Working Groups

Members

The PKI Consortium brings together leading organizations committed to trustworthy digital identities and secure communication.

Browse all members →
Edit on GitHub

Categories

The following categories of the PKI maturity model are defined with the appropriate weight based on the applicability and importance:

IDCategoryDescriptionWeight
strategy-and-visionStrategy and visionResponsible for the PKI management and strategy. Includes alignment with organizational goals and requirements, risk management, and policy decisions.5
policies-and-documentationPolicies and documentationFormal policies and practice statements for supported PKI services and use-cases. Formal management of agreements between parties involved in the PKI.4
complianceComplianceAdherence to standards and applicable regulations and requirements for the PKI and trust services. Standards and regulations may be internal or external, country specific or purpose specific.2
processes-and-proceduresProcesses and proceduresProcesses and procedures related to PKI management tasks and operational activities. This includes also the supply chain procedures and processes that includes acceptance or receipt of the HW and SW related to the PKI.3
cryptographyCryptographyCryptographic governance: approved algorithms, parameters, and protocols used within the PKI; visibility into cryptographic usage; lifecycle, deprecation rules, and cryptographic agility.5
key-managementKey managementKey management policy and procedures related to PKI cryptographic keys and its lifecycle. Inventory of cryptographic keys. Secure and trusted key ceremonies. Key escrow and key recovery if applicable.4
certificate-managementCertificate managementCertificate management policy and lifecycle. Inventory of certificates. Definition of the certificate profiles and supported states of the certificate including the transitions between the states. Proper validation of the certificates.4
infrastructure-managementInfrastructure managementAvailability of the PKI services, infrastructure setup to achieve availability goals. PKI continuity testing and infrastructure recovery. Infrastructure security controls.2
change-management-and-agilityChange management and agilitySecure and controlled process for the change management. Formal process to request changes in the PKI, approval, staging, roll-back.3
resilienceResilienceQuickly respond to potential attack and unavailability of the PKI services or other related resources.4
automationAutomationAutomation of certificate lifecycle management. Technology and tools for the automation. Monitoring of automated certificate operations.2
interoperabilityInteroperabilityInteroperability between applications, implementations, and technologies. Application of interoperable protocols and standards. Transparency and vendor lock avoidance strategy.2
monitoring-and-auditingMonitoring and auditingMeasurement of the PKI metrics, collecting evidence, monitoring and alerting of relevant issues, including references to incident response management.2
sourcingSourcingAvailability of skilled resources to manage PKI. Processes and procedures to maintain the required resources in time, monitoring of the skills.4
knowledge-and-trainingKnowledge and trainingEducation of people and continuously gathering required knowledge and skills to manage PKI. Training plans and improvement.3
awarenessAwarenessProviding awareness about the PKI in the organization and its purpose. Awareness how to apply the PKI in a trusted and secure way.3

For more information on categories, please refer to the Categories description.

The weights of the categories are used to calculate the overall maturity level of the PKI.