Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

AppViewX adds hybrid PQC certificates and an MCP server as machine identities hit a 144-to-1 ratio over humans

AppViewX's Summer 2026 release introduces hybrid post-quantum cryptography (PQC) certificates and MCP server features. The update addresses security needs as machine identities vastly outnumber humans, with a current ratio of 144 to 1. This release aims to facilitate post-quantum migration and support agentic AI developments.

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · AppviewxPost-quantum CryptographyCertificate Lifecycle ManagementMachine Identity
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
AppViewX adds hybrid PQC certificates and an MCP server as machine identities hit a 144-to-1 ratio over humans

Key takeaways

01

Machine identities now outnumber human identities by a ratio of 144 to 1.

02

AppViewX's release includes hybrid PQC certificates and MCP server features to enhance security.

03

The update is designed to support post-quantum migration and agentic AI use cases.

Machine identities now outnumber human identities by 144 to 1, up sharply from a 92-to-1 ratio in the first half of 2024, according to research cited by GlobeNewswire. That growth, driven largely by the proliferation of AI agents embedded in enterprise infrastructure, landed at the center of AppViewX's Summer 2026 product release, announced July 22. The company shipped two capabilities at once: hybrid composite post-quantum cryptography (PQC) certificates and a Model Context Protocol (MCP) Server for AI-driven certificate lifecycle management.

The timing is deliberate. Enterprise security teams are simultaneously managing three converging deadlines: the White House's Executive Order 14412 on Securing the Nation Against Advanced Cryptographic Attacks, signed in June 2026; the CA/Browser Forum's scheduled transition to 47-day maximum certificate lifespans; and the operational reality that AI agents are minting new machine identities faster than manual CLM processes can track. AppViewX is positioning its Summer 2026 release as a single platform response to all three.

Hybrid PQC certificates without a hard cutover

The hybrid composite PQC certificate approach pairs a classical algorithm, either RSA or ECC, with the ML-DSA post-quantum algorithm inside one certificate. Legacy applications validate the classical component and continue working without modification; quantum-capable infrastructure validates the post-quantum component. No full environment replacement is required before the migration begins.

According to GlobeNewswire, support spans Root, Intermediate, and End-Entity certificates across AppViewX's PKI hierarchy. Enterprises migrating from Active Directory Certificate Services (AD CS) can enable PQC as part of that same initiative rather than running parallel workstreams, collapsing what would otherwise be two separate modernization projects into one. CMDB-enriched risk assessments within the platform prioritize which certificates to migrate first, scored by business impact rather than by volume alone.

An enterprise that waits for a clean-slate quantum migration will still be waiting when the first cryptographically relevant quantum computer arrives, hybrid PQC certificates make starting now the lowest-risk option on the table.

The 47-day certificate lifespan mandate from the CA/Browser Forum sharpens the urgency further. Shorter validity windows mean higher renewal frequency, and any organization still renewing certificates through manual ticketing workflows will face an unsustainable ops burden once that schedule takes effect. AppViewX's hybrid PQC capability is explicitly designed to let teams tackle PKI modernization and lifespan compliance through a single initiative, according to HackRead's coverage of the announcement.

An MCP server that puts AI agents inside certificate governance

The AppViewX MCP Server is built on the open Model Context Protocol standard and exposes certificate lifecycle operations as structured, callable actions. AI agents built on any major agent framework can invoke those actions in real time: requesting new certificates, triggering renewals when expiry or policy events are detected, and running automated discovery and inventory across distributed environments.

The critical design constraint, as described by both GlobeNewswire and HackRead, is that agent-initiated actions run within the same governance layer security teams already maintain. Permissions, issuance policies, and audit controls are enforced at the API layer rather than delegated to the agent. Every agent action produces an audit-ready log, which matters for compliance teams who need to demonstrate that autonomous operations stayed within policy bounds.

That architecture distinction separates the MCP Server from ad-hoc automation scripts, which typically bypass policy enforcement entirely. Enterprises deploying agentic AI across IT operations have struggled to maintain auditability when those agents touch security-sensitive systems. AppViewX's approach enforces governance at the interface rather than relying on the agent itself to behave correctly.

