PKI Design & Build
Service

PKI Design & Build

Unsung delivers tailored PKI design and implementation services to meet your business and security needs. From selecting technologies to building and integrating systems, we create future-ready, efficient PKI solutions.

Why 

At Unsung, PKI is all we do. We design and build end-to-end public key infrastructure shaped around your business requirements, not just your infrastructure.

With experience across both public and private sectors, we recognise that successful implementation means addressing people, processes and governance alongside the technology. We offer vendor-agnostic advice and deliver scalable, standards-based architectures using appropriate tools rather than preferred ones.

Architecture design that balances security and operability

We help organisations navigate the architectural decisions that determine security posture, operational complexity and long-term flexibility.

CA hierarchy design

We design hierarchy structures based on your security requirements and your operational capacity to run them:

  • Two-tier architecture combining an offline root CA with online issuing CAs, balancing security through air-gapped root authorities with operational efficiency for day-to-day issuance.
  • Three-tier architecture introducing intermediate CA layers between root and issuing authorities, enabling role segregation and compartmentalisation for large enterprises.
  • Hybrid models combining private PKI for internal infrastructure with public certificate authorities for external-facing services requiring universal browser trust.

Our delivery of a highly assured PKI root and greenfield PKI design and discovery case studies show how these decisions play out in practice.

Root CA and issuing CA configuration

We establish hierarchies where the root CA operates permanently offline with tamper-evident safety mechanisms, while issuing CAs handle day-to-day certificate operations. That separation keeps root certificates protected without compromising operational efficiency.

Deployment models

We assess the trade-offs between private CA deployment, public certificate authorities and managed services:

  • Private PKI providing complete control over certificate policy, validation procedures and security policy.
  • Public CA integration for external services requiring browser trust.
  • PKI as a service reducing operational overhead while maintaining policy customisation.
  • Internal PKI secured through hardware security module protection and comprehensive access controls.

Robust private key protection

We implement defence-in-depth strategies protecting the private key at every certificate authority level.

Hardware security module implementation

We deploy hardware security modules providing validated, tamper-resistant storage for CA private keys. These dedicated cryptographic appliances ensure private keys never exist in plaintext outside secure hardware boundaries, with tamper-evident mechanisms destroying key material if physical intrusion is detected.

Offline root CA security

We establish offline root authorities with air-gapped systems, strict physical access controls and multi-person authorisation. The root CA activates only for signing intermediate CA certificates or revocation lists, minimising exposure while maintaining certification path integrity across the whole PKI.

Key management procedures

We develop key management protocols covering:

  • Key ceremony procedures for root CA private key generation.
  • Private key protection throughout the certificate lifecycle.
  • Key escrow and recovery for business continuity.
  • Role separation ensuring no single administrator can compromise certificate operations.

Complete certificate lifecycle management

We design and implement automated certificate lifecycle management spanning request through revocation. The capabilities that matter are set out in our article on the four pillars of CLM.

Enrolment automation

We implement appropriate enrolment mechanisms for diverse environments. Which certificate management protocol suits which system is one of the more consequential design decisions:

  • Auto-enrolment through Active Directory for Windows domain environments.
  • SCEP for network devices.
  • ACME for cloud-native applications.
  • RESTful APIs for microservices and container platforms.
  • Manual processes where human validation is required.

Issuance and distribution

We establish issuance workflows using certificate templates that enforce security policy while enabling operational efficiency. Templates define key usage restrictions, validity periods and subject name formats, ensuring certificates are issued with appropriate security characteristics regardless of who requested them.

Renewal and expiration management

We implement monitoring and automation preventing the service outages that expired certificates cause. Layered alerting, automated renewal workflows and discovery across hybrid environments keep certificates current without manual intervention.

This matters more each year. Public TLS lifetimes are falling to 47 days, taking renewal volume up roughly eightfold.

Distribution infrastructure

We configure Authority Information Access and CRL distribution points so certificate validation functions across network boundaries. Load-balanced, highly available infrastructure supports chain validation from any location — including the segmented networks where validation most often fails in practice.

Comprehensive revocation infrastructure

We implement mechanisms ensuring revoked certificates cannot be used for unauthorised purposes.

Certificate revocation list management

We configure CRL publication at a frequency balancing security against operational load. Delta CRLs reduce bandwidth while providing incremental updates between full publications.

OCSP deployment

We deploy OCSP responders providing real-time revocation checking, with OCSP stapling configured on web servers to improve TLS handshake performance and remove client-side validation delays.

Validation infrastructure optimisation

We size and optimise revocation infrastructure to handle peak validation loads well above steady-state volumes, with caching strategies that maintain performance without compromising security.

Security policy and governance

We develop the documentation establishing operational procedures and security controls for your certification authority infrastructure.

