Non-Human Identity Software
an independent guide to NHI security software
Subscribe
Tool

What's Your Credential Rotation Debt?

Cumulative exposure from your current rotation cadence

"We rotate annually" sounds fine until you count how many credentials never get rotated at all — and a credential's risk isn't just whether it's rotated, but how long it sits unchanged at any given moment. This calculator turns your rotation cadence into a single cumulative figure, and shows what addressing your never-rotated bucket would actually buy you.

Your credential inventory

Group your credentials by how often each bucket actually gets rotated — not policy, practice.

Never rotatedCreated once, still valid, no rotation has ever occurred
Rotated annually~365-day cycle
Rotated quarterly~90-day cycle
Rotated monthly~30-day cycle
Automated / short-livedDynamically issued, e.g. via Vault — hours, not days
Assumptions (adjust if you have better numbers)

Annual/quarterly/monthly buckets assume rotations are staggered, so a credential's average age at any moment is about half its rotation interval. The two figures below are the assumptions worth checking against your own environment.

Average age of never-rotated credentialsIn days — 730 ≈ 2 years is a common starting point for legacy credentials
TTL for automated/short-lived credentialsIn hours — e.g. a 60-minute Vault lease
Estimated cumulative exposure
188,376
credential-days — roughly 516 cumulative years across 800 credentials

Where the exposure comes from

Bucket Count Avg. age (days) Credential-days

What if you addressed the never-rotated bucket?

Move a share of never-rotated credentials to automated rotation and see the effect on total exposure.

Share of never-rotated credentials moved to automated rotationThe rest of this bucket is left as-is 50%

Moving credentials out of the never-rotated bucket is exactly what Phase 3 of the NHI rollout guide is built around — the usage-delta audit identifies what's safe to change, and the shadow-policy dry-run validates it before enforcement. The staged JIT migration in Phase 4 is the mechanism that actually gets a credential into the "automated" bucket above.

Export your exposure breakdown. Download this — including your inventory and the what-if comparison — as a PDF to share with your team. Requires a free subscription.

See what's in the paid edition →