Local government units should assign digital certificate expiration reminder ownership to a named primary owner, a backup owner, and an escalation official. The certificate holder still protects and uses the certificate, while assigned staff monitor dates, application progress, affected signing work, and completion evidence. This shared control reduces the risk of an expired certificate interrupting an approval.
This guide concerns Philippine National Public Key Infrastructure (PNPKI) end-user signing certificates, not Secure Sockets Layer certificates used by websites. LGUs using GoLGU digital signature workflows for Philippine LGUs need a repeatable ownership process long before a certificate reaches its valid-to date.
Who Should Own Digital Certificate Expiration Reminders?
The local government unit (LGU) should assign one primary reminder owner for routine monitoring and one backup reminder owner for absences, transfers, and unresolved actions. A department head or other designated official should receive escalations when a delay threatens a required signing activity.
The LGU certificate lifecycle owner should coordinate the record, but should not use another employee’s certificate or collect the holder’s private credentials. The certificate holder remains responsible for completing the application and protecting the private key, personal identification number, and password.
Commission on Audit (COA) Circular No. 2021-006 directs government entities using electronic signatures to designate a focal person for electronic-signing implementation. An LGU should place reminder coordination with this electronic signing focal person or another authorized office under its written procedures.
Why Should Reminder Ownership Extend Beyond the Certificate Holder?
A holder might overlook an email, change official addresses, take extended leave, or move to another post. A reminder process tied to one inbox leaves no clear path for certificate holder follow-up when a required document approaches its signing date.
Shared ownership separates three duties. The holder completes requirements and controls the certificate. The primary owner monitors the signing certificate expiration date and application status. The backup owner checks missed actions and alerts the assigned official. This division supports continuity without transferring signing authority.
The backup reminder owner does not become an alternate signer by default. Any alternate signing arrangement must follow the LGU’s approved delegation, authorization, records, and audit requirements.
Which Certificate Details Should the LGU Record?
The LGU should keep enough non-secret information to identify each certificate and its affected signing work. A digital certificate status register should include the holder’s name, office, authorized signing function, certificate type, non-secret certificate identifier, valid-from date, valid-to date, responsible owners, and current application stage.
The register should also identify recurring documents that depend on the certificate. Examples include a monthly report, an approval batch, or a submission that must remain in its original electronic form. This link between the certificate and the document route helps staff see the operational effect of delay.
Never store a private key, certificate password, personal identification number, or one-time password in the register. The PNPKI Digital Certificate Subscriber Agreement states that only the subscriber should use the certificate and that the subscriber must protect the private key and its activation credentials.
How Should Primary and Backup Owners Divide Their Work?
The primary owner should maintain dates, issue reminders, confirm current application requirements, record missing items, and monitor completion. The backup owner should review open records at agreed checkpoints and act when the primary owner is absent or a response stays overdue.
The electronic signing focal person should oversee the LGU’s approved procedure, keep roles clear, and bring unresolved risks to the proper official. The certificate holder should respond to reminders, submit accurate requirements, and report changes that affect the application.
Assign names and positions, not office names alone. “ICT Office” does not tell staff who acts today. A named primary owner with a named substitute creates accountability while an office assignment keeps the duty connected to the organization.
When Should Reminder and Escalation Checkpoints Begin?
No single official PNPKI schedule sets the same reminder interval for every LGU. Each LGU should set checkpoints after checking current Department of Information and Communications Technology (DICT) requirements, its internal review steps, expected signing dates, staff availability, and observed application time.
For a PNPKI certificate expiration reminder, an LGU may organize its work through the following action sequence:
- Preparation: Confirm the certificate record, holder details, current requirements, affected documents, and approved owners.
- Application: Check whether the holder submitted a complete new application and record any missing requirement.
- Escalation: Refer an unresolved delay to the designated official before the affected document reaches its signing deadline.
- Continuity: Confirm the approved alternative for documents that still require action.
- Closure: Record issuance of the new certificate, check the affected route, and store completion evidence.
These stages are recommended internal controls, not DICT-prescribed deadlines. The LGU should review its schedule when requirements, staffing, or processing experience changes.
The PNPKI certificate expiration reminder should name the required action, responsible person, status date, and next review point. A clear reminder asks for a verifiable update instead of a vague reply.
How Should LGUs Handle a New PNPKI Certificate Application?
DICT states that an end-user digital certificate is valid for up to two years from issuance. After expiration, the holder must apply for a new certificate and satisfy the application requirements again. The PNPKI Certificate Practice Statement also says end-user subscriber certificates are not subject to renewal. A new certificate with new keys follows the initial issuance process.
The record should therefore use “new application,” not “automatic renewal.” For each new PNPKI certificate application, the owner should record only the operational stage, such as preparation, submitted, pending requirements, under processing, issued, or closed. Staff should confirm current instructions through official PNPKI channels because requirements and submission procedures might change.
The owner supports tracking. The holder remains responsible for identity information and application requirements. The process should never let another employee impersonate the holder or control the holder’s private key.
What Should the Expiration Ownership Record Include?
A compact ownership record gives each responsible person the same status view. The following fields support the process:
| Record field | Purpose |
|---|---|
| Certificate holder and office | Identifies the subscriber and organizational location. |
| Approved signing function | Connects the certificate to authorized document work. |
| Certificate type and non-secret identifier | Distinguishes the signing certificate without storing credentials. |
| Valid-from and valid-to dates | Sets the monitoring period and expected preparation window. |
| Primary and backup owners | Shows who monitors, substitutes, and escalates. |
| Application-support office and status | Shows where support comes from and what action remains. |
| Affected signing workflow | Identifies documents at risk if the certificate expires. |
| Last follow-up and escalation official | Preserves the latest action and the next decision point. |
| Issuance confirmation and evidence location | Supports verification and formal closure. |
The digital certificate status register should show who updated the record and when. Access should stay limited to personnel with a valid business need.
