PKI Architecture & Design
End-to-end design of a production-grade PKI hierarchy: trust anchor, CA policies, HSM integration, CP/CPS drafting.
Brussels-based PKI boutique helping banks, financial institutions, and smart-city operators design, deploy, and automate enterprise PKI โ fully aligned with DORA, NIS2, and eIDAS 2.0.
PKI is invisible โ until it isn't. Expired certificates take down production. Misconfigured CAs fail audits. Four forces are converging.
Cryptographic controls are an explicit pillar of DORA. Register, audit, remediate โ on schedule.
Boards can be personally liable. PKI hygiene is no longer an IT back-office concern.
New qualified trust services require conformance against ETSI EN 319-series norms.
Crypto-agility is the new hygiene. Inventory, prioritise, and pilot ML-KEM / ML-DSA early.
Scoped, fixed-price where we can โ time & materials where scope genuinely moves. No junior account manager between you and the work.
End-to-end design of a production-grade PKI hierarchy: trust anchor, CA policies, HSM integration, CP/CPS drafting.
Structured review of cryptographic controls against DORA ICT risk requirements. Register, map, remediate.
Hands-on installation and hardening โ Enterprise Java Beans CA, Microsoft ADCS, HashiCorp Vault.
ACME, EST, SCEP, cert-manager, Venafi integration. No more expired certs taking down production.
Private-key compromise, CA migration, revocation storms โ 24h senior on-call during the bleed.
On-site or remote workshops for your engineering, ops, and compliance teams. No slides โ live labs.
MYKEYPAIR is led by Ismail Zemouri, CISSP โ 6+ years of hands-on PKI engineering across EU banks, financial market infrastructure, and critical utilities. Previous engagements with leading EU banks, a major central bank, critical infrastructure operators, and a global automotive group.
Vendor-agnostic. EJBCA, Microsoft ADCS, HashiCorp Vault, enterprise HSMs, AWS CloudHSM โ the tool follows the architecture, not the other way around.
All prices exclude 21% VAT. EU reverse charge applies for B2B outside Belgium.
Scoping call. Senior-to-senior. No sales deck.
Architecture, gap assessment, or deployment โ scoped, fixed.
Senior PKI on-call for your team. Cap 10 days/month.
30-minute discovery call โ senior-to-senior. No sales deck, no demos, no junior account manager.