PKI Health Check (Systems Integrator)
Project Description
The engagement
Unsung was engaged by a defence sector client to conduct a comprehensive assessment of an Enterprise PKI service recently transitioned from an incumbent supplier. The health check scope encompassed documentation review, governance and operational processes, architecture assessment, and technical health evaluation of PKI platform components.
The engagement originated from client concerns regarding the quality and completeness of knowledge transfer and documentation handover during the service transition.
Why supplier transitions expose PKI estates
Service transition is the point at which undocumented knowledge becomes visible, because it is the point at which the people holding it leave. PKI is unusually exposed to this. Certificate authorities accumulate configuration decisions over years, many of them made to accommodate a specific consuming system or a particular constraint, and the reasoning behind them is frequently held informally rather than recorded. A transition process that captures the runbooks but not the rationale leaves the incoming team able to operate the service on a good day and unable to reason about it on a bad one.
The client had recognised that the handover had not delivered what it should have, and had done so early, while the incoming arrangements were still being established. That timing mattered. Concerns of this kind are more often surfaced by an incident some months later, at which point the assessment is conducted under pressure and the gap has already had operational consequences.
The assurance dimension
In a defence context the requirement extends beyond operational capability. The organisation must be able to evidence how identities are issued, managed and revoked, and to demonstrate that the controls described in policy are the controls actually in force. An incoming operator that cannot fully account for the configuration it has inherited cannot make that demonstration with confidence, whatever the underlying platform is doing. Establishing an evidenced baseline was therefore an assurance requirement as much as an operational one.
Why the scope was drawn broadly
The health check deliberately covered documentation, governance and operational process, architecture and technical platform health, rather than concentrating on the technology alone. The client's concern was about the completeness of a handover, and a handover encompasses process and knowledge as well as configuration. Assessing only the platform would have answered a narrower question than the one being asked, and would have missed the process gaps that a transition of this kind most commonly leaves behind.
Outcomes & Deliverables
Unsung delivered a comprehensive health check report providing clear visibility of PKI service health and actionable recommendations.
A detailed report presented findings across all assessed dimensions, with evidence-driven, prioritised recommendations informing a remediation roadmap and investment case. Assessment followed the four dimensions defined in scope, applying Unsung's established health check methodology within each.
Documentation review
We assessed what had been transferred against what an operator of an Enterprise PKI service actually requires: architecture documentation, configuration records, operational procedures, and the decision history explaining why the platform is configured as it is. Gaps were identified specifically rather than in general terms, since a finding that documentation is incomplete is of limited use without a statement of which documents are missing and what each is needed for.
Governance and operational process assessment
Certificate Policy, Certificate Practice Statement and supporting operational documentation were reviewed for completeness, accuracy and alignment to the compliance frameworks the client operates under. We examined whether the procedures described were being carried out in practice under the new operating arrangements, which is where transition-related gaps most often sit: the policy transfers intact, the practice does not. Findings covered ownership, escalation, change control and the routine operational tasks that a certificate service requires but which are easily dropped when responsibility moves.
Architecture assessment
The architecture was assessed against the requirements it served and against good practice for an enterprise trust hierarchy, covering the certificate authority structure, key protection arrangements, validation and revocation infrastructure, and the integrations connecting the service to the wider estate. This established both whether the design was sound and, equally importantly for an incoming operator, what the design actually was.
Technical health evaluation
Platform components were examined directly: certificate authority configuration, certificate templates and profiles, Authority Information Access locations, CRL generation and distribution, key protection, backup arrangements and monitoring coverage. Vulnerabilities, misconfigurations and process weaknesses were documented and categorised by risk level, each with its context, potential impact and recommended mitigation.
Remediation roadmap and investment case
Findings were prioritised and sequenced into a remediation roadmap, and framed to support an investment case. This was the deliverable that gave the report its practical value. An assessment that identifies twenty issues without indicating which matter most, what each will cost to address and in what order they should be tackled leaves the client with a new problem rather than a route out of the existing one. Prioritisation allowed the client to address the material risks first and to make the case for the resource required to do so.
Establishing what "good" looked like
Assessing a transitioned service requires a reference point, and in this case the obvious one, the documentation set the incumbent should have handed over, did not exist in usable form. Findings were therefore assessed against the standards the service was required to meet and against Unsung's experience of comparable enterprise and defence PKI estates, rather than against the client's own prior documentation. This produced a more demanding benchmark than a like-for-like handover comparison would have done, and a more useful one: the question the client needed answered was not whether the handover matched what preceded it, but whether the incoming operator could run and evidence the service to the standard required.
Prioritisation across four dimensions
With findings arising across documentation, governance, architecture and technical health, prioritisation had to work across categories rather than within them. A documentation gap can carry more operational risk than a technical misconfiguration, and an architectural constraint may matter more than either while being considerably more expensive to address. Findings were therefore ranked on risk and consequence rather than grouped by the dimension that produced them, which is what allowed the remediation roadmap to sequence work sensibly rather than tackling one category at a time.
This also gave the client a realistic view of effort. Some findings were resolved by producing a document; others required configuration change under change control; a small number implied architectural work with its own delivery timeline. Making those distinctions explicit is what turns a list of findings into a plan that can be resourced.
Challenges
An incomplete knowledge transfer
Operational responsibility for the PKI service had recently transferred through a process that failed to deliver comprehensive knowledge transfer. This required Unsung consultants to conduct forensic analysis of the technical platform to establish baseline understanding and inform assessment findings.
The practical consequence was that neither the outgoing nor the incoming party could provide a complete account of the environment. Assessment therefore had to proceed from the platform itself: reading configuration directly, establishing how components were connected, and inferring intent from implementation. Working this way demands deeper platform expertise than a documentation-led review, because there is no design to check the environment against and no colleague to ask.
Assessing a service in transition
The service was being assessed while operational responsibility was still bedding in, which meant the target was moving. Some findings reflected genuine configuration issues; others reflected arrangements that had not yet been fully established under the new operator. Distinguishing between the two was necessary for the report to be fair and useful, and required findings to be validated with the client rather than reported from inspection alone.
Producing findings that supported an investment case
The report needed to serve technical remediation and business justification simultaneously. That meant each finding had to carry not only its technical substance but its consequence in terms the client could take into a funding conversation. Structuring the output this way allowed a single report to inform the remediation roadmap and to underpin the case for resourcing it, without a separate translation exercise between the two.
Rebuilding operational confidence
The underlying issue was confidence rather than any single technical defect. An operator that cannot fully account for the service it has inherited will hesitate before making changes, defer improvements it cannot fully assess, and escalate cautiously. That caution is rational, and it degrades the service steadily over time as necessary work goes undone. The evidenced baseline produced by the assessment was what allowed the incoming team to operate the service on the basis of knowledge rather than inference, which is the precondition for maintaining and improving it.
For the client, the assessment also established a documented position at the start of the new operating arrangement. That has continuing value: subsequent change can be measured against a known baseline, and the condition of the service at the point of transfer is a matter of record rather than of recollection.
The engagement also demonstrated why a health check is worth commissioning at the point of service transition rather than after a period of operation. Assessed early, gaps in a handover are a supplier and process matter that can still be addressed. Assessed a year later, they have become the incoming operator's problem, and the opportunity to resolve them at source has passed.
Technologies Used
Related Services
Learn more about our PKI health check, defence sector.

