OmniTrust Blog
Categories
Recent Posts
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
The CRA gets real today. From September 11, manufacturers face new vulnerability reporting obligations. But when a critical flaw hits an open-source component, can you identify every affected product fast enough? Open source is no longer just an engineering issue. It’s a boardroom issue.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
Your suppliers may be your biggest CRA compliance risk. Blog #8 of our Tales From the Trenches series looks at why SBOMs, vulnerability response, support commitments, and supplier evidence now matter as much as your own controls – and why CRA readiness has to extend across the entire supply chain.
- NP Nick Parnaby
- AI & Agentic Security, Executive Viewpoints
What can Switzerland teach us about AI? 🇨🇠A lot. As models, harnesses, clouds and costs keep shifting, the smartest enterprise strategy may be to stay neutral, stay agile and keep control. The Switzerland Principle is a simple way to think about AI without betting the company on today’s winner.
- NP Nick Parnaby
- TrafficAuth, V2X, Work Zone Safety
Learn how TrafficAuth helps transportation agencies protect roadside crews in real time while automatically creating tamper-evident, cryptographically verifiable records of worker presence and work zone incidents.
- Jimmy Kim
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
The Cyber Resilience Act is exposing a problem many companies did not expect: cybersecurity teams cannot solve compliance alone. CRA connects engineering, product, legal, suppliers, security, quality, and leadership. The organizations that succeed will be the ones that finally connect them around one continuous operating model.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
The CRA gets real today. From September 11, manufacturers face new vulnerability reporting obligations. But when a critical flaw hits an open-source component, can you identify every affected product fast enough? Open source is no longer just an engineering issue. It’s a boardroom issue.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
Your suppliers may be your biggest CRA compliance risk. Blog #8 of our Tales From the Trenches series looks at why SBOMs, vulnerability response, support commitments, and supplier evidence now matter as much as your own controls – and why CRA readiness has to extend across the entire supply chain.
- NP Nick Parnaby
- AI & Agentic Security, Executive Viewpoints
What can Switzerland teach us about AI? 🇨🇠A lot. As models, harnesses, clouds and costs keep shifting, the smartest enterprise strategy may be to stay neutral, stay agile and keep control. The Switzerland Principle is a simple way to think about AI without betting the company on today’s winner.
- NP Nick Parnaby
- TrafficAuth, V2X, Work Zone Safety
Learn how TrafficAuth helps transportation agencies protect roadside crews in real time while automatically creating tamper-evident, cryptographically verifiable records of worker presence and work zone incidents.
- Jimmy Kim
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
The Cyber Resilience Act is exposing a problem many companies did not expect: cybersecurity teams cannot solve compliance alone. CRA connects engineering, product, legal, suppliers, security, quality, and leadership. The organizations that succeed will be the ones that finally connect them around one continuous operating model.
- NP Nick Parnaby
- TrafficAuth, V2X, Work Zone Safety
Discover how connected work zone technology can save lives by making roadside crews digitally visible, delivering real-time vehicle alerts, and uniting workers, vehicles, and agencies through OmniTrust’s secure, standards-based V2X ecosystem for safer roads everywhere.
- Jimmy Kim
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
Waiting for perfect CRA clarity could be the most expensive compliance decision your company makes. With critical deadlines approaching, manufacturers can’t afford analysis paralysis. Discover why product inventories, supply-chain visibility, governance, evidence, and lifecycle risk management need to start now – even while the standards are still evolving.
- NP Nick Parnaby
- Certificate Lifecycle & Automation, PKI & Cryptographic Governance
Nobody wants a certificate. They want the thing that stops working without one. Every question you ask beyond that is a tax you charge for your own policy. ILM request attributes let an RA profile declare what a request needs, where each value comes from, and what a client may never set — so the requester answers a short form and the trust guarantees stay put.
- Roman Cinkais
- Certificate Lifecycle & Automation, Software, Signing & Integrity
Ask a security team where their certificates live and you get a clear answer. Ask who used a signing key last week, and which authority stamped the result, and the answer arrives in fragments. ILM now performs signing and RFC 3161 timestamping itself, with signing profiles, per-operation records, and authenticated endpoints. One inventory, one authorization model, one audit trail.
- Roman Cinkais
- PKI & Cryptographic Governance, Post-Quantum & Crypto Agility
Every maturity model faces the same pressure: someone needs it to say more about their sector or their risk. So it either grows until it fits nobody, or it gets forked privately and stops being comparable. PKI Maturity Model 2.0.0 takes a third path with optional overlays that never touch the core, and the first one — PQC Readiness — is openly marked as still under development.
