- Key Takeaways
- The Comparison, Dimension by Dimension
- What Self-Managed AD CS Actually Requires for PQC
- What Managed PKI Actually Provides
- The Staffing Question Matters as Much as the Cost Question
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Genuine Trade-Off, Not a Clear Winner
- Frequently Asked Questions
Quick answer: Neither self-managed AD CS nor managed PKI is universally the right PQC migration path; the right choice depends on your specific control requirements, deployment timeline, and staffing capacity. AD CS offers full control and no per-certificate service fees, but requires your own team to handle the parallel-hierarchy deployment, HSM firmware validation, and hybrid coexistence work directly, and Microsoft’s PQC rollout landed in stages through 2025 and 2026 that your team needs to track. Managed PKI shifts that operational burden to a provider, generally reaching PQC readiness faster since the provider has already solved firmware validation and hierarchy deployment across many customers, at the cost of some control and a recurring service cost. This guide compares both across the dimensions that actually matter for the decision.
This isn’t a question with a universally correct answer, and content that argues otherwise is usually selling something. AD CS is a mature, capable platform that many organizations run well; managed PKI solves real operational burden for organizations that don’t want to carry it themselves. The right choice depends on specifics.
Key Takeaways
- AD CS gained ML-DSA support through a staged Microsoft rollout across late 2025 and 2026, and has no in-place upgrade path, requiring a parallel CA hierarchy for either deployment model.
- Managed PKI providers typically absorb the firmware validation, hierarchy deployment, and hybrid coexistence engineering work, trading direct control for faster time-to-readiness.
- Staffing capacity, not just cost, is often the deciding factor: PQC-specific PKI expertise is genuinely scarce, and self-managed AD CS requires your team to develop or acquire it directly.
- Total cost comparison needs to include the value of internal engineering time, not just license and service fees, to be accurate.
The Comparison, Dimension by Dimension
| Dimension | Self-Managed AD CS | Managed PKI |
|---|---|---|
| Control | Full control over CA configuration, key custody, and policy | Shared or delegated control depending on provider model; key custody terms vary |
| Algorithm support | Follows Microsoft’s staged rollout timeline directly; your team tracks and applies updates | Provider typically tracks and applies platform updates on your behalf |
| Deployment speed | Bounded by your team’s available capacity and PQC-specific expertise | Generally faster, since the provider has deployed the parallel hierarchy pattern across many customers already |
| HSM options | You select, procure, and validate HSM firmware directly | Provider typically manages HSM selection and validation as part of the service |
| Hybrid hierarchy management | Your team designs and operates the parallel classical-and-PQC hierarchy | Provider typically operates this as a standard part of the migration service |
| Interoperability testing | Your responsibility to test against your specific relying-party population | Provider may offer broader tested compatibility data, but your specific environment still needs validation |
| Staffing | Requires in-house PKI and increasingly PQC-specific expertise | Reduces in-house staffing requirement; provider expertise substitutes for it |
| Total cost | No per-certificate or service fee, but real internal engineering time cost | Recurring service cost, often offset by reduced internal engineering time |
What Self-Managed AD CS Actually Requires for PQC
Microsoft’s own PQC rollout for AD CS, covered in depth in our ML-DSA AD CS configuration guide, landed in stages, CNG and SymCrypt primitives in November 2025, AD CS ML-DSA support in May 2026, hybrid TLS and composite algorithms in July 2026, and it carries a hard operational constraint: there is no in-place upgrade path, so PQC support requires standing up a new, parallel certification authority hierarchy. Running this yourself means your team handles trust anchor distribution, certificate template reconfiguration, HSM firmware validation, and the multi-year parallel-hierarchy operation directly, the full scope covered in our parallel PKI migration guide.
