smartenterprisewisdom Skip to main content

Accutive Security

The Cryptography, Data Protection and Identity Security Center of Excellence

Articles How CyberArk and Venafi Products Integrate With Palo Alto Networks

How CyberArk and Venafi Products Integrate With Palo Alto Networks

Keval Varia

Senior Cybersecurity Solutions Engineer

Posted on 09/01/2026
Keval Varia is a Senior Cybersecurity Solutions Engineer with a strong background in Public Key Infrastructure, Certificate Lifecycle Management, and Code Signing. He is certified on multiple leading machine identity security platforms.
Posted on 01/09/2026

Product names rarely survive one acquisition intact, let alone two. If your runbooks, license records, or support tickets still reference Trust Protection Platform, TLS Protect Cloud, or CyberArk PAM, you’re not alone, and you’re not wrong. Those products still exist. They just don’t go by those names anymore.

Palo Alto Networks now owns CyberArk, which itself acquired Venafi in 2024. In the acquisition process, the underlying technology in both companies has been renamed, restructured, and, in some cases, folded into entirely new platforms. For practitioners, the immediate effect is a set of unfamiliar product names attached to familiar technology. And it isn’t only CyberArk and Venafi customers affected: a network customer who never bought either now has NGTS and Idira, certificate lifecycle management (CLM) and privileged access management (PAM), sitting inside a platform they already own.

What follows is a map of where each capability landed, and what it means if you own one of these platforms today.

How We Got Here: The Timeline

The ownership changes happened in quick succession:

  • October 1, 2024: CyberArk completed its acquisition of Venafi.
  • July 30, 2025: Palo Alto Networks announced its agreement to acquire CyberArk, at an equity value of approximately $25 billion.
  • February 11, 2026: Palo Alto Networks completed its acquisition of CyberArk, establishing identity security as a core pillar of its platformization strategy.
  • March 23, 2026: Next-Generation Trust Security (NGTS) became generally available.
  • May 12, 2026: Idira, Palo Alto Networks’ next-generation identity security platform, was unveiled at IMPACT.

Status of Each Platform After Acquisitions

As Venafi and CyberArk’s product lines settled into their new homes, a clear pattern emerged in where each capability landed. Cryptography and machine identity moved toward the network control plane, while privileged access moved toward the identity control plane. Trust and access are different disciplines, and keeping them on separate planes lets each platform stay focused on what it actually governs. Here’s how each technological offering has landed.

Original name CyberArk-era name Status today
Trust Protection Platform (TPP), the on premises certificate manager Certificate Manager, Self-Hosted (CMSH) Continues to be supported and sold
Zero Touch PKI (ZTPKI) N/A Continues to be sold standalone; also powers Next-Generation Trust Security (NGTS)’s private PKI
TLS Protect Cloud (TLSPC) Certificate Manager SaaS (CMSaaS) Evolved into NGTS
CyberArk PAM, Secrets, Workload Identity CyberArk Identity Security Platform Idira

What NGTS Means for Network Teams

Venafi’s certificate management technology has been through several names, from TLS Protect Cloud to Certificate Manager SaaS under CyberArk, and now sits inside Palo Alto Networks as NGTS, embedded directly in Strata Cloud Manager alongside firewalls, GlobalProtect gateways, and SASE services. In practice, that means certificate visibility, automated renewals, and CA-neutral orchestration now run from the same control plane as network enforcement, closing the gap between certificate governance and the transitions, distrust events, and reissuance that used to catch teams off guard. NGTS also includes SaaS-based private PKI, which is Zero Touch PKI, still sold standalone as well. It shifts CA hosting to Palo Alto rather than removing HSMs from the picture, so key custody becomes the question to work through.

For the mechanics behind each of these, Accutive Security’s deep dive on NGTS is worth a read. NGTS covers half of what’s significantly changed. The other half is identity, and that’s where platform teams feel the shift next.

Accutive Security is a longstanding Advanced Venafi CyberArk Partner

What Idira Means for Identity and Platform Teams

Idira is positioned as the next-generation identity security platform built on CyberArk’s foundation. Existing CyberArk customers can keep using the platform as before, with cross-platform capabilities across the broader Palo Alto Networks portfolio arriving over time rather than all at once.

The platform extends privileged access controls beyond human identities to machine and AI agent identities, all under a single framework. That’s a meaningful shift from how PAM has traditionally worked: instead of separate tools for employee access, service accounts, and now autonomous agents, Idira applies one consistent set of rules across all three.

The architecture behind it is built around a zero standing privilege model. Rather than credentials sitting active and available at all times, access gets provisioned dynamically, granted when it’s needed and pulled back when it isn’t, all coordinated through a centralized control plane.

That framework is already reaching outward. CyberArk’s capabilities are being deeply integrated into Palo Alto Networks’ Strata and Cortex platforms, strengthening identity verification for AI agents across those platforms too, rather than staying contained to Idira alone.

Put the two platforms next to each other, and the shape of the strategy becomes clear. Machine identity now spans both sides of the portfolio: certificates on the NGTS side, and secrets, workloads, and agents on the Idira side. That adjacency is exactly why both platforms matter to the same buyer. One governs what a machine identity proves. The other governs what it’s allowed to do.

Continuity for Legacy Venafi Deployments

For CyberArk’s own end-users, the ownership change has been straightforward: a single shift, from CyberArk to Palo Alto Networks. Venafi’s road here has been longer: it’s changed hands twice, first into CyberArk, then into Palo Alto Networks. That matters if you’re one of the customers carried through both, watching product names shift twice in the span of about sixteen months.

