PKI Assessment & Architecture

Assess your PKI. Find what's hiding.

A structured review of your certificate infrastructure: uncover weaknesses and define the architecture you need.

Whether your PKI was built ten years ago or last quarter, it has accumulated decisions that made sense at the time and may not hold up now. We assess the full estate: root and issuing CAs, certificate profiles, key algorithms, HSM posture, revocation infrastructure, enrolment flows and operational runbooks. You get a prioritised architecture document you can act on.

7Assessment domains
20 yrArchitecture horizon
1 dayTo findings workshop

What we assess

Seven areas that determine whether your PKI will survive the next audit cycle.

Trust hierarchy review

Map every root, intermediate and issuing CA. Identify orphaned CAs, expired intermediates and trust paths that should not exist.

Cryptographic posture

Key algorithms, key sizes, signature hashes. Flag RSA-1024, SHA-1 and other legacy crypto that fails modern compliance checks.

Certificate profiles

Review naming conventions, validity periods, key usage extensions and subject naming. Catch profiles that are too permissive or misconfigured.

Revocation readiness

OCSP responder availability, CRL freshness, AIA chase-up paths. If revocation takes hours instead of seconds, that is a finding.

HSM & key protection

Where are root keys stored? Are they extractable? Is there a key-ceremony record, or was the root generated on a laptop?

Enrolment & automation

How are certificates requested, approved and distributed? Is renewal automated or manual? Are there shared enrolment passwords in circulation?

Operational runbook

Is there a documented incident response? Key rotation procedure? Disaster recovery plan? If the answer is "in someone's head", that is a finding.

Get a prioritised architecture, not a 200-page report

You get a clear architecture document with prioritised findings: what to fix now, what to fix next quarter, and what is fine as-is. No padding, no generic filler. Just the specific gaps in your PKI and the steps to close them.