Six disciplines. One senior engineer. Brussels & Tokyo.
PKI Architecture
Enterprise Public Key Infrastructure
Complete CA hierarchy design and deployment across regulated environments. Multi-platform expertise — EJBCA, Keyfactor Command, IDnomic/Eviden, AWS PCA — with mTLS integration for certificate-based authentication. From central banks to automotive OEMs.
mTLS — certificate-based authentication across services
CP, CPS, and compliance documentation
Outcome
→ Your CA is live, documented, and audit-ready in 6 weeks
Deliverables
Architecture Design DocumentIncluded
Docker Infrastructure (HA)Included
Certificate Policy (CP)Included
Certificate Practice StatementIncluded
Key Ceremony ProcedureIncluded
SOPs (8 documents)Included
Monitoring & AlertingIncluded
How It Works
1
Discover
Full inventory scan — every certificate in every system, mapped and classified
2
Automate
ACME, EST, SCEP auto-enrollment workflows replacing manual processes
3
Monitor
Expiry alerts, failure notifications, and audit trails at every renewal
4
Report
Compliance dashboard and evidence package ready for auditors
Certificate Lifecycle
Certificate Lifecycle Management
Automate certificate discovery, enrollment, renewal, and alerting across your entire estate. Eliminate manual tracking and expired certificate incidents with ACME, EST, and SCEP workflows integrated into your existing toolchain.
Outcome
→ Zero expired certificates, full visibility in 4 weeks
Regulatory Compliance
DORA, NIS2 & EU Regulatory Compliance
Compliance advisory for financial institutions and regulated enterprises navigating DORA, NIS2, and eIDAS 2.0. Gap analysis, control mapping, RFP drafting for PKI and KMS solutions, and threat modeling for cloud PKI environments.
Outcome
→ Audit-ready compliance package with evidence mapping
Coverage Areas
DORA Article 6 & 7 gap analysis
NIS2 cryptographic controls mapping
eIDAS 2.0 readiness assessment
Certificate Policy & CPS authoring
RFP drafting and vendor evaluation
Threat modeling for cloud PKI
Key Management Policy documentation
Audit preparation and evidence package
Migration Roadmap
01
Inventory
Crypto-asset taxonomy — every algorithm, key, and certificate in scope
02
Assess
Crypto-agility gaps, algorithm dependencies, and blast-radius mapping
03
Plan
PQC migration roadmap per FIPS 203/204/205 (ML-DSA, ML-KEM)
04
Hybrid
Dual-algorithm certificate strategies for phased, zero-downtime rollout
Post-Quantum Readiness
Post-Quantum Cryptography Readiness
Prepare your cryptographic infrastructure for the post-quantum transition before it becomes a compliance requirement. Crypto-asset inventory, FIPS 203/204/205 migration planning (ML-DSA, ML-KEM), crypto-agility assessment, and hybrid certificate strategies.
Outcome
→ Know exactly what breaks when quantum arrives
IoT & Device Security
IoT & Device Certificate Security
Secure device authentication and firmware integrity for connected environments. SCEP/Intune/EAP-TLS device onboarding, Code Signing CA centralization, OT/ICS PKI, and connected vehicle certificate architectures using AWS PCA with SCEP.
Outcome
→ Every device authenticated, every firmware signed
Use Cases
🔐
Device Authentication
SCEP, Intune MDM, and EAP-TLS for enterprise endpoints and OT/ICS devices
✍️
Code Signing
Centralized Code Signing CA — firmware and software integrity at scale
⚙️
Connected OT/ICS
PKI architectures for manufacturing and industrial environments using AWS PCA + SCEP
What I Check
SSL/TLS Configuration
Certificate Chain
DNS Security
Email (SPF/DKIM/DMARC)
Web Application
SSH Hardening
Port Exposure
CIS Benchmarks
Security Assessment
Find What's Broken Before Attackers Do
Comprehensive vulnerability assessment and penetration testing. OSINT reconnaissance, network scanning, web application testing, and detailed remediation reports with findings ranked by business risk.
Outcome
→ Full report with exploitable findings ranked by business risk
All Services at a Glance
Six disciplines. One senior engineer. Brussels & Tokyo.
PKI Architecture
Enterprise Public Key Infrastructure
Complete CA hierarchy design and deployment across regulated environments. Multi-platform expertise — EJBCA, Keyfactor Command, IDnomic/Eviden, AWS PCA — with mTLS integration for certificate-based authentication. From central banks to automotive OEMs.
→ Your CA is live, documented, and audit-ready in 6 weeks
Certificate Lifecycle
Certificate Lifecycle Management
Automate certificate discovery, enrollment, renewal, and alerting across your entire estate. Eliminate manual tracking and expired certificate incidents with ACME, EST, and SCEP workflows integrated into your existing toolchain.
→ Zero expired certificates, full visibility in 4 weeks
Regulatory Compliance
DORA, NIS2 & EU Regulatory Compliance
Compliance advisory for financial institutions and regulated enterprises navigating DORA, NIS2, and eIDAS 2.0. Gap analysis, control mapping, RFP drafting for PKI and KMS solutions, and threat modeling for cloud PKI environments.
→ Audit-ready compliance package with evidence mapping
Post-Quantum Readiness
Post-Quantum Cryptography Readiness
Prepare your cryptographic infrastructure for the post-quantum transition before it becomes a compliance requirement. Crypto-asset inventory, FIPS 203/204/205 migration planning (ML-DSA, ML-KEM), crypto-agility assessment, and hybrid certificate strategies.
→ Know exactly what breaks when quantum arrives
IoT & Device Security
IoT & Device Certificate Security
Secure device authentication and firmware integrity for connected environments. SCEP/Intune/EAP-TLS device onboarding, Code Signing CA centralization, OT/ICS PKI, and connected vehicle certificate architectures using AWS PCA with SCEP.
→ Every device authenticated, every firmware signed
Security Assessment
Find What's Broken Before Attackers Do
Comprehensive vulnerability assessment and penetration testing. OSINT reconnaissance, network scanning, web application testing, and detailed remediation reports with findings ranked by business risk.
→ Full report with exploitable findings ranked by business risk
Ready to start?
Let's talk about your PKI estate.
30-minute discovery call — senior-to-senior. No sales deck, no demos, no junior account manager.