A revocation of digital certificate It is the act of invalidating a certificate before its expiration date, blocking its use when there is a risk, loss of control, or inconsistency that compromises the identity of the holder and the security of transactions. This prevents a compromised credential from continuing to sign documents, access systems, or represent a company in electronic operations.
When this cancellation is handled quickly, the organization reduces its exposure to fraud, operational errors, and questions about authorship. This is especially relevant in areas such as legal, tax, procurement, and IT, where certificates are often linked to signing contracts, issuing invoices, accessing public portals, and routines with a high impact on compliance.
In operational terms, revocation is not the same as expiration. Expiration is the natural termination of validity. Revocation is an early interruption due to safety reasons, error, or loss of usability. For teams working with digital document managementThis difference defines the level of urgency for internal treatment and the risk involved.
Summary
- Revocation invalidates the certificate before its expiration date when there is an incident, media loss, password error, or compromise.
- The process typically involves identifying the problem, requesting revocation, confirming the status, and issuing a new certificate.
- Companies can track KPIs such as incident response time and the number of invalidated certificates during the period.
- Good preventative practices include inventory, security policy, access review, and a rapid replacement plan.
Quick facts
- According to the Digital Government portalA qualified electronic signature uses a digital certificate within the legal framework applicable to interactions with public authorities.
- According to the service Obtain a Digital CertificateA3 certificates can be valid for up to 5 years, and the loss of the cryptographic media can mean the loss of the certificate.
- According to VALIDATEHowever, a certificate may appear as revoked in some situations, requiring consultation with the certifying authority or GOV.BR.
What is digital certificate revocation and why does it protect operations?
Revoking a digital certificate acts as a formal block on the cryptographic identity linked to a person or company. By invalidating the certificate, the organization prevents the future use of that credential, which helps preserve the reliability of electronic signatures, authentications, and transactions.
In the ICP-Brasil ecosystem, this process is not peripheral. According to the ITICertification Authorities issue, distribute, revoke, and manage certificates, in addition to maintaining lists of revoked certificates. This helps to understand why revocation is a structural part of the chain of trust and not just an exceptional procedure.
This logic also connects to the legal value of the certificate. ITI itself states that digital certification streamlines processes, reduces costs, and guarantees authenticity, integrity, reliability, and non-repudiation. When a digital identity ceases to be secure, rapid revocation becomes a containment measure to preserve precisely these attributes.
When does revocation typically occur in practice?
In companies, revocation usually occurs in incident or loss of control scenarios. The most common cases are loss of token or card, suspicion of misuse, irretrievable password loss, machine formatting without adequate backup, termination of an employee with a linked certificate, and failures that undermine trust in the credential.
Loss, theft, or misplacement of media
This is one of the most objective triggers. In certificates that rely on cryptographic media, such as certain A3 models, losing the device can mean losing the ability to securely use the credential. Therefore, the incident should be treated as a security event and not just an operational problem.
Password error or access blocked
When the certificate holder loses control of the PIN, PUK, or authentication mechanism linked to the certificate, the practical consequence can be the complete unavailability of the credential. In some contexts, this requires rapid replacement to avoid disruption of workflow in areas that use it. signature with digital certificate in sensitive documents.
Media formatting or loss of the user environment.
If the certificate was stored in a local environment, token, or structure that was formatted, corrupted, or discarded without a continuity plan, the risk is no longer just technical. The company needs to ensure that the old certificate does not continue to circulate as a valid asset while the operation attempts to reorganize.
Invalidation due to change of condition
There are cases where the credential ceases to be relevant due to changes in registration information, termination of employment, clerical error, or other occurrence that compromises the suitability of the certificate to its holder. According to the IRSRevoking a digital certificate means making it invalid, and the request must be made on the issuing certification authority's website.
| Situation | Main risk | Expected action |
|---|---|---|
| Loss or theft of token | Misuse of digital identity | Revoke and issue a new certificate. |
| Unrecoverable password | Process halted | Confirm that it is unusable and replace it. |
| Formatting or media failure | Operational unavailability and uncertainty | Check status and arrange for a new issue. |
| User shutdown | Unauthorized access after change of affiliation. | Revoke and update inventory |
In a well-structured routine of digital complianceThe company documents these events, identifying responsible parties, maximum response time, reporting channels, and evidence of the incident. This reduces improvisation and speeds up the recovery of operations.
What to do after identifying the problem.
The real gain lies not only in revoking, but in revoking methodically. In a corporate environment, the ideal is to work with a short, traceable, and repeatable workflow, especially when the certificate is linked to tax obligations, contract signing, or access to government platforms.
- Identify the incident: confirm if there was a media loss, suspected compromise, blocked access, or a material error.
