Digital certificates, diplomas & badges

Digital credential lifecycle management

Digital credential lifecycle management is the workflow for issuing, claiming, renewing, expiring, revoking and archiving digital certificates, diplomas and badges across their full lifespan. TRUE handles every stage automatically, writes each event to a blockchain audit trail, and needs no manual monitoring in between.

Scope note: this page covers credential lifecycle for training, education and professional credentials. Healthcare provider credentialing software, such as Zivian, IntelliSoft and Symplr, is a different category.

TL;DR

Most credential programmes are built entirely around the moment of issue, and everything after it runs on spreadsheets. Lifecycle management is the other 95% of a credential's life: whether the holder claimed it, when it expires, whether they renewed, and how fast it stops verifying when it is revoked. TRUE automates all seven stages. Expiry dates are monitored continuously, renewal notices go out at 90, 60, 30 and 7 days, revocation propagates to every verification channel in seconds, and each event is written to a blockchain record that an auditor can read years later. Credentials are never deleted, so an expired or revoked one still resolves and shows its true status.

  • Seven stages: issuance, claim, active use, pre-expiration, expiration, renewal, revocation.
  • Renewal notices fire automatically at 90, 60, 30 and 7 days before lapse.
  • Revocation is immediate across QR scans, the portal and the chain record.
  • Nothing is deleted, so the audit trail survives every status change.

Why does manual credential lifecycle management break down?

Because the work arrives continuously and unevenly. Renewals fall due one at a time across the year, audits ask for complete histories on short notice, and revocation is urgent exactly when the process is slowest. A spreadsheet copes at 200 credentials and stops coping at 2,000.

Most organisations focus entirely on the moment of issuance. The credential goes out, and then the hard work begins.

Missed renewals

When renewal tracking lives in spreadsheets, things fall through. Credential holders let certifications lapse. In regulated industries, an expired credential still in use isn't embarrassing, it's legally significant.

Compliance audit failures

Regulators want complete histories: who held which certification, when it was issued, when it expired, when renewed. Providing this from spreadsheets and email archives is slow, incomplete, and error-prone.

Revocation delays

Manual revocation processes are slow. Hours or days may pass between the decision to revoke and the credential becoming unverifiable. In fraud or misconduct situations, those hours matter.

Scale limitations

What works for 200 credentials breaks at 2,000. Manual lifecycle management requires proportionally more staff as programme volume grows, a ceiling that automated systems don't have.

What forces credentials to have a lifecycle at all?

Regulators do. Continuing competence rules put a clock on professional credentials, and EU law is moving those credentials into wallets that expect a current, machine checkable status. Meanwhile most employers never check the status at all. All three figures below are from a regulator or published third party research.

  • UK nurses and midwives revalidate every three years, and must complete 35 hours of CPD in each cycle, at least 20 of them participatory. That is a hard renewal deadline attached to every individual record. Source: Nursing and Midwifery Council.
  • Every EU Member State must offer at least one EU Digital Identity Wallet by 2026, built to common specifications, and the Commission names education diplomas among the documents those wallets will hold. Source: European Commission, on Regulation (EU) 2024/1183, adopted 20 May 2024.
  • Only 52% of large employers verify all the academic credentials they are shown, falling to 37% at medium sized organisations and 29% at small ones. Source: Prospects Luminate, November 2025, from a YouGov survey of 526 HR decision makers.

A credential whose status is published and current answers the regulator and the employer with the same lookup, which is the point of managing the lifecycle rather than the send.

What does automated lifecycle management handle?

Four things a person would otherwise chase: watching expiry dates, sending renewal notices, executing revocations, and answering the question of what state the whole programme is in right now. Each one runs without anybody remembering to run it.

Remove the human bottleneck from every post-issuance stage.

Proactive expiration tracking

Every credential has an optional expiration date. TRUE monitors all dates automatically, surfacing credentials approaching expiry in your dashboard and triggering notifications at 90, 60, 30, and 7 days before lapse.

Automated renewal notifications

TRUE sends branded renewal notifications directly to credential holders at configurable intervals, with expiration date, renewal requirements, and direct action link. New credentials issue automatically on completion.

Instant revocation

Revocation processes in seconds. QR scans, verification portal, and blockchain record all update immediately. No delay, no window of exposure after the decision is made.

Real-time status dashboard

At any moment, see your complete programme: Active | Expiring Soon | Expired | Revoked | Renewal Pending | Unclaimed. Complete visibility without running reports or querying spreadsheets.

What are the seven stages of a credential lifecycle?

Issuance, claim, active use, pre-expiration, expiration, renewal and revocation. Each stage has a trigger and writes its own timestamp to the blockchain record, so the credential's whole history stays readable long after the programme that produced it has changed.

1. Issuance

Trigger: completion

Credential created and delivered. Blockchain record written with an immutable issuance timestamp. Expiration countdown begins. Claim tracking starts.

2. Claim

Trigger: recipient accepts

Credential marked claimed and visibility preferences captured. It becomes publicly verifiable, analytics begin, and the claim timestamp is written to the blockchain.