What Managed PKI Actually Provides
A managed PKI service absorbs the operational engineering behind the same requirements: the provider has typically already validated HSM firmware, built the parallel-hierarchy deployment pattern, and tested interoperability across a broader customer base than any single organization would encounter on its own. What it does not eliminate is the need for your organization to still validate the service against your own specific relying-party population, applications, and compliance requirements, since a provider’s general compatibility testing doesn’t substitute for testing against your actual environment.
The Staffing Question Matters as Much as the Cost Question
PQC-specific PKI expertise is genuinely scarce as of 2026, and self-managed AD CS requires your organization to either develop that expertise internally or bring in contracted support for the duration of the migration. This isn’t a cost question alone; it’s a capacity and timeline question, since a team without current PQC-specific experience will move slower on genuinely novel work, parallel hierarchy design, hybrid coexistence, HSM validation, than a provider that has already done this work repeatedly across other customers.
What We’d Actually Recommend
Choose self-managed AD CS where control, existing internal PKI expertise, and the absence of a per-certificate service model matter most, and your team has genuine capacity to take on the parallel-hierarchy engineering directly. Choose managed PKI where deployment speed, reduced staffing burden, and provider-absorbed operational risk matter most, and where the recurring service cost is offset by the internal engineering time it saves. Calculate total cost including internal engineering time, not just license or service fees, to make this comparison honestly.
How Encryption Consulting Can Help
Encryption Consulting supports both paths rather than favoring one by default. For organizations continuing with self-managed AD CS, CertSecure Manager layers policy-driven certificate lifecycle management on top of your existing AD CS hierarchy, handling the pure, hybrid, and composite certificate complexity without requiring you to build that orchestration yourself. For organizations that want the operational burden shifted off their own team, our managed PKI services provide the same PQC-ready hierarchy, HSM validation, and hybrid coexistence covered in this guide as a service.
Our PQC Advisory Services help make this specific decision against your actual environment, control requirements, and staffing capacity, rather than defaulting to one model.
A Genuine Trade-Off, Not a Clear Winner
Self-managed AD CS and managed PKI both reach the same PQC-ready end state through genuinely different paths, and neither is universally correct. The decision comes down to how much your organization values direct control against how much it values offloading genuinely scarce PQC-specific engineering effort, and an honest total-cost comparison needs to weigh internal engineering time as seriously as any service fee. Making that trade-off deliberately, rather than defaulting to whichever model your organization has always used, is what actually produces the right choice for your specific situation.
Frequently Asked Questions
Does AD CS support ML-DSA certificates today?
Yes, since Microsoft’s May 2026 security update, but only through a newly deployed, parallel certification authority hierarchy; there is no in-place upgrade path for an existing AD CS installation.
Is managed PKI always faster to reach PQC readiness than self-managed AD CS?
Generally, since the provider has typically already solved the parallel-hierarchy deployment, HSM validation, and interoperability testing across other customers. Self-managed AD CS can move just as fast with sufficient dedicated internal expertise and capacity, but that capacity is often the limiting factor.
What should be included in a total cost comparison between the two models?
Internal engineering time for self-managed AD CS, not just the absence of a service fee, compared against the managed PKI service cost. Omitting internal engineering time from the comparison understates the real cost of the self-managed path.
Does choosing managed PKI mean giving up control over certificate policy?
This varies by provider and service model; some managed PKI offerings preserve significant customer control over policy while handling the underlying operational engineering. Confirm the specific control model with any provider rather than assuming a uniform level of control across the managed PKI category.
Can an organization use both models for different parts of its PKI?
Yes. Some organizations run self-managed AD CS for internal, high-control use cases while using managed PKI for other certificate categories, treating the choice as a per-use-case decision rather than an all-or-nothing organizational commitment.
- Key Takeaways
- The Comparison, Dimension by Dimension
- What Self-Managed AD CS Actually Requires for PQC
- What Managed PKI Actually Provides
- The Staffing Question Matters as Much as the Cost Question
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Genuine Trade-Off, Not a Clear Winner
- Frequently Asked Questions