- Roman Cinkais
- PKI & Cryptographic Governance
Asking a certificate management process to govern cipher suites was always a category error. PKI Maturity Model 2.0.0, now in public preview, fixes the taxonomy rather than adding to it: a new Cryptography category in Governance, two cipher-suite requirements removed, and stable identifiers replacing position-based numbers. Here is what changed and what it means for existing assessments.
- Roman Cinkais
- Certificate Lifecycle & Automation, PKI & Cryptographic Governance
Release notes tell you which pull requests merged. They rarely tell you what changed about the way you work. ILM 2.19.0 makes signing and timestamping first-class capabilities, moves PKI complexity off the person requesting a certificate, and replaces scattered status updates with an explicit certificate state machine. Here are the four themes behind the changelog, and the specific changes under each one.
- Roman Cinkais
- PKI & Cryptographic Governance, Post-Quantum & Crypto Agility
A cryptographic inventory is only as useful as it is trustworthy, so the interesting question about a CBOM tool is not how much it reports but how it behaves when it does not know. CycloneDX 1.7 made that question sharper with two closed enumerations where one wrong value invalidates the whole document. CBOM Lens 1.1.0 emits them, and omits what it cannot prove.
- Roman Cinkais
- Certificate Lifecycle & Automation, PKI & Cryptographic Governance, Trust Lifecycle Management
The move to 47-day TLS certificates is accelerating, forcing organizations to rethink how they manage PKI and machine identities. Watch PKI expert Roman Cinkais explain what’s changing, the risks of manual certificate management, and the practical steps to automate certificate operations and modernize your trust infrastructure.
- Caroline Yao
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
Most organizations think the EU CRA’s 24-hour reporting requirement is about incident reporting. It isn’t. It’s about whether you can quickly determine if a newly disclosed vulnerability affects your products. That’s a product intelligence problem, not a reporting problem.
- NP Nick Parnaby
- Certificate Lifecycle & Automation, Trust Lifecycle Management
47-day TLS certificates are coming faster than most organizations realize. If you’re still relying on manual renewals, you’re already behind. Learn how to avoid outages, automate certificate management, and prepare for the next wave of PKI modernization before these changes become an operational crisis.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
Think CRA compliance ends when your product ships? Think again. 🚨 The hardest part begins after release. Discover why post-market cybersecurity, vulnerability management, and lifecycle governance are becoming the biggest challenges facing OEMs, software vendors, and connected product manufacturers under the EU Cyber Resilience Act.
- NP Nick Parnaby
- Executive Viewpoints, Threat, Risk & Vulnerability, Trust Lifecycle Management
What starts as hanging one picture becomes a full home renovation… just like connected product security. OmniTrust’s Sam Delsing brilliantly explains why cyber risk, compliance, and evidence must evolve with your product—and why static assessments simply don’t cut it anymore.
- NP Nick Parnaby
- Certificate Lifecycle & Automation, PKI & Cryptographic Governance, Post-Quantum & Crypto Agility
Discover 10 practical Identity Lifecycle Management (ILM) use cases and learn how to get started with certificate lifecycle management, machine identities, cloud PKI, Kubernetes, DevOps, trust automation, and post-quantum cryptography (PQC). Explore open-source integrations and modern trust operations.
- Jakub Moravek
- AI & Agentic Security, Executive Viewpoints
AI has crossed a new line. JadePuffer demonstrates how autonomous AI can execute sophisticated cyberattacks with minimal human involvement – adapting, escalating, and making decisions in real time. Discover why this changes the cybersecurity landscape forever, and why modernizing identity, cryptography, and AI governance is rapidly becoming a business imperative.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Trust Lifecycle Management
You can have mature cybersecurity, proven engineering practices, and recognized certifications—and still not be CRA-ready. The biggest challenge isn’t building secure products; it’s proving cybersecurity has been governed, documented, and maintained throughout the product lifecycle. In our latest EU CRA Tales From The Trenches blog, we explore why security maturity alone is no longer enough.
- NP Nick Parnaby
- PKI & Cryptographic Governance, Post-Quantum & Crypto Agility, Trust Lifecycle Management
Why would a commercial cybersecurity company open-source one of its core platforms? Roman Cinkais explains why OmniTrust believes the future of trust automation will be built through open collaboration.