3. Active use

Trigger: ongoing

Views, shares and verifications tracked continuously, with geographic analytics. The expiration countdown is monitored in the background.

4. Pre-expiration

Trigger: notification window

Renewal notices sent at defined intervals. Dashboard status moves to expiring soon, reminders escalate, and an administrator alert fires if the holder does not respond.

5. Expiration

Trigger: end date reached

Status updates instantly and verification reflects it. The expiration timestamp is recorded on chain. The credential stays accessible for audit with its expired status shown.

6. Renewal

Trigger: holder completes renewal

A new credential issues with updated dates. The previous one is archived rather than deleted, and the blockchain records the relationship between them.

7. Revocation

Trigger: administrator action

Immediate. Every verification channel updates within seconds, the reason is recorded internally, and the blockchain carries a timestamped revocation record showing who revoked it and when.

What does the blockchain audit trail record?

Six event types, each with a timestamp that cannot be rewritten: issuance, claim, every verification, every renewal cycle with its predecessor link, expiration, and revocation with the administrator who initiated it. That is the record an auditor asks for and the one a spreadsheet cannot produce.

What regulators expect, and what TRUE delivers.

Lifecycle EventWhat Is RecordedBlockchain?
IssuanceTimestamp, issuer, recipient, credential detailsImmutable
ClaimWhen and how the credential was acceptedImmutable
Verification eventsEvery verification with timestamp and geographic dataImmutable
RenewalEach renewal cycle with dates and predecessor relationshipImmutable
ExpirationTimestamp when credential lapsedImmutable
RevocationTimestamp, initiating administrator, reasonImmutable

How long does lifecycle automation take to implement?

About four weeks: a week auditing the credentials you already have, a week designing expiry and renewal rules, a week integrating and configuring notifications, and a week testing full lifecycle scenarios before going live with the next cohort.

Week 1

Lifecycle audit

  • Inventory active credentials
  • Map expiration patterns
  • Define compliance requirements
  • Identify integration points

Week 2

Workflow design

  • Set expiration rules per type
  • Define notification schedules
  • Design renewal workflow
  • Configure revocation process

Week 3

Integration

  • API / webhook setup
  • Notification templates
  • Dashboard configuration
  • Compliance report scheduling

Week 4

Launch

  • Full lifecycle scenario testing
  • Staff training
  • Compliance team sign-off
  • Go live for next cohort

How do you value automating the credential lifecycle?

By costing the staff time renewals consume today and by pricing the exposure that a slow revocation leaves open. The first is arithmetic you can do from your own numbers. The second depends entirely on your regulator, so treat any figure attached to it as your legal team's to supply, not ours.

Staff time on renewals

Time your own renewal handling, then multiply by annual renewal volume. At 1,000 renewals a year, every minute of handling is roughly 17 hours of staff time. Automation removes the tracking, the chasing and the reissuing.

Compliance exposure

An expired credential still being relied on is a finding in any regulated audit. TRUE does not publish a monetary figure for that risk, because penalties vary by regulator and jurisdiction. What TRUE provides is the complete, timestamped history an audit asks for.

Revocation window

Manual revocation can leave hours between the decision and the credential ceasing to verify. TRUE closes that window to seconds, which is the part that matters in fraud, misconduct and termination cases.

What do teams ask about credential lifecycle management?

Four questions: how renewal tracking works, how fast revocation takes effect, what the audit trail contains, and whether expired credentials remain readable. The last answer is yes, and it is the one auditors care about most.

How does automated renewal tracking work?

TRUE monitors all credential expiration dates automatically and triggers configurable notifications to credential holders at defined intervals (e.g., 90, 60, 30, 7 days before expiry). No manual monitoring required.

How quickly can credentials be revoked?

Revocation is instant. From the moment of revocation, all verification channels update immediately. QR code scans, verification portal, and blockchain record all reflect the change.

What does the blockchain audit trail include?

Every lifecycle event is captured immutably: issuance timestamp, claim, each verification with timestamp and location, all renewal cycles with predecessor relationships, expiration timestamp, and revocation with initiating administrator and reason.

Are expired credentials still accessible for audit?

Yes. Credentials are never deleted. They remain accessible with their expired status clearly displayed. The complete history is preserved on blockchain indefinitely, satisfying even the most demanding regulatory audit requirements.

What do TRUE customers say?

Two issuers on running credentials as a managed programme rather than a one off send. Both handle recurring cohorts, so the value they describe sits after issuance, in what happens when a credential is opened, shared, checked or renewed.

“The animation looks fantastic, and it’s so simple for our recipients. It has made things much easier for us at Sitevision with the digital certificates.”
Jessica Adolfsson, Customer Success Manager, Sitevision
“We are very happy with our work with TRUE Original. Their technology let our customers get lots of positive attention.”
Martin Hägerdal, CEO, Kvalprak

Stop managing renewals in spreadsheets

Automate every stage of your credential lifecycle, with blockchain-secured audit trails that satisfy the most demanding compliance requirements.