Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

How to Choose Between Self-Managed PKI and PKIaaS

PKI

The decision to build and operate your own public key infrastructure or hand that responsibility to a managed service provider is one of the most consequential infrastructure choices a security team makes. Get it wrong and you are either over-paying for operational overhead your team cannot actually sustain, or you are locked into a managed service that does not give you the control your regulatory environment requires.

The decision looks simpler than it is. Both models are described in similar terms by vendors, and “control” is invoked to argue for both sides. This guide cuts through that and gives you a practical framework for the decision, built on five dimensions that actually distinguish the two models in production: control, compliance, cost, time-to-value, and staffing. Each dimension gets a structured comparison, a scoring rubric, and real organizational signals to look for.

Quick Answer: Self-Managed PKI vs PKIaaS

Self-managed PKI means your team designs, builds, and operates the full CA infrastructure including hardware, HSMs, root CA ceremonies, CP/CPS, and 24/7 monitoring. PKIaaS means a specialist provider does all of that while you retain root CA key ownership through escrow and focus on using the PKI to issue and govern certificates. The choice is not about trust in a vendor; it is about where your organization’s operational capacity actually sits and what your compliance posture requires.

Key Takeaways

  • Self-managed PKI maximizes direct operational control but requires dedicated PKI expertise, capital investment in HSMs and infrastructure, and ongoing operational coverage. Most enterprises underestimate the real staffing and maintenance cost until they are three years in.
  • PKIaaS transfers operational burden to a specialist provider while preserving customer ownership of root CA keys through key escrow. The governance model does not change: you define what gets issued and to whom; the provider ensures the infrastructure that issues it is secure and available.
  • A third option, customer-hosted private CA, sits between the two models. It gives you direct key custody and more infrastructure control than PKIaaS while reducing operational complexity compared to fully self-managed PKI. It suits organizations with strict data sovereignty requirements that cannot accept keys living in a provider’s HSMs.
  • The CA/Browser Forum’s Ballot SC-081v3 schedule (47-day maximum TLS validity by March 2029) and NIST IR 8547’s post-quantum deprecation timeline (RSA/ECC deprecated around 2030, disallowed by 2035) both favor the model that integrates certificate lifecycle automation most completely with the CA layer.
  • The five-dimension scoring matrix in this guide produces a weighted score that most enterprises can apply directly to their own situation in under an hour.

Defining the Three Models

Before scoring anything, the models need precise definitions. The terminology problem in the PKI market is real: vendors use “self-managed,” “private CA,” “cloud PKI,” and “PKIaaS” interchangeably in ways that obscure meaningful operational differences. For the purposes of this guide, three models are in scope.

Self-Managed PKI

Your organization designs, procures, builds, and operates the full CA stack. This includes selecting CA software, provisioning and managing HSMs (on-premises FIPS 140-3 Level 3 hardware or cloud HSM services), designing the CA hierarchy, conducting root CA ceremonies, drafting and maintaining a CP/CPS, managing CRL distribution points and OCSP responders, monitoring the CA for availability, and handling incidents. All keys live in infrastructure you control directly.

Self-managed PKI may be on-premises only, cloud-only (CA software on cloud compute backed by cloud HSMs), or hybrid (offline root on-premises, online issuing CAs in cloud). In all cases, your team owns every operational decision and every operational failure.

PKIaaS (PKI as a Service)

PKIaaS transfers infrastructure design, deployment, and operations to a specialist provider. The provider conducts root CA ceremonies, manages HSMs, maintains the CP/CPS, operates CRL and OCSP infrastructure, provides 24/7 monitoring, and handles incident response. Your organization uses the running PKI to issue, renew, and revoke certificates across your environment.

A critical non-negotiable: in any properly structured PKIaaS service, the customer retains ownership of root CA cryptographic materials through customer-controlled key escrow. You can recover and re-establish your PKI independently of the provider if the relationship ends. Any provider that cannot demonstrate this independently verifiable exit path should not be on your shortlist.

