Assess your PKI. Find what's hiding.
A structured review of your certificate infrastructure: uncover weaknesses and define the architecture you need.
Whether your PKI was built ten years ago or last quarter, it has accumulated decisions that made sense at the time and may not hold up now. We assess the full estate: root and issuing CAs, certificate profiles, key algorithms, HSM posture, revocation infrastructure, enrolment flows and operational runbooks. You get a prioritised architecture document you can act on.
What we assess
Seven areas that determine whether your PKI will survive the next audit cycle.
Trust hierarchy review
Map every root, intermediate and issuing CA. Identify orphaned CAs, expired intermediates and trust paths that should not exist.
Cryptographic posture
Key algorithms, key sizes, signature hashes. Flag RSA-1024, SHA-1 and other legacy crypto that fails modern compliance checks.
Certificate profiles
Review naming conventions, validity periods, key usage extensions and subject naming. Catch profiles that are too permissive or misconfigured.
Revocation readiness
OCSP responder availability, CRL freshness, AIA chase-up paths. If revocation takes hours instead of seconds, that is a finding.
HSM & key protection
Where are root keys stored? Are they extractable? Is there a key-ceremony record, or was the root generated on a laptop?
Enrolment & automation
How are certificates requested, approved and distributed? Is renewal automated or manual? Are there shared enrolment passwords in circulation?
Operational runbook
Is there a documented incident response? Key rotation procedure? Disaster recovery plan? If the answer is "in someone's head", that is a finding.
Get a prioritised architecture, not a 200-page report
You get a clear architecture document with prioritised findings: what to fix now, what to fix next quarter, and what is fine as-is. No padding, no generic filler. Just the specific gaps in your PKI and the steps to close them.