Certificate policy

We create certificate policies defining usage standards, naming conventions, validation requirements and trust levels — establishing which authorities may issue certificates for which purposes, and what identity verification requesters must complete.

Certification practice statement

We document the operational procedures implementing those policy requirements in your specific environment, covering lifecycle procedures, key management practices, physical security controls and incident response.

Certificate requirements analysis

We work with stakeholders to define requirements across:

  • User certificates for email encryption, authentication and digital signatures.
  • Server certificates for TLS and application authentication.
  • Device certificates for IoT and network infrastructure.
  • Code signing certificates for application and firmware integrity.

Identity verification

We establish verification procedures aligned to certificate type and intended use, from domain validation through to extended validation for public certificates, and Active Directory integration for internal operations.

Compliance and standards alignment

We ensure infrastructure meets regulatory requirements and industry standards.

Regulatory compliance

We design PKI satisfying the frameworks that apply to you, including FIPS 140-3 for government and defence, PCI DSS for financial services, data protection requirements in healthcare, and eIDAS for European entities.

Standards-based architecture

We implement following RFC standards for certificate formats and protocols, CA/Browser Forum baseline requirements where applicable, vendor security guidelines, and sector-specific policy.

Audit preparation

We develop the documentation and evidence collection that supports compliance audits, with continuous monitoring tracking configuration compliance, access controls and operational procedures.

Why organisations choose Unsung

  • PKI specialists. PKI is our sole focus. Our engineers maintain deep expertise across certificate authorities, HSMs, certificate management platforms and integration, with proven experience from complex deployments.
  • Vendor-agnostic guidance. We select technologies based on your requirements, not vendor relationships. Our experience spans commercial platforms, open-source solutions and hybrid approaches.
  • Business-focused design. We design PKI that solves business problems rather than implementing technology for its own sake, addressing compliance requirements and operational constraints alongside architecture.
  • End-to-end delivery. From requirements analysis through operational handover, you receive functioning infrastructure with documented procedures, trained staff and ongoing support options.
  • Future-ready architecture. We design for evolution, including crypto agility and migration to post-quantum cryptography.

What

How Unsung solves PKI challenges

At Unsung, PKI is all we do. We design and build end-to-end public key infrastructure shaped around your business requirements, not just your infrastructure.

With experience across both public and private sectors, we recognise that successful implementation means addressing people, processes and governance alongside the technology. We offer vendor-agnostic advice and deliver scalable, standards-based architectures using appropriate tools rather than preferred ones.

Architecture design that balances security and operability

We help organisations navigate the architectural decisions that determine security posture, operational complexity and long-term flexibility.

CA hierarchy design

We design hierarchy structures based on your security requirements and your operational capacity to run them:

  • Two-tier architecture combining an offline root CA with online issuing CAs, balancing security through air-gapped root authorities with operational efficiency for day-to-day issuance.
  • Three-tier architecture introducing intermediate CA layers between root and issuing authorities, enabling role segregation and compartmentalisation for large enterprises.
  • Hybrid models combining private PKI for internal infrastructure with public certificate authorities for external-facing services requiring universal browser trust.

Our delivery of a highly assured PKI root and greenfield PKI design and discovery case studies show how these decisions play out in practice.

Root CA and issuing CA configuration

We establish hierarchies where the root CA operates permanently offline with tamper-evident safety mechanisms, while issuing CAs handle day-to-day certificate operations. That separation keeps root certificates protected without compromising operational efficiency.

Deployment models

We assess the trade-offs between private CA deployment, public certificate authorities and managed services:

  • Private PKI providing complete control over certificate policy, validation procedures and security policy.
  • Public CA integration for external services requiring browser trust.
  • PKI as a service reducing operational overhead while maintaining policy customisation.
  • Internal PKI secured through hardware security module protection and comprehensive access controls.

Robust private key protection

We implement defence-in-depth strategies protecting the private key at every certificate authority level.

Hardware security module implementation

We deploy hardware security modules providing validated, tamper-resistant storage for CA private keys. These dedicated cryptographic appliances ensure private keys never exist in plaintext outside secure hardware boundaries, with tamper-evident mechanisms destroying key material if physical intrusion is detected.

Offline root CA security

We establish offline root authorities with air-gapped systems, strict physical access controls and multi-person authorisation. The root CA activates only for signing intermediate CA certificates or revocation lists, minimising exposure while maintaining certification path integrity across the whole PKI.

Key management procedures

We develop key management protocols covering:

  • Key ceremony procedures for root CA private key generation.
  • Private key protection throughout the certificate lifecycle.
  • Key escrow and recovery for business continuity.
  • Role separation ensuring no single administrator can compromise certificate operations.

Complete certificate lifecycle management

We design and implement automated certificate lifecycle management spanning request through revocation. The capabilities that matter are set out in our article on the four pillars of CLM.

