Decide why you\'re rotating.
The reason changes the urgency and the comms strategy:
- Suspected compromise. Move fast. Revoke immediately. Treat anything encrypted to the old key after the suspected compromise date as potentially compromised.
- Algorithm upgrade. Moving from RSA to Ed25519, or v4 to v6. No urgency. Normal grace period.
- Expiration. Just extend the expiration if the key is otherwise fine. Only rotate to a new key if you actually want a new identity.
- Periodic refresh. Some organizations and individuals rotate every 2–4 years as policy. Normal grace period.