What Happens When the Reminder Owner Transfers or Takes Leave?
Open items should pass to the backup owner through a recorded handoff. The handoff should list certificates approaching expiration, pending requirements, last contact dates, affected signing work, and upcoming escalation points.
The LGU should also review digital signing access after staff transfers. Reminder ownership and access authority are separate controls. Changing the reminder owner does not change who holds or uses a signing certificate.
A quarterly review of owner assignments helps prevent orphaned records. The LGU certificate lifecycle owner should confirm that the primary person, substitute, and escalation official still hold the assigned duties.
How Should LGUs Protect Private Keys and Certificate Passwords?
Ownership records should contain dates and status information, not secrets. The certificate holder must keep the private key and its activation credentials confidential. No reminder owner, supervisor, or support employee should ask the holder to share them.
If the holder suspects loss, exposure, or compromise, the matter requires prompt reporting through the applicable PNPKI and LGU procedure. The Subscriber Agreement links suspected compromise to a revocation request. An expiration process should never replace the separate incident and revocation process.
LGUs should also prepare employees for PNPKI digital signature training so holders understand their responsibilities before receiving signing work.
What Should Happen Before a Certificate Expires?
The primary owner should confirm the holder’s new application status, unresolved requirements, expected signing dates, and approved continuity arrangement. The owner should also document each certificate holder follow-up without copying sensitive application files into an informal log.
COA Circular No. 2021-006 states that a certificate used to sign a document should be valid, unexpired, and unrevoked at the time of signing. The same guidance calls for updated records when certificates expire or are revoked. The LGU should stop treating an expired certificate as available for new signing work.
An expired PNPKI certificate response should state who verifies the status, who informs the affected office, what approved route applies to pending documents, and who confirms the new certificate before normal signing resumes.
The LGU should test its expired PNPKI certificate response against a real recurring document before a disruption occurs. The test should confirm notification, decision authority, record handling, and safe resumption steps.
What Evidence Closes the Reminder Process?
A reminder record should close only after the responsible office verifies issuance of the new certificate and checks the related signing route. An email saying “done” gives less assurance than a recorded issuance confirmation, status update, and named verifier.
Useful closure evidence includes the new certificate’s non-secret identifier, valid-to date, issuance confirmation, verification date, verifier, affected route check, and controlled evidence location. The record should show the date normal signing resumed.
Digital signature continuity planning also needs a short review of any delay, missed checkpoint, or unclear handoff. The LGU should revise owners or timing based on observed evidence rather than an assumed processing period.
What Does the Process Look Like for a Recurring Monthly Report?
Consider a department head who signs a monthly electronic report. The signing certificate expiration date falls near the next reporting period. The primary owner confirms current requirements and asks the holder to prepare the new application. The owner records the status without collecting the holder’s credentials.
The holder submits the requirements but one item stays unresolved. The primary owner records the missing item and the latest contact. Before the report deadline, the backup owner sees the open status and refers the risk to the designated official.
The workflow owner checks the LGU’s approved alternative for the report. Staff do not share the department head’s certificate, imitate the signature, or invent a substitute route. Once the new certificate is issued, an authorized person verifies the status and tests the approved signing path. The record then closes with evidence.
This example shows why digital signature continuity planning connects certificate status with real documents. A reminder has value only when the LGU knows which service, report, or approval depends on the certificate.
How Does GoLGU Support Controlled Digital Signing Workflows?
GoLGU supports controlled digital signing workflows by placing requestors, approvers, and remote signing activities within an organized Enterprise Resource Planning (ERP) environment. Authorized staff should still maintain certificate ownership records that show assigned owners, expiration dates, open follow-ups, escalations, and affected document routes.
Role-based access should keep reminder records separate from private keys and certificate passwords. Technology does not decide who holds legal or administrative authority. The LGU must define the responsible offices, alternate arrangements, evidence requirements, and escalation path.
Clear digital certificate expiration reminder ownership connects those rules to named people and dated actions. Department heads should review the assignments whenever staffing or signing responsibilities change.
For a review of your current ownership records and signing routes, request a GoLGU digital signature workflow consultation.
Frequently Asked Questions
How long is a PNPKI digital certificate valid?
DICT states that a digital certificate stays valid for up to two years from issuance. The certificate’s own valid-to date should control the LGU’s monitoring record.
Is an expired PNPKI certificate renewed or replaced?
For end users, PNPKI requires a new certificate application after expiration. DICT says all application requirements must be satisfied again, and its Certificate Practice Statement specifies a new certificate with new keys.
Who should own certificate expiration reminders in an LGU?
Digital certificate expiration reminder ownership should sit with a named primary owner, supported by a named substitute and an escalation official. The holder completes the application and protects the certificate.
What happens when the primary reminder owner is unavailable?
The backup should receive a recorded handoff, review open actions, continue reminders, and escalate unresolved risk under the approved LGU procedure.
Should the expiration record contain the certificate password?
No. The record must exclude passwords, private keys, personal identification numbers, one-time passwords, and other activation secrets.
References
- DICT PNPKI Frequently Asked Questions
- PNPKI Certification Practice Statement
- COA Circular No. 2021-006
- PNPKI Digital Certificate Subscriber Agreement
- Republic Act No. 8792, Electronic Commerce Act of 2000
- Republic Act No. 12254, E-Governance Act
Disclaimer
This guide provides general operational information for Philippine LGUs. Each LGU should confirm current PNPKI requirements and align its procedure with applicable laws, COA guidance, DICT instructions, records rules, security policies, and authorized local approvals.
Sign in to leave a comment.