Verisign has unveiled a new security product aimed at addressing what it calls "stale trust" in digital certificate validation. The service, named Verisign Informed, provides real-time status updates for certificates, reducing the risk of systems relying on outdated or cached revocation information. The product is currently in limited beta, with a general release planned for the first half of 2027. Alongside this, Verisign has applied for the .pki top-level domain (TLD), positioning it as a potential namespace for public key infrastructure (PKI) use cases.
What Verisign Informed offers
Verisign Informed functions as an Online Certificate Status Protocol (OCSP) responder, delivering cryptographically signed responses about certificate validity. The service is designed to minimize the window during which a compromised certificate might still be trusted, a concern amplified by the accelerating speed of AI-driven exploitation. Verisign highlights its existing infrastructure, which handles approximately 8.6 million DNS transactions per second, as a foundation for scaling the new service. The company argues that traditional certificate revocation checks, which may rely on cached or outdated data, create security gaps that its real-time service aims to close.
The .pki TLD application
In a separate announcement, Verisign confirmed its application for the .pki TLD, submitted to ICANN. The company has previously stated its intent to act as a registry service provider if awarded the domain. ICANN is set to reveal all new TLD applications later this week, though no timeline has been provided for the evaluation or delegation process. Verisign has not disclosed specific use cases for the .pki namespace but suggests it could serve PKI-related scenarios, such as secure authentication or encrypted communications.
Background: The Online Certificate Status Protocol (OCSP) is a standard for checking the revocation status of digital certificates in real time, replacing older methods like Certificate Revocation Lists (CRLs). Verisign, a registry operator for .com and .net, also provides infrastructure services for DNS and PKI.
Why the announcements matter
The introduction of Verisign Informed reflects broader industry efforts to improve the responsiveness of certificate validation systems. As cyber threats evolve, the reliance on stale or cached certificate data has become a growing liability. By offering a real-time OCSP service, Verisign aims to reduce the attack surface for systems that depend on timely revocation checks. The .pki TLD application, meanwhile, signals the company’s interest in expanding its role in PKI ecosystems, though its adoption will depend on ICANN’s approval and market demand.
For operators, the beta service presents an opportunity to evaluate whether real-time OCSP responses align with their security requirements. However, the product’s effectiveness will hinge on its integration with existing PKI workflows and the willingness of systems to adopt a new dependency on Verisign’s infrastructure.
What to watch
The general availability of Verisign Informed in early 2027 will be a key milestone, as will ICANN’s decision on the .pki TLD application. If approved, the domain could emerge as a niche namespace for PKI-related services, though its success will likely depend on industry adoption and use-case development. Operators should also monitor how the service’s performance and pricing compare to existing OCSP responders, particularly in high-volume environments.
Automated pipeline · Security
Synthesized from 1 industry feed on 5 Oct 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story Verisign's application for .pki TLD is not covered in recent or older articles.
- Writing the article — Draft created article_id=653 slug=verisign-launches-real-time-certificate-status-service-applies-for-pki-tld
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states 'ICANN is set to reveal all new TLD applications later this week' without explicit confirmation of the exact date in the source. The source only mentions 'On Wednesday, ICANN will reveal all TLD applications,' which resolves to 7 October 2026 from the source publication date (5 October 2026). The phrasing 'later this week' is vague but defensible.
- Style compliance: The standfirst ('Verisign introduces a new OCSP-based service to reduce reliance on stale certificate data') slightly echoes the source phrasing ('provide current certificate status information'). While not a direct lift, it could be further paraphrased for distinctiveness.
- Quote integrity: No blockquote is used in the draft, but the source does not contain a verbatim quote suitable for one. This is compliant with style rules.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #19
- Linking related stories — Linked 4 relations from 333 candidates
- Publishing — Published verisign-launches-real-time-certificate-status-service-applies-for-pki-tld
- Mastodon — Posted https://mstdn.social/@hostingpaper/117390519944848479




Discussion · coming soon
Be the first to join the thread when community discussion launches.