Network Security

Next-Generation Trust Security
Automate and Future-Proof Digital Resilience

Launched March 23, 2026. Network-native certificate lifecycle management plus a SaaS private PKI, embedded in Strata Cloud Manager, with Idira (formerly CyberArk) machine-identity integration.

Overview

When Digital Trust Breaks, the Business Stops

Expired and non-compliant certificates trigger outages, security breaches, and compliance failures. NGTS transforms cryptographic trust from a manual liability into an automated advantage.

The Certificate Crisis

The industry is moving toward a 47-day certificate renewal cycle — a dramatic acceleration from the current 397-day standard. Manual certificate management simply cannot keep pace. NGTS transforms cryptographic trust from a manual, error-prone process into an automated, network-integrated capability. It combines network-native certificate lifecycle management with a SaaS private PKI, is delivered and operated from within Strata Cloud Manager, and integrates with Idira (formerly CyberArk) for machine-identity intelligence. Launched March 23, 2026.

Because it lives in Strata Cloud Manager rather than a separate console, NGTS reaches the same NGFW and Prisma Access estate the customer already manages — no new management infrastructure to stand up.

47 Days

New certificate renewal cycle

In SCM

Network-native, delivered through Strata Cloud Manager

PQ Ready

Post-quantum cryptographic agility

Capabilities

Core Capabilities

Three pillars of automated, network-native trust management, delivered with a SaaS private PKI so customers can issue and rotate internal certificates without running their own CA infrastructure.

Gain Increased Visibility

Discover where trust lives across all network services and applications. Eliminate shadow certificates and blind spots. Map every certificate, key, and trust relationship across the entire network infrastructure in real time.

Facilitate Operational Resilience

Automatically identify and refresh credentials before they disrupt customer transactions or internal services. Proactive renewal prevents outages and maintains continuous service availability across the organization.

Build Cryptographic Agility

Accelerate the post-quantum transition. Handle faster renewal cycles and evolving encryption standards without manual effort. The SaaS private PKI issues and rotates internal certificates centrally, so a crypto-algorithm change is a policy change rather than a rebuild of the CA estate.

Why NGTS

Key Differentiators

What sets NGTS apart from standalone certificate lifecycle management tools.

  • Only Provider Embedding Trust into the Network Layer

    NGTS is the only solution that embeds certificate lifecycle management directly into the network firewall. Trust is enforced at the network layer, not bolted on as a separate tool.

  • Network-Native, Not Standalone CLM

    Unlike standalone CLM tools that require separate infrastructure and integration, NGTS operates natively within the Strata network security platform and is administered from Strata Cloud Manager, with real-time visibility and enforcement on the existing NGFW estate. The private PKI is delivered as SaaS, so there is no CA server to build.

  • Idira Integration for Machine Identity Intelligence

    Integration with Idira (formerly CyberArk — the acquisition closed Feb 11, 2026 and the platform rebranded as Idira, GA May 12, 2026) provides machine-identity intelligence on machine-to-machine trust relationships, service accounts and credential rotation. Certificate Manager is a confirmed Idira product name; scope which Idira components the customer already owns before promising an integration.

  • Post-Quantum Ready

    Built from the ground up for the post-quantum era. Supports emerging quantum-resistant cryptographic algorithms and automated migration paths from legacy encryption standards — ensuring organizations are prepared before quantum threats materialize.

Pre-Sales

Scoping Checklist

Data points to collect before quoting Next-Generation Trust Security.

Certificate Inventory — Total number of TLS/machine certificates in use, and how many the customer can actually enumerate today (the gap between the two is the shadow-certificate number that sizes the deal)
Annual Issuance Volume — Certificates issued and renewed per year, split public CA vs internal CA, plus expected growth as renewal cycles shorten
Current PKI / CA Estate — Which CAs are in use (public CA vendors, Microsoft ADCS, other internal CAs), how many issuing CAs, and who operates them
CA / CLM Vendor Contract End Date — Incumbent certificate authority and certificate-lifecycle-management vendor, annual spend, and renewal date — this sets the compelling event
Certificate Outage History — Number of expiry- or misconfiguration-driven outages in the last 24 months, duration, and business impact per incident
Machine and Workload Identity Counts — Servers, load balancers, network devices, containers, service accounts and non-human identities requiring certificates
SCM Tenancy — Existing Strata Cloud Manager tenant(s), tier (Essentials free or Pro paid), and number of tenants — NGTS is administered from SCM, so tenancy design is a prerequisite
Idira Integration Scope — Which Idira (formerly CyberArk) components the customer owns — for example Certificate Manager, Idira Secrets Hub, Idira Privileged Access Manager — and which machine identities must be shared with NGTS
Compliance and Crypto-Agility Requirements — Frameworks in scope (PCI, HIPAA, NIS2, DORA, FIPS), key-length and algorithm policy, and any audit finding already raised on certificate management
Post-Quantum Requirements — Documented PQC migration deadline, data-confidentiality horizon, and whether Quantum-Safe Security (GA Jan 30, 2026) and PAN-OS 12.2 PQC for GlobalProtect belong in the same proposal
Automation and Services Scope — Which teams own certificates today (network, security, DevOps, app), which enrolment protocols and CI/CD pipelines must be automated, and implementation effort required

Discovery

Discovery Questions

Use these questions to uncover certificate management pain points and position NGTS.

Why ask: Reveals the maturity of their certificate management process. Many organizations still rely on spreadsheets, manual tracking, or fragmented tools that miss certificates entirely.

Listen for: "We use spreadsheets" — immediate NGTS opportunity. "We have a CLM tool" — position network-native advantage. "Our PKI team handles it" — ask about scale and automation gaps.

Why ask: Certificate-related outages are common and costly. Even major enterprises like Microsoft, Google, and Spotify have suffered high-profile incidents. This creates urgency for automated management.

Listen for: "Yes, it was painful" — quantify the business impact and position NGTS. "Not yet" — highlight the inevitability with 47-day cycles. "We have monitoring" — ask if it's proactive or reactive.

Why ask: The industry push toward 47-day cycles (driven by Apple and Google) will break manual certificate management processes. Organizations that don't automate will face constant renewal failures.

Listen for: "We hadn't heard about that" — education opportunity and urgency driver. "We're concerned" — NGTS is purpose-built for this. "We can handle it" — probe how many FTEs are dedicated to cert management.

Why ask: Post-quantum preparedness is increasingly a board-level concern. NGTS's cryptographic agility capability positions it as the migration path to quantum-resistant infrastructure.

Listen for: "We haven't started" — position NGTS as the first step. "It's on our roadmap for next year" — accelerate the timeline. "NIST just released standards" — connect NGTS to their compliance needs.

Why ask: Certificate management often spans network ops, security, DevOps, and application teams — creating coordination overhead and finger-pointing during outages. NGTS centralizes this into the network layer.

Listen for: "Three or more teams" — consolidation opportunity. "It's nobody's full-time job" — risk of dropped renewals. "We have a dedicated PKI team" — position the scale challenge with 47-day cycles.