What's Your Credential Rotation Debt?
Cumulative exposure from your current rotation cadence
"We rotate annually" sounds fine until you count how many credentials never get rotated at all — and a credential's risk isn't just whether it's rotated, but how long it sits unchanged at any given moment. This calculator turns your rotation cadence into a single cumulative figure, and shows what addressing your never-rotated bucket would actually buy you.
Your credential inventory
Group your credentials by how often each bucket actually gets rotated — not policy, practice.
Assumptions (adjust if you have better numbers)
Annual/quarterly/monthly buckets assume rotations are staggered, so a credential's average age at any moment is about half its rotation interval. The two figures below are the assumptions worth checking against your own environment.
Where the exposure comes from
| Bucket | Count | Avg. age (days) | Credential-days |
|---|
What if you addressed the never-rotated bucket?
Move a share of never-rotated credentials to automated rotation and see the effect on total exposure.
Moving credentials out of the never-rotated bucket is exactly what Phase 3 of the NHI rollout guide is built around — the usage-delta audit identifies what's safe to change, and the shadow-policy dry-run validates it before enforcement. The staged JIT migration in Phase 4 is the mechanism that actually gets a credential into the "automated" bucket above.
Export your exposure breakdown. Download this — including your inventory and the what-if comparison — as a PDF to share with your team. Requires a free subscription.