Enrolment automation

We implement appropriate enrolment mechanisms for diverse environments. Which certificate management protocol suits which system is one of the more consequential design decisions:

  • Auto-enrolment through Active Directory for Windows domain environments.
  • SCEP for network devices.
  • ACME for cloud-native applications.
  • RESTful APIs for microservices and container platforms.
  • Manual processes where human validation is required.

Issuance and distribution

We establish issuance workflows using certificate templates that enforce security policy while enabling operational efficiency. Templates define key usage restrictions, validity periods and subject name formats, ensuring certificates are issued with appropriate security characteristics regardless of who requested them.

Renewal and expiration management

We implement monitoring and automation preventing the service outages that expired certificates cause. Layered alerting, automated renewal workflows and discovery across hybrid environments keep certificates current without manual intervention.

This matters more each year. Public TLS lifetimes are falling to 47 days, taking renewal volume up roughly eightfold.

Distribution infrastructure

We configure Authority Information Access and CRL distribution points so certificate validation functions across network boundaries. Load-balanced, highly available infrastructure supports chain validation from any location — including the segmented networks where validation most often fails in practice.

Comprehensive revocation infrastructure

We implement mechanisms ensuring revoked certificates cannot be used for unauthorised purposes.

Certificate revocation list management

We configure CRL publication at a frequency balancing security against operational load. Delta CRLs reduce bandwidth while providing incremental updates between full publications.

OCSP deployment

We deploy OCSP responders providing real-time revocation checking, with OCSP stapling configured on web servers to improve TLS handshake performance and remove client-side validation delays.

Validation infrastructure optimisation

We size and optimise revocation infrastructure to handle peak validation loads well above steady-state volumes, with caching strategies that maintain performance without compromising security.

Security policy and governance

We develop the documentation establishing operational procedures and security controls for your certification authority infrastructure.

Certificate policy

We create certificate policies defining usage standards, naming conventions, validation requirements and trust levels — establishing which authorities may issue certificates for which purposes, and what identity verification requesters must complete.

Certification practice statement

We document the operational procedures implementing those policy requirements in your specific environment, covering lifecycle procedures, key management practices, physical security controls and incident response.

Certificate requirements analysis

We work with stakeholders to define requirements across:

  • User certificates for email encryption, authentication and digital signatures.
  • Server certificates for TLS and application authentication.
  • Device certificates for IoT and network infrastructure.
  • Code signing certificates for application and firmware integrity.

Identity verification

We establish verification procedures aligned to certificate type and intended use, from domain validation through to extended validation for public certificates, and Active Directory integration for internal operations.

Compliance and standards alignment

We ensure infrastructure meets regulatory requirements and industry standards.

Regulatory compliance

We design PKI satisfying the frameworks that apply to you, including FIPS 140-3 for government and defence, PCI DSS for financial services, data protection requirements in healthcare, and eIDAS for European entities.

Standards-based architecture

We implement following RFC standards for certificate formats and protocols, CA/Browser Forum baseline requirements where applicable, vendor security guidelines, and sector-specific policy.

Audit preparation

We develop the documentation and evidence collection that supports compliance audits, with continuous monitoring tracking configuration compliance, access controls and operational procedures.

Why organisations choose Unsung

  • PKI specialists. PKI is our sole focus. Our engineers maintain deep expertise across certificate authorities, HSMs, certificate management platforms and integration, with proven experience from complex deployments.
  • Vendor-agnostic guidance. We select technologies based on your requirements, not vendor relationships. Our experience spans commercial platforms, open-source solutions and hybrid approaches.
  • Business-focused design. We design PKI that solves business problems rather than implementing technology for its own sake, addressing compliance requirements and operational constraints alongside architecture.
  • End-to-end delivery. From requirements analysis through operational handover, you receive functioning infrastructure with documented procedures, trained staff and ongoing support options.
  • Future-ready architecture. We design for evolution, including crypto agility and migration to post-quantum cryptography.

How

The Unsung approach

Requirements definition

We work with stakeholders to define business, compliance and technical certificate requirements, cataloguing certificate holders across users, devices and applications while anticipating future growth.

Where an existing estate is in scope, a PKI health check establishes the real starting position before design begins.

Architecture and solution design

We create vendor-agnostic hierarchy designs aligned with best practice. Decisions cover trust models, validity periods, policy frameworks and integration with existing security infrastructure.

Security policy framework

We develop the certificate policy and certification practice statement documentation providing the operational and legal foundation for your certification authority.

Platform integration and implementation

We deploy and configure complete PKI infrastructure integrated with your existing security and identity systems.

Certificate authority setup

We implement certificate authorities using the appropriate platform for your environment:

Active Directory integration

We configure integration with AD CS, using existing domain infrastructure for automated enrolment while maintaining security through centralised templates and Group Policy enforcement.

Certificate store management

We establish appropriate certificate stores across user systems, servers and devices, ensuring distribution, chain validation and automated renewal all function correctly.

