Managed PKI Certificates
High-assurance, WebTrust-audited PKI — without the infrastructure overhead
Managed PKI Certificates is a fully managed, cloud-hosted certificate platform for users, devices, workloads, and services. Built for regulated and high-compliance environments, it gives you WebTrust-audited private certificates — with audit pass-through for SOC2, HIPAA, and supply chain requirements — delivered as a shared-service subscription. No CA infrastructure to operate.
What are Managed PKI Certificates?
Managed PKI Certificates are digital identities issued from a managed, cloud-hosted platform that utilizes a highly secure, multi-tenant architecture. This product is uniquely governed by a continuous WebTrust audit, providing customers with a shared, high-assurance infrastructure that maintains strict logical isolation for certificate issuance, policy enforcement, and lifecycle automation.
Key Value Propositions
Security by Design
Operational Efficiency
Compliance and Governance
Enterprise Scale
Core Capabilities: Issued from a dedicated private root of trust outside the CA/Browser Forum. WebTrust-compliant issuance governed by the same audit standards as public roots. Supports SCEP, EST, ACME, and REST API enrollment. All keys are HSM-backed with FIPS 140-2/3 alignment. High-availability OCSP and CRLs for real-time verification.
Key benefits
Root of Trust
Inherit SSL's WebTrust audit evidence for your PKI, without building or funding your own audit program.
WebTrust-Compliant
Partners, regulators, and customers can inspect your CA's audited governance, not just its certificates.
HSM-Backed Security
ACME, SCEP, EST, REST API enrollment, built for DevSecOps, Kubernetes, MDM, and factory-floor issuance.
Namespace Protection
All CA private keys generated and stored in certified hardware, never exportable in plaintext.
Automated Enrollment
Hybrid post-quantum profiles (ML-KEM, ML-DSA, SLH-DSA) available at the Ecosystem/IoT tier.
Validation Services
Same API used for public-trust certificates, no separate integration required.
Elastic billing
Certificate inventory, expiration forecasting, immutable audit logs, SIEM/SOAR integration.
Request Early Access
Join the Early Access programme to start using Managed PKI Certificates, lock in launch pricing, and shape the product roadmap. Indicate your tier and primary use cases — Professional and Enterprise tier accounts are being onboarded now; Ecosystem/IoT accounts are available on request.
Common Use Cases
High-Assurance IoT & Device Identity
High-assurance IoT and device identity for secure boot, firmware updates, and mutual TLS in industrial IoT, medical devices, automotive systems, and critical infrastructure.Supply Chain Trust
Supply chain trust: providing cryptographic proof of trust for third-party onboarding, partner extranets, and supplier authentication in B2B ecosystems.Regulatory Compliance
Regulatory compliance: meeting SOC 2 Type II, HIPAA Security Rule, GDPR Article 32, and PCI DSS v4 requirements via audit-ready certificate infrastructure with documented controls.Zero Trust Architecture
Zero Trust architecture: securing machine-to-machine communication with audited governance. Every workload, service, and device gets a cryptographically verified identity enforced at connection time.PQC Transition
PQC transition: testing quantum-resistant certificate profiles (ML-KEM, ML-DSA, SLH-DSA) to future-proof internal systems before NIST PQC mandates become production requirements.Platform Architecture
Compliance & standards
WebTrust for CAs
SSL's dedicated PKI operations are covered by the same WebTrust audit as our public trust platform.
FIPS 140-2 Level 3
RFC 5280 (X.509)
ACME RFC 8555
SCEP / EST
NIST PQC standards
Service tiers
Pricing is indicative during Early Access — lock in launch pricing by joining the waitlist.
Professional
- Internal mTLS, VPN, baseline compliance
- Up to 500 active certificates
- WebTrust audit pass-through
- HSM-backed signing keys
- SCEP, EST, ACME, REST API
- Namespace validation included
Enterprise
- Automated environments (Kubernetes, MDM, Intune)
- Up to 5,000 active certificates
- Includes Hybrid PQC (Post-Quantum) readiness
- Lower effective per-cert cost
- Lower per-cert overage rate
- Everything in Professional
Ecosystem / IoT
- High-volume device "birth certificates"
- Up to 100,000 active certificates
- High-throughput APIs
- Custom OIDs for device metadata
- Best volume amortisation
- Everything in Enterprise
Subscription logic & benefits
- Active inventory billing. Pricing is based on concurrent “Active” certificates rather than total issuance, supporting high-velocity DevOps workflows where certificates rotate frequently. Active = Total Issued − (Expired + Revoked).
- Audit inheritance. Your subscription includes access to SSL.com’s WebTrust for CAs audit reports, allowing you to satisfy SOC2, HIPAA, or specialised industry requirements by passing through the compliance of our audited data centres and processes.
- Namespace validation. Every tier includes rigorous vetting and reservation of your private namespaces (e.g.,
*.internal.yourcompany.com) to ensure your identities are unique and protected from overlap with other tenants. - HSM-backed security. All private keys are generated and stored in FIPS 140-2 Level 3 Hardware Security Modules — a core requirement for high-assurance use cases.
Frequently asked questions
Managed PKI Certificates is currently in Early Access. Join the waitlist to get priority onboarding, input into the roadmap, and locked-in launch pricing. Professional and Enterprise tier accounts are being onboarded now; Ecosystem/IoT accounts are available on request.
In this shared environment, you utilize a high-assurance infrastructure shared between different customers to reduce overhead. This grants you "audit pass-through" capabilities to meet SOC2 mandates by inheriting the provider's certified operational rigor.
This audited status ensures your private certificates provide documented proof of governance through auditor-witnessed Key Ceremonies and tamper-evident logs — essential for securing supply chains and ensuring the legal non-repudiation of digital signatures.
We use an Elastic Inventory model: Active = Total Issued − (Expired + Revoked). You are only billed for what is currently valid and usable in your environment.
All keys used to sign your certificates are stored in FIPS 140-2 Level 3 Hardware Security Modules (HSMs). While the physical hardware may be shared, keys are cryptographically isolated per customer and protected by strict RBAC and dual-control requirements.
Three subscription tiers (Professional, Enterprise, Ecosystem/IoT) with included active certificate thresholds of 500, 5,000, and 100,000 respectively. Pricing is indicative and subject to change while the product is in Early Access. The effective per-certificate cost decreases at higher tiers, and the per-certificate overage rate also drops at higher tiers — so customers running close to the threshold get cheaper overages on the higher tiers.
Managed PKI Certificates is a shared multi-tenant service — you don't own the Root CA, and the platform is fully operated by SSL.com. Private Enterprise PKI and Private Compliance PKI give you a fully dedicated CA hierarchy with your own Root CA. Choose Managed PKI Certificates when you need WebTrust audit pass-through at lower cost without CA infrastructure overhead; choose a dedicated product when you need your own Root CA or full self-service CA control.
Ready to start using Managed PKI Certificates?
Related Products
Private Compliance PKI
Private Enterprise PKI
Need a dedicated Root CA for internal use, without the audit overhead.