Never lose control of
another certificate.
AEYRiX MIPS (Machine Identity Protection) automates the full machine-identity lifecycle — request, approval, issuance, installation, renewal, revocation, inventory and governance — inside the ServiceNow platform your enterprise already runs on, orchestrated with CyberArk Certificate Manager.
Security owns the Certificate Servers (PKI). Infrastructure owns the servers. App teams own the apps. Nobody owns the certificates.
Certificates fall between teams — and that gap is where outages, failed audits and 2 a.m. incidents come from. MIPS closes it.
Unknown ownership
No single answer to "who owns this certificate?" when it matters most.
Disconnected teams
Responsibility scattered across security, infrastructure and application owners.
Inaccurate inventory
Certificate and installation-location records that don't match reality.
Failed & delayed renewals
Manual renewal cycles that slip, stall or never happen.
Manual deployment
Hand-installing certificates to endpoints, server by server.
Expiry-related outages
Services taken down by a certificate nobody was tracking.
Slow approvals & change
CAB and approval steps that turn renewals into week-long projects.
Incomplete governance
Gaps in audit trails that surface at exactly the wrong time.
Shorter lifetimes
Every mandate cut multiplies the manual work until it breaks.
A native scoped application built on ServiceNow.
MIPS isn't another console to learn. It's enterprise certificate lifecycle automation that runs inside your own ServiceNow instance — using the catalog, workflows, approvals, CMDB, users and groups you already operate and govern.
Machine identities become first-class operational objects: owned, tracked, automated and audit-ready from request to decommission.
- Runs in your ServiceNow instance — no separate platform to stand up
- Uses existing CMDB, users and groups — no duplicate system of record
- Orchestrates issuance & installation with CyberArk Certificate Manager
- Certified and listed on the ServiceNow Store
ServiceNow at the front. Automation at the back. AEYRiX in between.
MIPS turns ServiceNow into your certificate control plane — self-service, approvals and audit up front — while orchestrating the technical work of issuance and installation behind the scenes.
Requests, approvals, CMDB, change, incident and a complete audit trail — where your enterprise already works.
Validates, routes and drives every request through the full lifecycle — automatically and consistently.
Issuance, installation and machine-identity automation, orchestrated by MIPS from ServiceNow.
Extend your certificate platform — don't replace it.
MIPS orchestrates issuance and installation with CyberArk Certificate Manager, adding the full power of ServiceNow on top: self-service, workflow, approvals, CMDB association and audit. There is no rip-and-replace.
- Connect self-hosted and cloud certificate environments — in any combination
- Orchestrate managed enrollment, installation, renewal and revocation
- Keep certificate changes in step through automatic synchronization
- One governed source of truth, mapped to your CMDB
MIPS brings certificate requests, approvals, lifecycle operations, ownership, and reporting together in ServiceNow through integration with CyberArk Certificate Manager.
The complete certificate lifecycle — automated.
Every stage, driven from ServiceNow workflows and orchestrated to your certificate platform.
- 1RequestSelf-service, guided or CSR-based
- 2ApproveYour approval groups & policy
- 3IssueAutomated issuance
- 4InstallAutomated deployment to endpoints
- 5MonitorExpiry tracking & dashboards
- 6RenewAutomated & on-demand
- 7RevokeWith captured reason
- 8DecommissionRetire & stop tracking
Everything you need to operate machine identities at scale.
A complete certificate operations toolset, delivered natively in ServiceNow. Some endpoint automation and bulk operations vary by deployment model — the AEYRiX team confirms specifics for your environment.
New certificate requests
Guided self-service requests from the ServiceNow catalog.
CSR-based requests
Request against a customer-supplied CSR, with automatic policy validation.
Renewal
Automated and on-demand renewal, with renew-and-install chaining.
Revocation
Revoke current and previous versions with a captured reason.
Decommissioning
Retire certificates and installation locations from active tracking.
Certificate installation
Automated deployment to supported enterprise endpoints.
Bulk lifecycle operations
Bulk request, renewal and revocation in a single action.
ServiceNow Service Catalog
Certificate services in the catalog your users already use.
Workflow approvals
Route through your existing approval groups and policy.
Change management
Gate installs on approved ServiceNow change requests.
Incident creation
Auto-create incidents for certificates nearing expiry.
CMDB association
Map every certificate to applications and configuration items.
Application ownership
Tie certificates to business applications and their owners.
Custodian & approval groups
Owner, support and approval groups drive access and routing.
Certificate inventory
A governed certificate inventory, in step with your CMDB.
Keystore & installation inventory
Track where every certificate is actually installed.
Expiry monitoring
Daily expiry tracking with escalating alerts.
Automated & on-demand renewal
Renew at policy thresholds or with a single click.
Reverse synchronization
Changes made in the certificate platform sync back into ServiceNow.
Multi-environment support
Connect multiple self-hosted and cloud environments together.
Dashboards & reporting
Customizable dashboards for requests and expiry management.
Complete audit trail
Every request logged, approved and reportable on demand.
Supported endpoint automation
Automated installation to enterprise endpoints, by deployment model.
