For many years, S/MIME email certificates remained in the shadow of TLS certificates. Although they played a critical role in ensuring the confidentiality and integrity of electronic communication, their development was relatively slow, and validation processes were often perceived as archaic, manual, and difficult to scale. In 2025, however, this situation began to change noticeably.
Published updates to standards by the CA/Browser Forum, together with accompanying industry analyses, show that email certificates are entering a new phase of evolution. This phase is built on two parallel pillars: automation of the certificate lifecycle using the ACME protocol and preparing S/MIME infrastructure for cryptography resistant to quantum attacks (Post-Quantum Cryptography, PQC).
These changes are not cosmetic. They affect the very foundation of trust in email communication and have significant implications for both certificate providers and organizations that treat email as a critical business communication channel.
Table of Contents
ToggleS/MIME certificates are formally part of the public key infrastructure (PKI). Their purpose is to cryptographically confirm the identity of the message sender and enable end-to-end encryption of email content. Unlike TLS, which protects the communication channel between servers, S/MIME operates at the level of the message itself.
This characteristic is precisely why the compromise of cryptographic algorithms used in S/MIME can have far longer temporal consequences. Archived email messages, signed or encrypted today, may remain in circulation for years or even decades. In the context of the growing risk of harvest now, decrypt later attacks, cryptographic resilience is no longer a theoretical concern.
For this reason, the work on updating the S/MIME Baseline Requirements conducted by the CA/Browser Forum is of strategic importance, not merely operational significance.
One of the most significant changes introduced into the S/MIME standards is the formal acceptance and specification of automated email address validation using the ACME protocol (Automated Certificate Management Environment).
ACME revolutionized the TLS certificate market by enabling full automation of issuance, renewal, and revocation of HTTPS certificates. Until now, email certificates remained outside this ecosystem. Validation of control over an email address was most often performed manually or semi-automatically, which effectively limited the scalability of S/MIME deployments in large organizations.
The new standards introduce a coherent model in which a CA can:
In practice, this means that email certificates begin to be managed in the same way as TLS certificates, using agents, scripts, and MDM systems. For enterprise environments, this is a necessary condition for S/MIME to be deployed at scale rather than only in isolated cases.
The update to the S/MIME Baseline Requirements is not limited to ACME alone. The document also specifies how email addresses are assigned to certificates, the use of the subjectAltName extension, and requirements related to Extended Key Usage.
This is significant because for years the email certificate market suffered from a lack of interpretational consistency. Different issuers applied different validation models, which led to interoperability issues and audit ambiguities. The current changes aim to standardize practices across the entire industry, in a manner similar to what previously occurred in the TLS certificate ecosystem.
The second, far more long-term aspect of these changes is the opening of S/MIME standards to post-quantum cryptographic algorithms. The CA/Browser Forum has allowed the experimental use of algorithms approved by NIST, such as ML-DSA and ML-KEM.
It is no coincidence that email certificates are among the first candidates for PQC testing within public PKI. The nature of S/MIME means that:
In this context, implementing quantum-resistant algorithms in S/MIME is a logical preparatory step rather than an experiment detached from business realities.
From the perspective of the certificate market, these changes signal a clear shift: S/MIME is no longer a niche add-on and is increasingly treated as a full-fledged component of communication security strategy.
For organizations, this means the ability to:
For providers such as HEXSSL, this is also a clear signal that the market expects not only the sale of certificates, but also advisory services in PKI architecture, automation, and long-term cryptographic resilience.
The update of S/MIME standards reflects a broader trend across the entire PKI industry. Certificates are no longer treated as one-time products, but rather as elements of a continuous trust management lifecycle.
ACME automation and preparation for post-quantum cryptography are two clear signals that email, despite its maturity as a technology, remains a key area for security investment. Organizations that account for these changes in their strategies today will gain not only a technological advantage, but also regulatory and reputational benefits.
The update of S/MIME email certificate standards conducted by the CA/Browser Forum signals a significant change in the approach to electronic communication security. Email certificates are no longer perceived as niche or purely technical solutions, but are beginning to play the role of strategic components of an organization’s trust infrastructure.
The introduction of ACME-based automation and the formal opening of standards to post-quantum cryptography mean that the PKI market is entering a phase of transformation comparable to the earlier evolution of TLS certificates. For management boards and B2B customers, it is crucial to understand that these changes are not merely a technological evolution, but a response to real business, regulatory, and reputational risks.
From a decision-making perspective, the current directions of S/MIME development lead to three fundamental conclusions. First, automation of the email certificate lifecycle becomes a necessity in environments where the scale of users and mailboxes makes manual security management impractical. Second, long-term confidentiality and integrity of correspondence require preparation for scenarios in which classical cryptographic algorithms will no longer be sufficient. Third, compliance with CA/Browser Forum standards is beginning to have not only operational but also audit and contractual significance, particularly in B2B relationships and regulated sectors.
For organizations that treat email as a critical business communication channel, these changes require a transition from a reactive approach to a strategic trust management model, in which S/MIME certificates are elements of a coherent PKI architecture rather than isolated technical deployments.
In response to the direction set by the CA/Browser Forum and global trust infrastructure providers, HEXSSL is developing its email certificate offering beyond the traditional model of certificate sales. The focal point is not the product itself, but rather architecture, automation, and organizational cryptographic readiness.
HEXSSL treats S/MIME as an integral part of both public and private PKI infrastructures of its customers. This includes not only certificate issuance, but also advisory services related to their role in business processes, regulatory compliance, and integration with email systems and MDM platforms. This approach enables B2B customers to move from isolated deployments to a coherent model of identity and trust management in email communication.
With the formal acceptance of ACME in S/MIME standards, we prepare customers for full automation of the email certificate lifecycle. This enables deployment, renewal, and rotation of certificates without manual processes, which is critical in corporate and distributed environments.
For B2B customers, automation means:
At HEXSSL, we view ACME not as an additional feature, but as the foundation of modern certificate management, including in the email domain.
Another element of the offering is preparing organizations for post-quantum cryptography. In the context of S/MIME, this is particularly important because email messages are often retained for many years and may contain sensitive data with a long confidentiality horizon.
HEXSSL supports customers in:
This approach allows organizations to test and prepare for upcoming changes without destabilizing existing systems. Our offering in S/MIME, automation, and Post-Quantum Readiness responds to a clear market trend: B2B customers today expect a technology partner, not merely a certificate provider. Trust management, compliance, and cryptographic resilience are becoming elements of business strategy rather than solely IT responsibilities.
In this context, email certificates cease to be an operational cost and begin to function as an investment in security, reputation, and business continuity.