Application and service integration

We integrate PKI with the applications that depend on it:

  • Web servers and load balancers for TLS.
  • VPN concentrators and network access control.
  • Email systems for S/MIME encryption and digital signatures.
  • Code signing workflows for software integrity.
  • IoT device authentication frameworks.

Deployment strategy and migration

We implement carefully orchestrated rollout phases, validating functionality before organisation-wide deployment. Our migration de-risking and Entrust to EJBCA migration case studies illustrate the approach.

Pilot deployment

We establish limited-scope pilots with representative use cases validating core functionality, covering diverse certificate types: user authentication, web server certificates and device certificates.

Root certificate distribution

We deploy root certificates establishing trust across all client systems, using Group Policy for domain-joined machines, mobile device management for mobile, and documented manual procedures for anything outside centralised management.

Legacy system integration

We develop integration strategies for applications lacking modern enrolment support, including manual installation procedures, format conversions and intermediate chain modifications. This is usually where deployments stall, and it is worth scoping honestly at the outset.

Operations handover

We transfer operational responsibility to your teams with knowledge transfer, training on certificate management platforms and documented procedures for routine operations. Where you would rather not run it in-house, PKI management and hosting is available as an alternative.

Monitoring and operational excellence

Certificate discovery and inventory

We implement automated discovery identifying certificates across on-premises infrastructure, public cloud and edge locations. In most estates we assess, the number found exceeds the number the organisation had on record. A cryptographic bill of materials extends this to algorithms and key lengths, and our guide to building a cryptographic inventory covers where to start.

Expiration monitoring

We configure layered alerting at appropriate intervals before expiry, escalating through management channels while triggering automated renewal where the system supports it. Our guide to overcoming resistance to automation covers the objections that typically surface here.

Security auditing

We establish logging and monitoring of all certificate operations, enabling compliance reporting and security investigation. Regular access reviews verify that only authorised personnel retain administrative access to certificate authorities.

Performance optimisation

We tune infrastructure for high-volume issuance, addressing the common bottlenecks: CA processing capacity, network bandwidth for distribution, and validation infrastructure sizing.

Governance, documentation and knowledge transfer

We create operational documentation supporting secure management of the infrastructure, including runbooks for certificate operations, incident response procedures and compliance reporting frameworks.

We upskill internal teams through targeted training on certificate lifecycle management, certificate authority administration, troubleshooting issuance problems and maintaining security controls.

Technical capabilities

Certificate authority technologies

  • Windows Server Certificate Services
  • EJBCA and Linux-based open-source certificate authorities
  • Cloud-native certificate authority services
  • Hardware security module integration from leading providers

Certificate management platforms

We work with all major certificate management platforms and recommend the most appropriate for your requirements. Our CLM vendor and licensing evaluation guide sets out how we approach that comparison.

Enrolment protocols

Auto-enrolment via Group Policy, SCEP, ACME, EST and RESTful APIs for modern applications. Our protocol comparison guide explains which suits which environment.

Validation infrastructure

CRL services, delta CRL optimisation, OCSP responders, OCSP stapling configuration and certificate chain validation optimisation.

Building digital trust infrastructure

Successful PKI implementation establishes the foundation of digital trust for your organisation. The architectural decisions made during initial design affect security, operations and business capability for years afterwards.

We make sure your public key infrastructure works as an enabler for secure communications, identity assurance and digital signatures — now, and when the cryptography underneath it needs to change.

Contact our team to discuss your PKI requirements.

Frequently Asked Questions

What is PKI design and build?

PKI design and build is a service that delivers customised public key infrastructure from initial technology selection through to deployment and integration. It covers complete PKI systems that support modern digital ecosystems, hybrid cloud environments, and IoT authentication requirements.

What are common mistakes in PKI deployment?

Organisations frequently rush PKI deployment without adequate planning, resulting in certificate management nightmares, security gaps, and compliance failures. Common mistakes include inadequate CA hierarchy architecture selections, insufficient private key protection mechanisms, certificate lifecycle mismanagement, weak revocation infrastructure, and integration failures with modern platforms and legacy systems.

What CA hierarchy options are available?

PKI design includes appropriate CA hierarchies based on specific security and operational requirements. Options include two-tier (offline root with online issuing CAs), three-tier (introducing intermediate layers), or hybrid models combining private and public infrastructure.

How is private key protection implemented?

Private key protection implementation includes hardware security module deployment providing tamper-resistant storage, offline root CA operations with air-gapped systems, and comprehensive key management procedures. This ensures the highest level of security for cryptographic keys.

What compliance standards does PKI design address?

PKI design addresses compliance alignment with FIPS 140-2, PCI DSS, HIPAA, and eIDAS standards. This includes development of certificate policies, certification practice statements, and identity verification procedures.