Okay, A replaced NAC could have the certificate enforced down to the device, but a new NAC will need to go through the process outlined in this document to install the certificates on a per-nac basis. Since your using 802.1x, you will need to go through the CSR process as well.