- Roman Cinkais
- Executive Viewpoints, Post-Quantum & Crypto Agility
Washington lit the fuse. Are you ready for what’s next? Celebrate the Fourth with two practical white papers that cut through the hype and show how to operationalize post-quantum cryptography, modernize trust infrastructure, and prepare your organization for the coming era of cryptographic agility and continuous trust.
- NP Nick Parnaby
- Executive Viewpoints, Industry Insights, Lifecycle Lessons, Threat, Risk & Vulnerability, Trust Lifecycle Management
Most companies assume CRA compliance starts with vulnerability management, SBOMs, secure development, and incident response. In reality, the hardest first step is often figuring out which products are actually in scope, how they should be classified, and what security obligations apply to each one. Companies are discovering hidden products, legacy versions, cloud services, OEM components, and acquisitions that can multiply their CRA scope by 5x or more. The article argues that successful CRA programs begin with product inventory, classification, governance, and lifecycle ownership – not security controls – and that getting classification wrong can create compliance risk for years.
- NP Nick Parnaby
- Certificate Lifecycle & Automation, Post-Quantum & Crypto Agility, Trust Lifecycle Management
The old approach to trust infrastructure isn’t scaling. As AI, machine identities, and post-quantum cryptography reshape cybersecurity, the open-source ILM Community is bringing builders together to create the future of trust automation. Discover why the community matters—and how you can help build what’s next.
- Caroline Yao
- Executive Viewpoints, Lifecycle Lessons, Threat, Risk & Vulnerability, Trust Lifecycle Management
Companies selling connected products into Europe are racing to prepare for the Cyber Resilience Act – but many are discovering that their biggest compliance challenges have little to do with cybersecurity controls. Why are mature security programs still struggling? Why are product inventories, SBOMs, and support commitments becoming board-level concerns? And why do some organizations move quickly while others stall? Learn the real lessons emerging from the front lines of CRA implementation in this new blog series from OmniTrust.
- NP Nick Parnaby
- Lifecycle Lessons
Certificates, keys, and secrets need lifecycle governance — but the platform providing it has always carried its own operational cost. The updated open-source ILM operator collapses that cost into two declared Kubernetes resources: one for the whole platform, one per connector. Tested upgrade bundles, continuous reconciliation, and declarative coverage of every place your cryptographic assets live.
- Roman Cinkais
- Certificate Lifecycle & Automation, Executive Viewpoints, PKI & Cryptographic Governance
AI is taking over the world… so why are expired certificates still taking down companies in 2026? In a world of AI agents and quantum computing, organizations are still being brought down by expired certificates. How is that possible? OmniTrust’s Sam Delsing unpacks one of cybersecurity’s most embarrassing secrets: why certificate expiration is still causing outages in 2026.
- NP Nick Parnaby
- AI & Agentic Security, Executive Viewpoints
AI is spreading across enterprises faster than governance, finance, and cybersecurity teams can control it. Shadow AI, runaway token spend, and autonomous agents are forcing CIOs and CISOs into a new role: not AI blockers, but the adults in the room helping businesses discover, control, optimize, and safely scale AI before operational chaos arrives.
- NP Nick Parnaby
- PKI & Cryptographic Governance
You cannot migrate to post-quantum cryptography without knowing what cryptographic assets you have. This post walks through the three-step process for building a comprehensive inventory — discovery, metadata collection, and structured cataloging — and explains how the Cryptography Bill of Materials (CBOM) standard from OWASP CycloneDX provides a standardized format for the result. Includes a comparison of open-source CBOM tooling.
- Roman Cinkais
- PKI & Cryptographic Governance
Most PKI environments grow organically without structured governance. The PKI Maturity Model (PKIMM), developed by the PKI Consortium, provides a CMMI-based assessment across 15 categories in four modules — Governance, Management, Operations, and Resources. It gives PKI architects a measurable way to identify gaps and build a concrete improvement roadmap.
- Roman Cinkais
- Trust Lifecycle Management
Certificates get lifecycle governance — renewal dates, revocation policies, audit trails. API tokens, service credentials, and signing keys rarely get the same treatment, even though they carry equivalent trust. This post explains why trust lifecycle management must cover every artifact that confers trust, not just X.509. The answer is not replacing Vault or AWS Secrets Manager, but adding a unified governance plane above them: one inventory, one policy, one audit stream.
- Roman Cinkais
Popular Tags
Subscribe
Subscribe for Trust and Security Insights
Receive the latest OmniTrust blog posts, expert insights, and digital trust updates directly in your inbox.