PKI & COMPLIANCE ENGINEERING

From security requirements to dependable operations.

Understand requirements. Implement security. Enable evidence. We connect ISMS and compliance frameworks to your PKI: from cryptographic policies and CP/CPS through tested integrations to procedures your operations team can run.

THE OPERATING CONTEXT

Requirements must work in daily operations.

An audit is approaching, new requirements affect an established PKI or a demanding AS4 integration needs to work. You need clarity on what applies, where the gaps are and how implementation will operate. keyONE combines long-standing PKI and cryptography experience with practical engineering. We align cryptographic policies, CP/CPS, architecture and procedures with ISMS, business and operations teams, connecting rules to technical controls, owners and verifiable evidence.

A roadmap from requirements to verifiable PKI operations.

A CONTROLLABLE RESULT

Clear requirements. Effective controls. Usable evidence.

Requirement → measure → test → evidence. For key protection, we connect the requirement to HSM configuration, access roles and a traceable test result. You can see what was implemented, how it was tested and who operates it.

01

A requirements matrix with clear ownership

Map applicable requirements to scope, measures, owners and evidence. Record gaps and priorities transparently rather than treating each framework as an isolated checklist.

02

Cryptographic policies and aligned CP/CPS

Develop or review cryptographic policies, Certificate Policy (CP) and Certification Practice Statement (CPS). Align protection objectives, roles, certificate profiles and key management with architecture and real operational procedures.

03

Feasibility before the operational decision

Validate representative workflows in our vendor-independent integration lab or an agreed test environment. Test PKI, HSMs, applications and custom AS4 connections together; document functionality, failure behavior and fallback to support the rollout decision.

04

Operational procedures and maintained evidence

Establish ownership, operating instructions, approvals and recurring controls. Map configurations, tests and operational evidence to requirements, and hand over a practical maintenance and review process.

THE APPROACH

Your roadmap: from requirements to operations.

The roadmap follows your concrete task. At each transition we ask: What is required? How is it implemented? How do we know it works? Requirements, tests and evidence stay connected from the action plan through operational handover.

  1. 01

    Define scope and applicable requirements

    Assess the ISMS, protection needs and affected services. Identify relevant ISO/IEC 27001, IT-Grundschutz, NIS2, DORA and PCI DSS requirements and applicable BSI guidelines. Result: a requirements matrix with scope, versions, owners and priorities.

  2. 02

    Inventory the estate and identify gaps

    Record certification authorities, HSMs, keys, certificates, applications and procedures. Compare requirements with the actual environment, using existing ICT and cryptographic inventories. Result: documented dependencies, gaps and actionable measures.

  3. 03

    Develop cryptographic policies and CP/CPS

    Align cryptographic policies with applicable IT-Grundschutz requirements, particularly CON.1. Structure CP and CPS using the RFC 3647 framework and address applicable TR-03145 CA operating requirements. Result: policies and roles ready for organizational approval.

  4. 04

    Derive architecture and technical controls

    Translate requirements into certificate profiles, key management, HSM usage, roles and approvals. Address application-specific parts of TR-03116 and relevant PCI DSS controls. Result: target architecture, operating rules and measurable acceptance criteria.

  5. 05

    Validate, integrate and develop where needed

    Test representative cases such as enrollment, signature verification, AS4 communication or certificate renewal. Develop scripts, providers and interfaces where necessary. Result: documented tests, known limitations and a controlled rollout plan with fallback.

  6. 06

    Establish operational procedures

    Integrate operating instructions, ownership, dual-control approvals, monitoring, renewal, revocation and recovery. Connect applicable ISMS, IT-Grundschutz, NIS2 and DORA requirements to these workflows. Result: an operations handbook, handover and verified operational readiness.

  7. 07

    Maintain evidence and manage change

    Link requirements to configurations, approvals, test records and operational evidence. Support audit preparation, recurring reviews and remediation of gaps. Plan for crypto agility and changes to requirements. Result: a maintained evidence matrix and improvement roadmap.

FRAMEWORKS & RESPONSIBILITY

Connect the applicable frameworks to your roadmap.

We identify which requirements apply to your scope and map them to measures, owners and evidence. Frameworks do not replace each other; technical delivery and independent assessment remain separate responsibilities.

01

ISO/IEC 27001 & ISMS

Steps 1, 4, 6 and 7: integrate cryptographic measures into ISMS risk treatment, ownership, approvals and ongoing review. Connect technical controls to the agreed scope and supporting evidence.

02

IT-Grundschutz & CON.1 Kryptokonzept

Steps 1 to 4 and 6: identify relevant modules for the information domain. Connect CON.1 to the selection, use and lifecycle of cryptographic mechanisms; translate policies into key, certificate and operating procedures.

03

NIS2

Steps 1, 4, 6 and 7: technically support applicable cybersecurity risk management and cryptographic measures. Connect ownership, operational procedures and verification of their effectiveness.

04

DORA

Steps 1, 2, 4, 6 and 7: integrate cryptography and key management into ICT risk management, operational procedures and evidence. Map technical dependencies to ICT services and third-party providers.

05

PCI DSS

Steps 1, 4, 5 and 7: implement and test relevant requirements for strong cryptography, protection of cryptographic keys, secure transmission and verifiable procedures within the agreed scope.

06

BSI TR-03145 · Secure CA operation

Steps 3 to 7: connect applicable certification authority requirements to CP/CPS, roles, key processes, technical implementation and operating evidence. Review documented procedures together with actual operations.

07

BSI TR-03116 · Application-specific cryptography

Steps 1, 4, 5 and 7: identify the part and version relevant to the use case. Translate algorithm and protocol requirements into configuration, implementation and interoperability tests.

THE RIGHT FIT

Where we can start together.

For organizations integrating PKI and cryptography into information security management, preparing for an audit or putting documented requirements into practice.

01

Connect ISMS and PKI

Cryptographic controls need to fit information security management and work on the affected systems. We bring business owners, ISMS and operations teams together around concrete rules and controls.

02

Update cryptographic policies or CP/CPS

Existing documentation no longer matches certification authorities, HSMs or applications. We review alignment, resolve inconsistencies and develop policies and operating procedures together.

03

Prepare for audits and remediate findings

Evidence is missing or documented procedures differ from actual operations. We help assess findings, prioritize measures and provide traceable evidence of technical implementation.

04

Integrate custom development and AS4

A standard product does not fully cover the required workflow. We assess feasibility and develop suitable scripts or interfaces, including certificate, signature and key processes for the agreed AS4 use case.

THE NEXT CONTROLLED STEP

Which requirement needs to work in your PKI?

Start with your concrete task: an audit, an outdated policy, an established PKI or a demanding integration. Together we define the scope, priorities and first verifiable result.

Discuss your project