Why two separate problems are actually one

Paul Trulove, Chief Product Officer at AppViewX, described the underlying dynamic in the company's announcement: AI agents are expanding the cryptographic attack surface at exactly the moment that surface needs to become quantum-resistant. Most organizations are treating PQC migration and agentic AI identity management as separate security programs with separate budgets and timelines. The company's argument is that treating them separately creates a gap that will close at a rate most teams are not prepared for.

The 144-to-1 machine-to-human identity ratio is not a future projection, it is today's inventory problem, and it compounds every time an AI agent spins up a new workload.

AppViewX CEO Archit Lohokare framed the release around operational practicality rather than a theoretical security posture, noting that hybrid PQC certificates give customers quantum readiness without disruption to existing environments, while the MCP Server gives AI agents the ability to manage certificates at scale without creating new governance blind spots, according to GlobeNewswire.

What this means for your team

  • Audit your current CLM tooling against the 47-day certificate lifespan timeline: if renewal is still predominantly manual, the CA/Browser Forum's schedule makes automation a near-term operational requirement, not an optimization.
  • Evaluate whether your PQC migration plan requires a full infrastructure cutover, hybrid composite certificates (RSA/ECC + ML-DSA) offer a staged path that maintains legacy compatibility and can be bundled with an AD CS migration already on the roadmap.
  • Establish governance requirements for AI agent identity actions now, before agents are deployed at scale: any CLM platform used for agentic workflows should enforce policy and produce audit logs at the API layer, not rely on the agent to self-govern.
  • Cross-check Executive Order 14412 compliance obligations for your organization against your current PKI modernization timeline, federal contractors and critical-infrastructure operators should treat the two as the same workstream.

Featured companies

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Imagine publishing your whole team.

This article was produced through MarketScale. Create a free workspace and turn your own team's Software & Technology expertise into the articles, video, and social content B2B marketing buyers in your industry are searching for. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

DTCC's tokenization platform goes live with BlackRock, Goldman and JPMorgan as Wall Street's post-trade infrastructure moves on-chain

DTCC's tokenization platform goes live with BlackRock, Goldman and JPMorgan as Wall Street's post-trade infrastructure moves on-chain

DTCC has launched its tokenization platform, performing blockchain-based transactions with over 25 Wall Street firms including BlackRock, Goldman Sachs, and JPMorgan. The service represents a significant move for Wall Street's post-trade infrastructure towards blockchain technology.

  • 01DTCC's tokenization service has gone live with the support of major financial firms.
  • 02Blockchain technology is being integrated into Wall Street's post-trade infrastructure.
  • 03Over 25 financial firms are participating in DTCC's blockchain-based transactions.

Jul 31, 2026

Amazon Business hits $60 billion in annualized gross sales as B2B ecommerce enters its agentic era

Amazon Business hits $60 billion in annualized gross sales as B2B ecommerce enters its agentic era

Amazon Business has achieved $60 billion in annualized gross sales, marking a significant milestone in B2B ecommerce as agentic AI reshapes the landscape. This shift is influencing how enterprise buyers discover and procure products online, highlighting the growing impact of AI on business operations.

  • 01Amazon Business has reached $60 billion in annualized gross sales.
  • 02Agentic AI is transforming the way enterprise buyers discover and procure products online.

Jul 30, 2026

OpenAI's $150 million enterprise push puts forward deployed engineers inside client operations

OpenAI's $150 million enterprise push puts forward deployed engineers inside client operations

OpenAI has launched a new services firm and a $150 million partner program to enhance the deployment of AI models in enterprise settings. This initiative aims to bridge the gap between the availability of AI technology and its practical implementation in business operations.

  • 01OpenAI has initiated a $150 million partner program to support enterprise AI deployment.
  • 02The new services firm by OpenAI focuses on integrating AI models into client operations.
  • 03This effort aims to improve the practical application of AI in businesses.

Jul 30, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512