If you configured SAP Cloud Identity Services when it launched 10 years ago and never touched your signing certificates since, they are about to expire — if they have not already. An expired signing certificate means invalid access tokens and broken authentication across every application in your tenant.
This is not just a maintenance task. It is an opportunity to shorten your certificate lifetimes, automate rotation, and position your organization for the post-quantum cryptography transition that is already underway. Here is what you need to know.