Certificate lifecycle and outage risk
Treat a KSeF certificate as a time-limited identity credential, not as a permission record or a complete business identity. KSeF checks permissions server-side, so replacing a certificate does not itself grant an ERP, employee or service provider authority to act for a company. Operational failure usually occurs elsewhere: the certificate expires unnoticed, the private key is unavailable, a connector loads the wrong credential, or teams revoke the old certificate before the replacement is proven. Map the lifecycle from request and secure key generation through deployment, monitoring, replacement and final revocation. Assign a service owner for invoice continuity, a credential owner for issuance and custody, and an application owner for each deployment. Keep compromise response separate from routine expiry rotation: suspected key exposure calls for containment and rapid revocation decisions, while planned rotation can use a tested transition and rollback path.