Product1 publisher2 min readPublished
DigiCert folds post-quantum migration into the 47-day certificate mandate
DigiCert chief executive Amit Sinha says the 47-day certificate mandate and the post-quantum rebuild share a 2029 deadline, so the renewal automation a PKI team is already budgeting is the migration's first floor. The interview is a vendor's account of its own customers.
The Product Desk · Product desk

What happened
- DigiCert chief executive Amit Sinha told theCUBE that customers have stopped arguing about post-quantum cryptography and are moving from planning into execution.
- DigiCert launched Quantum Central in July, which turns an inventory of machines, software and libraries into a cryptographic posture risk assessment.
- The interview ran during World Quantum Readiness Day, an event for which theCUBE disclosed it is a paid media partner of DigiCert.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision A team with one automation budget has to decide whether the certificate renewal build carries algorithm agility with it now or gets reopened as a separate post-quantum line item closer to 2029.
- cost The bill lands on the PKI team Sinha himself calls underfunded, and eight renewals a year per certificate is the part of the work that cannot be deferred behind a quantum timeline.
- constraint Anyone writing an internal business case off this interview has a vendor's account of peer progress and no migration figures to put in front of a finance committee.
- precedent If good enough inventory becomes the accepted standard, the person who drew the crown jewels list owns every exclusion when an auditor asks about the assets left off it.
A two-person PKI team keeps a list of certificate expiry dates and renews by hand when the alert fires. Under a 47-day maximum lifetime, that job comes around at least eight times a year for every certificate on the list [15][14].
DigiCert's chief executive, Amit Sinha, says the automation that fixes that is also the post-quantum project. "The road to crypto agility with the 47-day mandate is kind of the same road to post-quantum cryptography," Sinha said [3]. "Both of those deadlines are now 2029," he said [4]. He named the foundations as bringing public and private PKI together plus last-mile automation [18].
What is being sold is quantum readiness, and DigiCert sells a piece of it: Quantum Central, launched in July, which turns an inventory of machines, software and libraries into a cryptographic posture assessment [9]. What gets done next year is certificate discovery and renewal automation.
If certificates today get replaced when somebody notices, eight replacements a year per certificate means a script with an owner, or two more headcount. Sinha describes the people who would run it: "In many cases, PKI teams who are underfunded and now they look at this massive, Y2K-like times 10 event that is going to hit them," he said [7].
"What we tell customers is you don't need a perfect inventory, you need a good enough inventory. Identify crown jewels in your application suite that you want to attack first," Sinha said [8]. Whoever draws that crown jewels list owns the exclusions when something outside it comes up in an audit.
Sinha spoke with theCUBE's John Furrier at World Quantum Readiness Day, and theCUBE disclosed that it is a paid media partner for DigiCert's event [11]. The line about customers having worked through denial and bargaining to acceptance is a vendor's characterisation of its own pipeline [2]. The interview stops short of customer counts, migration rates, firmware and hardware refresh cycles [13].
Two questions sort the cryptographic assets. Can this be re-issued today by an automated call, yes or no. Does it protect data whose useful life runs past 2029, yes or no [4]. The yes/yes box is rehearsal for the algorithm swap. The no/yes box is the actual project: anything that needs a human, a vendor ticket or a replacement box. That box is the one worth counting before the next planning round, because the interview ran on 17 September 2026 and 1 January 2029 is 27 months later [12][16].
"PKI modernization is long overdue. And the deadline to do that is 2029. If you don't start today, you're already out of time," Sinha said [10].
What to watch
- Whether DigiCert publishes migration data out of Quantum Central, such as the share of customer certificates re-issued, instead of posture scores.
- Whether the 47-day maximum lifetime arrives in dated steps before 2029, which would move the automation work earlier than the interview implies.
- Whether other certificate authorities price post-quantum issuance separately from standard certificates.