Role-based access
Record-level visibility and actions driven by group membership.
Certificate operations, in the ServiceNow experience your teams know.
Representative MIPS interface. Backend terminology and interface labels may vary by product version and deployment.
Give every certificate an owner, a record and an audit trail.
MIPS maps each certificate to a business application and configuration item in your CMDB, and to the owner, support and approval groups responsible for it. The result: certificates stop being orphaned, and governance stops being a spreadsheet exercise.
Mapped to your CMDB
Applications, servers and CIs — no separate, drifting inventory.
Clear ownership
Owner, support and approval groups on every record.
Audit-ready by default
Every request, approval and change captured and reportable.
Policy-driven
Approved-domain, naming and SAN validation before issuance.
Manual certificate management is about to become impossible.
The CA/Browser Forum has mandated that maximum TLS certificate lifetimes collapse from 398 days to 47. Every renewal cycle you manage by hand multiplies — until it breaks.
- 398Today
- 200Mar 2026
- 100Mar 2027
- 47Mar 2029
Automation-grade certificate lifecycle management isn't a nice-to-have for the 47-day era. It's the only way your uptime and compliance survive it.
Fewer outages. Faster renewals. Cleaner audits.
One platform. Five teams that finally agree.
CISO & security leadership
Outage and audit risk from expired certificates, eliminated before the 47-day cliff.
PKI & machine-identity leaders
Automate the lifecycle at scale without abandoning your certificate platform.
ServiceNow platform owners
One more mission-critical workflow consolidated onto your platform — certified and governed.
Infrastructure & IT operations
No more 2 a.m. outage from a missed renewal. Self-service, automated and logged.
Audit, risk & compliance
Complete, reportable evidence for every certificate request, approval and change.
- Banking & financial services
- Insurance
- Healthcare
- Government
- Utilities
- Telecommunications
- Manufacturing
- Technology
Designed to support established machine identity and PKI practices.
MIPS helps organizations implement controlled, auditable certificate lifecycle workflows using ServiceNow and CyberArk Certificate Manager. It supports both SaaS and Self-Hosted deployments, allowing customers to use the model that best fits their environment.
-
ServiceNow Store Certified Application
MIPS is certified and available through the ServiceNow Store.
View ServiceNow listing -
NIST SP 800-57
Supports key and certificate lifecycle governance.
Inventory, ownership, issuance, renewal, revocation, rotation, and auditability.
View alignment details -
NIST SP 800-131A Rev. 2
Supports organizational cryptographic policies.
Helps govern certificate requests while leveraging CyberArk Certificate Manager and certificate authority policies for approved algorithms, key lengths and certificate configurations.
View policy mapping -
FIPS-Validated Environments
MIPS can operate with ServiceNow, CyberArk Certificate Manager, certificate authorities, HSMs and cryptographic modules configured by the customer for applicable FIPS requirements.
View platform dependencies
Standards note: MIPS supports workflows and controls that can help organizations align with established PKI and machine identity practices. Compliance and cryptographic validation depend on the customer's architecture, policies, configurations, certificate authorities, underlying platforms and validated cryptographic modules.
Go deeper.
MIPS at a glance
Capabilities, architecture and what the app does inside ServiceNow.
Download PDF WhitepaperPKI best practices
Why getting machine identity management right matters — and how to.
Download PDF ServiceNow StoreSee the listing
Explore the certified AEYRiX MIPS application on the ServiceNow Store.
View on StoreQuestions, answered.
What is AEYRiX MIPS?
AEYRiX MIPS (Machine Identity Protection) is enterprise certificate lifecycle automation delivered as a native scoped application on ServiceNow. It lets enterprises run the full certificate lifecycle — request, approve, issue, install, monitor, renew, revoke and decommission — from the platform they already govern, approve and audit in.
Does MIPS work with CyberArk Certificate Manager?
Yes. MIPS orchestrates certificate issuance and installation with CyberArk Certificate Manager, while ServiceNow provides the self-service catalog, workflow, approvals, CMDB association and audit trail. There is no rip-and-replace.
Do I need ServiceNow to use MIPS?
Yes. MIPS is a native scoped application that runs inside your own ServiceNow instance, reusing your existing catalog, workflows, approvals, CMDB, users and groups.
What is the 47-day certificate mandate?
The CA/Browser Forum has set maximum TLS certificate lifetimes to fall from 398 days to 200 days in March 2026, 100 days in March 2027 and 47 days by March 2029. Shorter lifetimes make manual certificate management impractical at enterprise scale and require automation.
Is MIPS certified on the ServiceNow Store?
MIPS is a certified application listed on the ServiceNow Store, deployed and supported by the AEYRiX team that builds it.
Which endpoints and environments does MIPS support?
MIPS supports certificate installation to enterprise endpoints and connects to multiple certificate environments. Specific endpoint automation and bulk operations can vary by deployment model, and the AEYRiX team confirms supported endpoints for your environment during scoping.
Automate your certificate lifecycle in ServiceNow.
See how MIPS gives every machine identity an owner, a workflow and an audit trail — before the 47-day era makes manual management impossible.