AppViewX ships hybrid PQC certificates and an MCP server as machine identities hit a 144-to-1 ratio over humans
AppViewX has launched its Summer 2026 product update, introducing hybrid post-quantum certificates and a machine credential processing server designed with AI capabilities. This release comes as enterprises confront the increasing complexity of cryptographic requirements due to the massive growth of machine identities. Machine identities now outnumber human identities by 144 to 1.
This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.
Key facts, context, and what it means, in one minute.
Key takeaways
AppViewX's Summer 2026 update includes hybrid post-quantum certificates to enhance security.
Machine identities currently have a 144-to-1 ratio compared to human identities.
An AI agent-native MCP server is part of the new features addressing cryptographic challenges.
Machine identities now outnumber human identities 144 to 1, according to research cited by GlobeNewswire in AppViewX's July 22 product announcement. That ratio was already striking at 92 to 1 in the first half of 2024. The jump reflects AI agents being embedded directly into enterprise infrastructure, and it is arriving at exactly the moment that certificate validity windows are collapsing toward 47 days and quantum computing is forcing a rethink of every cryptographic algorithm in production.
AppViewX, which positions itself as a machine and agent identity security platform, is treating those converging pressures as one problem rather than three. Its Summer 2026 release, announced July 22, ships two capabilities built to address them in concert: hybrid composite post-quantum cryptography certificates and an MCP Server that lets AI agents manage certificates autonomously under existing governance controls.
Hybrid PQC certificates for a phased migration
The hybrid composite certificate format combines a classical algorithm, either RSA or ECC, with ML-DSA, the post-quantum signature scheme standardized by NIST, inside a single certificate. The practical upside for operators is that legacy applications keep functioning on the classical portion while the quantum-safe layer begins building into the infrastructure. There is no hard cutover required.
Support covers Root, Intermediate, and End-Entity certificates across the AppViewX PKI hierarchy, according to the company's announcement on GlobeNewswire. The capability can also be layered into Active Directory Certificate Services migrations, meaning teams modernizing their PKI footprint can pursue quantum readiness and crypto-agility through a single project rather than sequencing them separately.
The timing aligns with real regulatory pressure. The White House issued Executive Order 14412 in June, titled Securing the Nation Against Advanced Cryptographic Attacks, making post-quantum migration an explicit federal priority. The CA/Browser Forum has separately balloted a reduction in certificate validity periods to 47 days, as reported by HackRead citing the CyberNewswire release. Both mandates land on the same CLM teams at the same time.
Enterprise CLM teams are facing a rare collision: the certificate renewal cycle is about to shrink by more than 85 percent while every underlying algorithm they rely on is due for replacement.
AppViewX has layered in CMDB-enriched risk assessments to help teams sequence the migration. Rather than treating every certificate as equally urgent, the platform uses configuration management data to prioritize remediation by business impact, which matters when the volume of affected certificates can run into the hundreds of thousands across a large enterprise.
An MCP server that brings AI agents into the CLM loop
The second major capability is the AppViewX MCP Server, built on the open Model Context Protocol standard. It exposes certificate lifecycle operations, discovery, issuance, renewal, and inventory, as structured, callable API actions. Any AI agent built on a major agent framework can invoke them in real time, according to the company announcement published by GlobeNewswire.
The governance architecture is the detail security teams will scrutinize. Agent-initiated actions enforce the same issuance policies and permission structures that human-driven workflows use, and every action generates an audit log entry. That design keeps autonomous operations traceable for compliance purposes without requiring a separate approval layer for each agent request.
Practically, an agent monitoring an application environment can detect an impending certificate expiry, trigger a renewal request through the MCP Server, and complete the workflow without a human in the loop, provided the request falls within pre-configured policy bounds. Organizations that have already moved to agentic architectures for infrastructure operations now have a native CLM integration point rather than a custom workaround.
The operational case for converging these on one platform
AppViewX's framing is that most organizations are treating PQC migration and AI-agent identity management as separate security workstreams. The company's chief product officer, Paul Trulove, was quoted in the HackRead and GlobeNewswire releases arguing that the two challenges are on a collision course that will outpace most organizations' current readiness. The platform's response is to offer a single roadmap rather than two parallel projects.
That argument carries operational weight at the procurement level. Running separate tools for PKI modernization, PQC transition, and agentic identity governance means separate vendor contracts, separate audit trails, and duplicate policy configurations. Consolidating those workflows into one platform with a shared permissions model reduces both administrative overhead and the surface area for policy gaps between systems.
AppViewX pointed to a recent customer case study in which an enterprise replaced years of manual certificate management processes, and a pattern of certificate-related outages, with the platform ahead of the 47-day mandate. The company did not name the customer in its public announcement.
What security and infrastructure teams should evaluate now
- Audit current certificate inventory for RSA and ECC certificates that will need PQC equivalents and rank them by CMDB-mapped business criticality before the 47-day validity window takes effect.
- Determine whether existing PKI infrastructure supports hybrid composite certificate formats, or whether an AD CS migration is already on the roadmap that could absorb PQC enablement as a parallel workstream.
- Assess AI agent deployments for certificate dependencies: any agent that authenticates to services or issues calls to APIs holds a machine identity that needs to be governed, renewed, and audited at scale.
- Evaluate CLM platforms against whether agent-initiated certificate operations enforce existing policy at the API layer and produce audit logs that satisfy compliance requirements without manual review of each action.
The immediate calendar pressure is the 47-day certificate lifespan transition set by the CA/Browser Forum. Any organization still renewing certificates manually has a hard deadline to automate before that window closes.
Sources
- AppViewX Summer 2026 release announcement ↗ · GlobeNewswire
- AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration ↗ · HackRead / CyberNewswire
- Chilean peso to Uzbekistani soʻm (CLP to UZS) ↗ · Business Insider
About the author
The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.