- Register the eventOpen an internal support ticket with the date, time, account holder, affected system, and impact on the process.
- Request revocationContact the issuing certification authority through the indicated channels.
- Check the statusCheck if the certificate is already listed as invalid or revoked.
- Request a new certificateDefine priorities based on the business process impacted.
- Update internal controlsInventory, access, workflows, responsible parties, and continuity documentation.
O My CertificateThe ITI service allows users to view certificates issued in their name, whether active or not, which helps with inventory verification and status checks in governance routines. This is also useful for areas that operate with... signature validationThis visibility facilitates audits and incident response.
Corporate Example 1
A finance manager loses the token used to sign powers of attorney and access tax systems. The company registers the loss, requests revocation on the same day, reassigns the critical task to another temporary responsible party, and issues a new certificate. The most relevant indicator here is the time between the incident and the effective invalidation.
Corporate Example 2
A legal team notices that a certificate linked to a former employee still appears in old records. Even without evidence of misuse, the situation calls for immediate verification, revocation where applicable, and a review of the termination process. In parallel, it's worth reviewing integrations with... contract management and internal systems.
Useful KPIs to track this process
Since the topic involves security and continuity, it's worth measuring the efficiency of the process. The indicators don't need to be complex. The most important thing is that they help answer whether the company detects incidents quickly, reacts quickly, and learns from them.
| KPI | What does it measure? | Practical reading |
|---|---|---|
| Incident response time | Time interval between identification and revocation request | The smaller the number, the smaller the risk window. |
| Time until recovery | Timeframe between incident and new operational certificate | It shows a real impact on continuity. |
| Number of invalidated certificates | Volume of revocations in a given period | It helps detect recurring problems. |
| Incidents by area | Distribution by legal, tax, purchasing, IT | Indicates where to strengthen controls. |
This data can be cross-referenced with policies of process optimizationTraining paths and critical asset reviews. If the company focuses revocations on a few sectors, the problem may lie less in the technology and more in the governance of its use.
Good practices to prevent avoidable new revocations.
Not all revocations are avoidable, but a large portion of incidents can be reduced with simple rules. This includes a centralized inventory of certificates, a media storage policy, designated substitutes, a routine for reviewing linking procedures, a termination checklist, and a formal procedure for loss, theft, or blocking.
- Maintain an inventory with the owner, purpose, expiration date, and responsible department.
- Define an internal SLA for incident communication.
- Separate certificates by business criticality.
- Document the emergency replacement of those responsible.
- Using routines document security and access control.
Check out these related articles as well:
- ICP-Brasil organizes the chain of trust used for issuing, validating, and revoking digital certificates in the country.
- Cloud-based digital certificates change the way they are used and reduce some of the risks associated with physical media.
- The process of signing a document with a digital certificate helps to understand where the credential fits into the operation.
A clear policy reduces risk and preserves trust.
Digital certificate revocation should be treated as a mechanism to protect electronic identity and operational reliability. When a company knows when to revoke, how to react, and how to measure the process, it reduces exposure to fraud, avoids lengthy disruptions, and strengthens the governance of digital flows. And to apply this process in your company, Click here to learn how ZapSign works as a Certification Authority..
Frequently Asked Questions (FAQ)
No. Expiration occurs at the natural end of the validity period stipulated in the certificate. Revocation happens before that, when there is a loss of control, suspicion of compromise, misuse, or another event that makes the continued use of that credential in the operation unsafe or inappropriate.
Generally, not automatically. The key point is whether the signature was made while the certificate was still valid and in good standing. Official validation services indicate that signatures produced during the validity period may continue to be recognized, depending on the context and the corresponding verification.
This depends on the rules of the certifying authority and the type of certificate issued. Generally, the request comes from the holder or authorized representative, following the data and procedures defined by the issuer. In a corporate environment, ideally this flow should already be foreseen in internal policies and a responsibility matrix.
Loss or theft of a token, suspected misuse, termination of an employee with an active credential, unrecoverable access failure, and registration inconsistencies are all relevant signs. The more the certificate is linked to tax, contractual, or regulatory routines, the shorter the time should be between identifying the problem and providing a formal response.
The most effective approach usually combines an up-to-date inventory, proper media storage, periodic access reviews, user training, and a rapid replacement plan. It also helps to define response indicators and review past incidents to understand if the cause lies in the process, storage, or lack of governance.

Getúlio Santos is the CEO of ZapSign, a lawyer, technology enthusiast, and entrepreneur.

![[Banner] Legal validity of digital and electronic signatures: definitive guide with expert analysis](https://blog.zapsign.com.br/wp-content/uploads/2024/11/Banners-para-blog-Opice-Blum.webp)


