A requirements matrix with clear ownership
Map applicable requirements to scope, measures, owners and evidence. Record gaps and priorities transparently rather than treating each framework as an isolated checklist.
Enterprise PKI · Digital Trust Engineering
PKI & COMPLIANCE ENGINEERING
Understand requirements. Implement security. Enable evidence. We connect ISMS and compliance frameworks to your PKI: from cryptographic policies and CP/CPS through tested integrations to procedures your operations team can run.
THE OPERATING CONTEXT
An audit is approaching, new requirements affect an established PKI or a demanding AS4 integration needs to work. You need clarity on what applies, where the gaps are and how implementation will operate. keyONE combines long-standing PKI and cryptography experience with practical engineering. We align cryptographic policies, CP/CPS, architecture and procedures with ISMS, business and operations teams, connecting rules to technical controls, owners and verifiable evidence.
A roadmap from requirements to verifiable PKI operations.
A CONTROLLABLE RESULT
Requirement → measure → test → evidence. For key protection, we connect the requirement to HSM configuration, access roles and a traceable test result. You can see what was implemented, how it was tested and who operates it.
Map applicable requirements to scope, measures, owners and evidence. Record gaps and priorities transparently rather than treating each framework as an isolated checklist.
Develop or review cryptographic policies, Certificate Policy (CP) and Certification Practice Statement (CPS). Align protection objectives, roles, certificate profiles and key management with architecture and real operational procedures.
Validate representative workflows in our vendor-independent integration lab or an agreed test environment. Test PKI, HSMs, applications and custom AS4 connections together; document functionality, failure behavior and fallback to support the rollout decision.
Establish ownership, operating instructions, approvals and recurring controls. Map configurations, tests and operational evidence to requirements, and hand over a practical maintenance and review process.
THE APPROACH
The roadmap follows your concrete task. At each transition we ask: What is required? How is it implemented? How do we know it works? Requirements, tests and evidence stay connected from the action plan through operational handover.
Assess the ISMS, protection needs and affected services. Identify relevant ISO/IEC 27001, IT-Grundschutz, NIS2, DORA and PCI DSS requirements and applicable BSI guidelines. Result: a requirements matrix with scope, versions, owners and priorities.
Record certification authorities, HSMs, keys, certificates, applications and procedures. Compare requirements with the actual environment, using existing ICT and cryptographic inventories. Result: documented dependencies, gaps and actionable measures.
Align cryptographic policies with applicable IT-Grundschutz requirements, particularly CON.1. Structure CP and CPS using the RFC 3647 framework and address applicable TR-03145 CA operating requirements. Result: policies and roles ready for organizational approval.
Translate requirements into certificate profiles, key management, HSM usage, roles and approvals. Address application-specific parts of TR-03116 and relevant PCI DSS controls. Result: target architecture, operating rules and measurable acceptance criteria.
Test representative cases such as enrollment, signature verification, AS4 communication or certificate renewal. Develop scripts, providers and interfaces where necessary. Result: documented tests, known limitations and a controlled rollout plan with fallback.
Integrate operating instructions, ownership, dual-control approvals, monitoring, renewal, revocation and recovery. Connect applicable ISMS, IT-Grundschutz, NIS2 and DORA requirements to these workflows. Result: an operations handbook, handover and verified operational readiness.
Link requirements to configurations, approvals, test records and operational evidence. Support audit preparation, recurring reviews and remediation of gaps. Plan for crypto agility and changes to requirements. Result: a maintained evidence matrix and improvement roadmap.
FRAMEWORKS & RESPONSIBILITY
We identify which requirements apply to your scope and map them to measures, owners and evidence. Frameworks do not replace each other; technical delivery and independent assessment remain separate responsibilities.
Steps 1, 4, 6 and 7: integrate cryptographic measures into ISMS risk treatment, ownership, approvals and ongoing review. Connect technical controls to the agreed scope and supporting evidence.
Steps 1 to 4 and 6: identify relevant modules for the information domain. Connect CON.1 to the selection, use and lifecycle of cryptographic mechanisms; translate policies into key, certificate and operating procedures.
Steps 1, 4, 6 and 7: technically support applicable cybersecurity risk management and cryptographic measures. Connect ownership, operational procedures and verification of their effectiveness.
Steps 1, 2, 4, 6 and 7: integrate cryptography and key management into ICT risk management, operational procedures and evidence. Map technical dependencies to ICT services and third-party providers.
Steps 1, 4, 5 and 7: implement and test relevant requirements for strong cryptography, protection of cryptographic keys, secure transmission and verifiable procedures within the agreed scope.
Steps 3 to 7: connect applicable certification authority requirements to CP/CPS, roles, key processes, technical implementation and operating evidence. Review documented procedures together with actual operations.
Steps 1, 4, 5 and 7: identify the part and version relevant to the use case. Translate algorithm and protocol requirements into configuration, implementation and interoperability tests.
THE RIGHT FIT
For organizations integrating PKI and cryptography into information security management, preparing for an audit or putting documented requirements into practice.
Cryptographic controls need to fit information security management and work on the affected systems. We bring business owners, ISMS and operations teams together around concrete rules and controls.
Existing documentation no longer matches certification authorities, HSMs or applications. We review alignment, resolve inconsistencies and develop policies and operating procedures together.
Evidence is missing or documented procedures differ from actual operations. We help assess findings, prioritize measures and provide traceable evidence of technical implementation.
A standard product does not fully cover the required workflow. We assess feasibility and develop suitable scripts or interfaces, including certificate, signature and key processes for the agreed AS4 use case.
THE NEXT CONTROLLED STEP
Start with your concrete task: an audit, an outdated policy, an established PKI or a demanding integration. Together we define the scope, priorities and first verifiable result.