Customer-Hosted Private CA (Middle Path)

A third model sits between the two. In a customer-hosted private CA deployment, you run CA software in your own cloud tenancy or on-premises environment and integrate it with a CLM platform for lifecycle governance and automation. Keys remain in your cloud HSM tenancy. The provider may supply the CA software and CLM tooling but does not operate your infrastructure or hold your keys.

This model suits organizations that have strict data sovereignty requirements or regulatory mandates that CA keys must stay within their own tenancy, but that also want to reduce operational complexity relative to fully self-managed PKI. It requires more infrastructure management than PKIaaS but less than building everything from scratch.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

The Five-Dimension Decision Framework

The five dimensions below cover the areas where self-managed PKI and PKIaaS actually differ in practice. For each dimension, there is a description of what each model delivers, the signals that push toward one or the other, and a 1-to-5 scoring rubric you can apply to your own situation.

Dimension 1: Control

Control in PKI means two things that are often conflated: key control (who physically holds the HSMs and can exercise the CA private keys) and governance control (who defines what certificates are issued, to whom, under what policy, and who can audit and enforce that policy).

Self-managed PKI gives you both. Every key lives in HSMs you provision and access. Every policy decision is yours. No third party has any ability to issue a certificate under your hierarchy without your systems and credentials. This is maximum control in the fullest sense.

PKIaaS gives you governance control but delegates key control to the provider’s infrastructure (under a key escrow arrangement that preserves your recovery rights). For the vast majority of enterprise use cases, governance control is what actually matters for security and compliance. The cases that require direct key control are narrower than they appear: classified environments, certain defense industrial base requirements, organizations in jurisdictions with specific data residency mandates that prohibit keys from being held by a foreign provider, and organizations with extremely unusual CA hierarchy requirements.

A useful question to ask before scoring this dimension: has your legal or compliance team produced a written requirement that CA keys cannot reside in a provider’s HSMs? If not, the control difference between PKIaaS (with proper key escrow) and self-managed PKI is largely operational rather than substantive from a security and governance standpoint.

Dimension 2: Compliance

Compliance in PKI has several layers: the certifications required of the CA infrastructure itself (SOC 2 Type II, FIPS 140-2/3 HSM validation, ISO/IEC 27001:2022), the documentation required by the organization’s regulatory environment (CP/CPS, audit logs, evidence of key ceremonies), and the ongoing monitoring and reporting required to demonstrate continuous compliance.

In self-managed PKI, all compliance burden falls on your team. Your security organization must obtain and maintain SOC 2 Type II for the CA infrastructure, procure and manage FIPS 140-3 certified HSMs, draft and maintain a CP/CPS, conduct documented root CA ceremonies, maintain CA audit logs, and produce evidence packages for internal and external auditors. This is a significant and often underestimated operational load, particularly when regulatory requirements change or CA software requires updates that affect the CP/CPS.

In PKIaaS, the provider maintains SOC 2 Type II for the full service, manages FIPS-validated HSMs, and typically develops and maintains the CP/CPS as part of the engagement. Your compliance team focuses on the policy decisions (what gets issued, to whom, under what conditions) rather than the operational evidence production. For regulated industries like CMMC Level 2 and above, FedRAMP authorized environments, HIPAA-covered entities, and organizations subject to DORA or NIS2, a PKIaaS provider with the relevant certifications and compliance documentation can materially reduce both the time and cost of meeting PKI-related control requirements.

One area where compliance requirements sometimes favor self-managed PKI: jurisdictions that require CA infrastructure to be located within specific geographic boundaries, operated by nationals of specific countries, or maintained on air-gapped systems with no external connectivity. These requirements are real and specific; if your regulatory environment includes them, confirm whether PKIaaS options meeting those constraints exist before defaulting to self-managed.