Legacy Venafi TPP, now Certificate Manager Self-Hosted, continues to be both supported and actively sold, and so does Zero Touch PKI. Neither has been quietly deprioritized in favor of pushing everyone toward NGTS. TLS Protect Cloud is the different case: it has now evolved into NGTS.

Tooling and integrations haven’t fragmented across the transition either. The VenafiPS automation module works across Certificate Manager Self-Hosted, Certificate Manager SaaS, and NGTS, and cert-manager’s issuer still honors the older Venafi configuration naming, “Venafi TPP” mapping to Certificate Manager Self-Hosted and “Venafi Cloud” to Certificate Manager SaaS, so existing automation doesn’t need to be rebuilt from scratch, whether you’ve moved to NGTS or not.

The practical takeaway: self-hosted customers face no forced migration event, and customers who were on TLS Protect Cloud are already on the platform that became NGTS rather than facing a cutover to something unfamiliar. For most estates, what has changed is the naming, and that’s worth taking seriously in its own right. Internal documentation, runbooks, and license records that still reference old product names are worth reconciling against what things are actually called today, if only so the next audit or support ticket doesn’t turn into a scavenger hunt through three generations of branding.

Map the Future of your Venafi and CyberArk Platforms

Start with a Health Check led by certified experts

Where the Integration Is Heading

A few directional signals are worth tracking here. One is enforcement continuity: firewalls, GlobalProtect gateways, SSL inspection, and SASE services all depend on certificates staying valid, and the direction is toward catching renewals ahead of time instead of after an outage. Certificate governance and network telemetry are also converging in Strata Cloud Manager rather than sitting in separate views, a detail worth noting whether you’re running Palo Alto Networks end to end or pairing it with a CLM tool like Keyfactor or AppViewX. For a mixed environment, the open question worth asking is how that convergence fits your setup: does it mean read-only visibility alongside your existing CLM tool, or does it assume Palo Alto Networks is managing the full certificate lifecycle? That one is not settled yet.

Post-quantum migration is a second area to watch. Right now, cryptographic upgrades tend to happen team by team, unevenly. The direction here points toward treating the network as one coordinated reissuance effort rather than leaving each team to solve it independently, useful in principle, though how smoothly that plays out will depend on how well certificate governance and network enforcement actually talk to each other in practice.

There’s also Prisma AIRS in the picture, Palo Alto Networks’ platform for securing AI agents as they act autonomously across an environment. Prisma AIRS 3.0 natively integrates with Idira, extending identity security and privilege controls to AI agents, while Cortex receives first-party identity signals from Idira to sharpen detection and trigger automatic response when something looks compromised.

What This Means for Your Environment

Where this all lands for you comes down to where you started. There’s no single path forward here. It’s a handful of different roads, branching off depending on which door you walked in through.

If you’re on legacy Venafi TPP, now Certificate Manager Self-Hosted, start with an inventory. Confirm your entitlements map correctly under the current naming, and evaluate NGTS on its merits rather than assuming a migration is mandatory. If you were on TLS Protect Cloud, you’re already on the lineage that became NGTS. The question isn’t whether to move. It’s which capabilities your current entitlement actually covers. If you’re a CyberArk Privileged Access Management (PAM) customer, the upgrade path to Idira varies by tier. Traditional PAM customers get discovery and user experience improvements automatically, with Zero Standing Privilege and agentic/machine identity protections available as paid add-ons.

Modern PAM customers on Enterprise or Dev tiers get discovery, Zero Standing Privilege, and user experience enhancements at no additional cost. Workforce Access customers get immediate user experience improvements too, with the option to upgrade to full Zero Standing Privilege, traditional PAM, and machine protections. Customers already running Secrets or Workload licenses can add traditional PAM and Zero Standing Privilege through new licenses to consolidate management on Idira.

And if you’re a Palo Alto Networks network customer who never had a certificate lifecycle management program to begin with, this isn’t something to evaluate from scratch. It’s already sitting inside a platform you own. That’s worth acting on given where the industry is headed: public TLS certificate lifespans are shrinking toward 47 days, and most organizations still haven’t automated certificate renewal. Palo Alto Networks itself frames the resulting gap as a business continuity risk, not just an operational inconvenience.

Where Accutive Security Fits

Our work here starts with entitlement reconciliation. We match what an environment actually holds today against three generations of naming: Venafi’s original products, CyberArk’s interim rebrand, and Palo Alto Networks’ current lineup. That way, nothing gets lost in translation between TLSPC, Certificate Manager SaaS, and NGTS. From there, the assessment turns practical: which platform, Idira or NGTS, actually serves which part of the estate, and where legacy self-hosted deployments still make sense to keep running as-is. Migration, where it’s warranted, gets planned in phases rather than forced in one move.

For existing Palo Alto Networks clients, we explain the features and functionality of the NGTS and Idira platforms, and assess whether these solutions would enhance your existing cybersecurity stack.

For most clients, a PKI and certificate lifecycle management assessment is the place to start, or a quantum readiness assessment for teams further along in the post-quantum shift covered above. From there, we help build an environment that can absorb the coming shifts in both cryptography and identity security, rather than one that has to chase every change as it happens.

Running CyberArk or Venafi Under Palo Alto Networks?

A PKI and certificate lifecycle assessment, led by certified experts.

Share Article

Leave a Reply

Comment

No Comments Found.
Gartner Peer Insights badge with five stars and 'Verified customer reviews' text, indicating trusted reviews.

Ready to start or accelerate your quantum readiness journey?

Connect with a Quantum Readiness Expert
Tags

No Tags

Step up your cybersecurity posture with Thales Hardware Security Modules

Seamless integrate HSMs into your cybersecurity stack

Optimized by Optimole

Download this Resource