What Is Machine Certificate?
A machine certificate is a digital certificate, typically X.509 format, issued to a device, server, application, or workload to prove its identity cryptographically to other systems. Issued by a certificate authority (CA) — internal or public — a machine certificate binds a public key to an identifier for the machine, enabling it to establish TLS/mTLS connections, authenticate to internal services, and encrypt traffic without relying on a shared password. Machine certificates are central to zero-trust architectures, where every connection between services must be cryptographically verified, and to IoT and industrial environments, where devices authenticate autonomously at scale. Unlike passwords, certificates carry a defined validity period and can be revoked via a certificate revocation list (CRL) or OCSP, but they require active lifecycle management to remain trustworthy.
Why It Matters
Machine certificates fail in two directions that both create risk: expiration and neglect. An expired certificate can trigger unplanned outages when trust chains break silently, while an unmanaged or forgotten certificate — issued years ago for a decommissioned service — can remain a valid, trusted credential long after anyone remembers it exists, giving an attacker who obtains the private key a legitimate-looking foothold. Certificate sprawl across cloud, on-prem, and IoT environments is common, and without centralized inventory, organizations routinely lose track of who owns which certificate and when it expires. This sits squarely within the broader non-human identity exposure OWASP's NHI Top 10 (2025) describes — 80% of identity breaches involve an NHI — and with machine identities now outnumbering human staff 45 to 1 in many organizations, certificate lifecycle failures are a growing, largely invisible source of both outages and breaches. NIS2 (enforcement from October 1, 2026) and ANSSI ReCyF Objective 13 both expect organizations to demonstrate control over machine credentials, certificates included.
How Cydenti Helps
Cydenti discovers machine certificates across your environments and correlates them with the workloads, services, and non-human identities that rely on them, surfacing certificates nearing expiry, issued to decommissioned assets, or lacking a clear owner. Rather than treating certificate management as a siloed PKI task, Cydenti places certificates within the same identity graph as service accounts, API keys, and tokens — giving security teams a unified view of machine trust across the organization. See how Cydenti's ITDR capabilities help catch certificate-related risk before it becomes an incident.
Explore →Frequently Asked Questions
What happens when a machine certificate expires unexpectedly?
Services relying on that certificate for TLS/mTLS can fail to establish trusted connections, causing outages that often surface suddenly because expiry dates are rarely tracked centrally. This is a leading cause of unplanned downtime in environments with large, unmanaged certificate populations.
How is a machine certificate different from an API key or token?
A machine certificate uses asymmetric cryptography (a public/private key pair) issued and vouched for by a certificate authority, typically for establishing encrypted, mutually authenticated connections like mTLS. API keys and tokens are simpler shared-secret or bearer credentials, usually used for API-level authorization rather than transport-level trust.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h