Dimension 3: Cost

PKI cost is frequently misunderstood because the visible costs (hardware, software licenses) are much smaller than the invisible ones (staff time, facilities, incident response, compliance documentation, and the cost of errors). A realistic total cost of ownership for a self-managed enterprise PKI includes:

  • Capital costs: FIPS 140-3 Level 3 HSMs for offline root CA (typically $20,000 to $60,000+ per unit depending on vendor and model), additional HSMs for issuing CAs, servers, secure offline root CA storage facility, and periodic hardware refresh cycles.
  • Software costs: CA software licensing or subscription, CLM tooling (if procured separately), and associated infrastructure software.
  • Staffing costs: At minimum one full-time staff member with senior PKI expertise. In practice, most enterprise PKI programs require 1.5 to 3 FTEs to sustain 24/7 availability, handle incidents, maintain compliance documentation, and manage CA software updates.
  • Operational costs: Root CA ceremony facilitation (internal labor or external consultant), CP/CPS legal review, ongoing HSM maintenance contracts, and FIPS validation documentation.
  • Incident and audit costs: Unplanned incident response (an expired CA certificate, a compromised issuing CA, or a missed CRL update can be costly incidents) and periodic audit evidence production.

PKIaaS converts most of these to a predictable subscription fee with no capital expenditure. The total cost comparison favors PKIaaS in most cases where the organization does not already have amortized HSM hardware and a staffed PKI team. For organizations that do have existing infrastructure and staff, the break-even calculation depends on whether that infrastructure requires refresh or re-architecture to meet current requirements (FIPS 140-3, post-quantum readiness, 47-day certificate automation).

Dimension 4: Time-to-Value

Time-to-value is the elapsed time from decision to a production-ready PKI issuing certificates in your environment. This dimension is frequently decisive for organizations responding to a deadline or an incident.

A self-managed PKI build from scratch typically requires 3 to 9 months, depending on organizational velocity and the availability of PKI expertise. The critical path items are HSM procurement and delivery lead time (often 6 to 12 weeks for dedicated hardware), CA software installation and testing, root CA ceremony preparation and execution, CP/CPS drafting and legal review, and integration testing with certificate consumers in your environment.

PKIaaS deployments, with a provider that has pre-built CP/CPS templates, established hardware infrastructure, and a structured onboarding process, typically reach production readiness in 2 to 6 weeks. For organizations that have received a compliance deadline, are responding to an audit finding, or are migrating from a failed or expiring on-premises PKI, this difference is often the single most important factor in the decision.

The time-to-value advantage of PKIaaS also compounds over time: when the CA/Browser Forum reduces certificate lifetimes (200 days as of March 2026, 100 days by March 2027, 47 days by March 2029 under Ballot SC-081v3), or when NIST finalizes post-quantum algorithm requirements, a PKIaaS provider absorbs the adaptation effort rather than placing it on your team.

Dimension 5: Staffing

PKI is a specialized discipline. The skills required to operate a CA well, including CA hierarchy design, HSM administration, root CA ceremony execution, CP/CPS authoring, CRL and OCSP management, and PKI incident response, are not the same as general IT or security skills, and they are not easily transferred from adjacent disciplines.

A realistic staffing requirement for a self-managed enterprise PKI with high availability, compliance documentation, and 24/7 incident response is 2 to 3 FTEs with senior PKI expertise. For many organizations, this represents either dedicated headcount that is hard to justify, or a shared responsibility model where PKI falls to someone for whom it is a secondary responsibility, which is the operating model that produces certificate outages and audit findings.

PKIaaS transfers the specialist operational burden to the provider. Your team needs enough PKI knowledge to define requirements, evaluate provider competency, review and approve CP/CPS content, configure certificate profiles, and govern the service, but the round-the-clock operational coverage is the provider’s responsibility. This model is more sustainable for organizations that cannot attract, retain, or justify dedicated PKI specialists, which describes most enterprises outside the very largest technology companies and financial institutions.

Certificate Management

Prevent certificate outages, streamline IT operations, and achieve agility with our certificate management solution.

The Scoring Matrix

Score your organization on each dimension from 1 to 5 using the descriptions below. Score 1 means your situation strongly favors self-managed PKI; score 5 means it strongly favors PKIaaS; scores 2, 3, and 4 capture the gradient in between. Multiply each score by the dimension weight and add all five to get your weighted total.

