HID PKI-as-a-Service

HID PKIaaS enables organizations to quickly create and deploy their own enterprise private PKI trust hierarchies to secure their networks, IT systems and IoT devices.

IdenTrust Keyfactor

PKI Made Simple

As a foundational security technology implemented for decades, Private Key Infrastructure (PKI) is already deployed in most enterprise IT infrastructures. However, the ongoing management and maintenance of an in-house PKI deployment can be difficult and require dedicated, skilled staff—adding to overall security costs.

  • Simplify operations by outsourcing the complexity of running a best-in-class PKI without losing control of trusted assets
  • Obtain PKI (Trust) infrastructure that aligns with industry best practices and leverages highly-secure and audited technical facilities with the expertise to deliver it all
  • Support Zero Trust with secure authentication and communications between machines, devices, IoT and virtual servers
  • Reduce cost and compliance risk related to internal PKI and CA management
  • Adapt to changing needs with complete flexibility to add new services at any time
  • Deploy scalable PKI services rapidly in weeks, not months
Building Blocks

Less Operational Complexity and Cost

HID PKIaaS eliminates operational complexity and dramatically reduces costs related to operating and deploying an organizational private PKI.

Choose from a simple preconfigured service for a Dedicated Issuing Certificate Authority (CA) or a completely customized Private Root PKI Service that:

  • Provides unique trust anchor at the issuing CA level and management of all CAs
  • Offers full turnkey service including private root key generation ceremony and custody management of all off-line key material
  • Manages all certificate validation systems


Your CorpRoot CA(Offline) Your CorpIssuing CA 1DeviceCertificatesServerCertificatesx.509 SVIDCertificatesMS AutoenrollCertificatesYour CorpIssuing CA 2Your CorpIssuing CA 3Your CorpIssuing CA 4

Enterprise SSL Subscription Service

Access your SSL service via our enterprise SaaS portal with complete policy control, delegated administration, on-demand auditing and reporting. Use your certificate on as many servers as you need and utilize unlimited subdomains at no additional cost – easily upgrade if you need more certificates. All for one low monthly fee and hassle-free cancellation.

Learn more about Enterprise SSL certificate management >>

How it Works

Complete Control With Account Certificate Management

HID Account Certificate Management (ACM) offers complete control, delegated administration, on-demand auditing and reporting. Automate and scale certificate provisioning for every system and device.
  • Web-based certificate management portal supports both private and trusted certificate services
  • Automation support for Microsoft Autoenrollment and other standards-based certificate management protocols such as SCEP, EST, and ACME as well as API support
  • Trusted certificate services including OV, EV, Wildcard and SAN certificates as well as client certificates such as S/MIME and code signing

Download the datasheet >>

Key Benefits

One Simple Annual Subscription Fee

Say so long to hidden costs or surprises with predictable, all-inclusive pricing. Get what you need, when you need it.


Eliminate management of complex certificate-based pricing or credits

Add new services at any time

Tailor the subscription to your specific requirements
Identity Lifecycle Management

Geographically Dispersed Data Centers

HID PKIaaS is designed with fully redundant and geographically distributed architecture to scale for millions of certificate issuances and billions of certificate validations. Instead of relying on a single data center, HID PKIaaS can automatically scale on-demand across multiple data centers and provide instant certificate enrollment, approval, issuance, revocation, and renewal. Our data centers help establish local residency and are securely located in:

  • Nevada, United States
  • Virginia, United States
  • Amsterdam, Netherlands
  • Dublin, Ireland

API and Third-Party Application Support

HID PKIaaS is already integrated into key management solutions, such as Venafi. And, our RESTful certificate management API is easy to incorporate into custom or third-party applications.

Explore the Breadth of HID’s PKI Solutions and Services

Establish security across all your networks and devices using a subscription-based cloud service or discrete digital certificates that solve the pain points of large complex organizations, medium-sized enterprises, and small businesses.



IoT Device Identity Management
Automate certificate provisioning and IoT
device identity lifecycle management to
support billions of secure IoT devices.
Learn more >>


Certificate Lifecycle Management
Protect your enterprise against certificate
related outages and cyber attacks with
trusted identities for every use case.
Learn more >>




Digital Certificates
Experience digital certificates that prove
identity and secure communications
and digital signing.
Learn more >>


Enterprise SSL
Secure every server with one low, fixed
subscription fee and the flexibility
to mix and match certificate types.
Learn more >>