.
Certificates and TLS configurations enter the programme as eligible assets. A named person then decides which are actually included — the same distinction Navigator applies across every transformation programme it governs, including:
- PQC Migration
- Weak Crypto Remediation
- Inventory Uplift
Every certificate and TLS configuration carries a governance review state.
Each asset in scope is tracked as reviewed, remediation planned, risk accepted, exception granted, or not reviewed — so the state of the programme is visible at the level of a single certificate, not just as an aggregate figure.
- Reviewed
- Remediation planned
- Risk accepted
- Exception granted
- Not reviewed
Closing requires evidence or a recorded exception.
A certificate or TLS item does not close on an assertion. It closes with evidence attached, or with a recorded exception and a written reason — the same mechanism used everywhere else in Navigator.
Governing the programme, not performing the work.
If the organisation already runs a certificate lifecycle management tool or a manual renewal process, Navigator does not replace it. It governs ownership, decisions and evidence on top — regardless of what system actually performs the renewal.
- A certificate lifecycle management tool
- A manual renewal process
- An internal PKI team's own workflow
- Ownership of each certificate and TLS configuration
- The governance review state per asset
- Evidence or a recorded exception before an item closes
Govern certificate and TLS transformation, whatever performs the renewal.
Request a Navigator demo to see how certificate governance and TLS modernisation fit alongside your existing tooling.