DimensionWeight1 — Strongly Self-Managed2 — Leans Self-Managed3 — Neutral4 — Leans PKIaaS5 — Strongly PKIaaS
Control20%Written legal or regulatory requirement for direct CA key custody; classified or air-gapped environment; CA hierarchy structure a provider cannot replicateNo hard mandate, but strong internal preference for direct key custody; concern about provider access to CA infrastructureKey escrow in PKIaaS satisfies recovery requirements; team is comfortable with governance control as the primary leverGovernance control over issuance policy, profiles, and audit is sufficient; no written requirement for direct key custodyFull confidence in provider key escrow model; priority is operational offload, not infrastructure ownership
Compliance25%CA must run on air-gapped systems; jurisdiction mandates keys in infrastructure you own and operate; no provider holds the required certifications for your environmentCompliance requirements are demanding but could be met by a provider with specific certifications; some uncertainty about provider qualificationEither model can satisfy compliance requirements; audit documentation effort is similar; no clear advantage either wayProvider’s SOC 2 Type II, FIPS-validated HSMs, and maintained CP/CPS reduce compliance burden; regulated industry benefits from provider’s existing frameworkProvider certifications (SOC 2 Type II, FIPS 140-3, ISO 27001, FedRAMP) fully satisfy all applicable requirements; provider-developed CP/CPS eliminates a major internal effort
Cost20%HSMs and CA software already fully amortized; dedicated PKI team on payroll; no infrastructure refresh required in the next 3 yearsExisting infrastructure approaching end of life but still serviceable; staffing partially in place; some additional investment requiredExisting infrastructure needs refresh; self-managed total cost of ownership and PKIaaS subscription are roughly comparable given current situationNo existing PKI hardware; PKI staffing would need to be hired or contracted; capital budget is constrained; subscription model fits betterStarting from zero PKI infrastructure; cannot justify dedicated PKI headcount; subscription cost is clearly lower than building and staffing from scratch
Time-to-Value15%No near-term deadline; 6 to 9 months to production is acceptable; PKI expertise available in-house to lead the buildMild timeline pressure; 4 to 6 months to production is workable if the project starts nowModerate deadline; 3 to 4 months to production is needed; either model could work with strong executionTight deadline; 6 to 10 weeks to production is required; self-managed build timeline is riskyUrgent deadline: audit finding, compliance date, incident response, or migration from a failed PKI; 2 to 4 weeks to production is needed; only PKIaaS is viable
Staffing20%2 to 3 senior PKI FTEs already in place; PKI is a recognized core competency with succession planning; retention risk is low1 to 2 PKI engineers on staff with solid PKI knowledge; coverage gaps exist for 24/7 incidents and CA ceremony workOne PKI generalist on staff; enough to govern a PKIaaS service but not enough to sustainably operate a self-managed CAPKI managed part-time by a security generalist; no dedicated PKI engineer; specialist hiring is being considered but not confirmedNo dedicated PKI staff; PKI managed on a best-effort basis; specialist hiring is not justifiable or not possible given market conditions

Score Interpretation

Weighted TotalIndicated ModelWhat This Usually Means in Practice
1.0 to 2.0Self-Managed PKIExisting investment, dedicated staff, and written regulatory requirements for direct key custody all align with self-managed. Modernize with CLM automation rather than switching models.
2.0 to 3.0Customer-Hosted Private CAKey custody preference or requirement exists but full operational self-management is not viable. Deploy CA software in your own tenancy connected to a managed CLM layer.
3.0 to 5.0PKIaaSLimited staffing, no amortized investment, compliance documentation benefit, or urgent timeline. Most enterprises score in the 3.0 to 4.5 range and are best served by PKIaaS.

Scenario Mapping: Common Situations and the Right Model

The matrix above produces a score, but real decisions are made in specific organizational contexts. The following scenarios map common enterprise situations to the right model.

ScenarioRecommended ModelKey Reason
Mid-size enterprise, no existing PKI, first-time deployment, compliance deadline in 90 daysPKIaaSSelf-managed PKI cannot be production-ready in 90 days; PKIaaS with an experienced provider can; compliance documentation included in the service
Large enterprise, existing on-premises PKI built 8 years ago, needs modernization, has 2 PKI engineersPKIaaS or customer-hosted private CAAging infrastructure needs replacement regardless; PKIaaS eliminates re-investment in hardware and transfers operational burden; if team has strong ownership preference, customer-hosted private CA with CLM automation is viable
Defense contractor, CMMC Level 2, keys must remain in US-controlled infrastructure under specific requirementsCustomer-hosted private CA or US-operated PKIaaSKey residency requirement must be confirmed against provider’s operating model; US-based PKIaaS providers with FedRAMP authorization may qualify; customer-hosted in own GovCloud tenancy is the safest default if provider qualification is uncertain
Technology company, 3 dedicated PKI engineers, complex certificate program across 50,000 certificates, existing HSM investmentSelf-managed PKI with CLM automation layerStaffing and existing investment justify self-managed; adding a CLM platform such as CertSecure Manager for lifecycle automation is the modernization path rather than a full model switch
Healthcare organization, HIPAA requirements, no PKI staff, needs S/MIME, device, and TLS certificatesPKIaaSNo staffing to sustain self-managed; compliance documentation benefit significant; multi-use-case PKI is well-served by a managed platform
Financial services organization, DORA compliance, multi-cloud environment, existing PKI under-resourcedPKIaaSDORA Article 9 requires strong cryptographic management evidence; PKIaaS provider’s SOC 2 Type II and CP/CPS simplify that evidence production; multi-cloud coverage is a PKIaaS strength
Startup with rapid growth, cloud-native infrastructure, first PKI need is workload and container certificatesPKIaaS or cloud-native private CA integrationNo infrastructure or staff to support self-managed; API-driven PKIaaS or cloud-provider private CA integrated with CLM is the right operating model for a cloud-native environment

What to Look For in Each Model

Self-Managed PKI: Minimum Requirements Before You Build

If your scoring matrix points toward self-managed PKI, confirm these are in place before starting procurement and design. Missing any one of them is the most common reason self-managed PKI projects run over time, over budget, or fail to meet compliance requirements after go-live.

  • Dedicated PKI staffing: At minimum one full-time senior PKI engineer, with a plan for coverage when that person is unavailable. PKI incidents do not wait for business hours.
  • HSM budget and procurement lead time: FIPS 140-3 Level 3 HSMs for offline root CA storage and online issuing CAs. Hardware procurement can take 6 to 12 weeks; include this in your project timeline.
  • Secure offline root CA facility: Physical access controls, tamper-evident storage, and documented procedures for who has access and under what conditions. A root CA key in a server room without proper physical controls is not a root CA; it is an incident waiting to happen.
  • CP/CPS authoring resources: Either an internal PKI policy expert or an external consultant who can draft, review, and maintain a Certificate Policy and Certification Practices Statement that reflects your actual operating procedures and regulatory requirements.
  • CLM integration plan: A self-managed CA is necessary but not sufficient. You also need a plan for certificate lifecycle automation, especially given the CA/Browser Forum’s phased reduction of public TLS certificate validity to 47 days by March 2029. Encryption Consulting’s CertSecure Manager integrates with self-managed CAs across all deployment models.
  • Incident response playbook: Documented procedures for CA compromise, certificate revocation at scale, CRL distribution point failure, and HSM failure scenarios.

PKIaaS: What to Require From Any Provider

If your scoring matrix points toward PKIaaS, these are the non-negotiable requirements to verify before signing a contract. A provider that cannot answer all of these clearly and in writing should not proceed to due diligence.

  • Customer-controlled key escrow: Documented, tested procedures for how you recover your root CA materials without provider cooperation. This is your exit right and your ultimate protection against vendor lock-in.
  • FIPS 140-2 or FIPS 140-3 Level 3 HSMs: Confirm dedicated HSM partitions for your CA keys, validated to the correct FIPS level. Request the NIST CMVP certificate number and verify it is current.
  • SOC 2 Type II report: Current report, full scope description, and willingness to share under NDA. SOC 2 Type I (design only) is not sufficient.
  • ISO/IEC 27001:2022 certification: For the infrastructure and operations scope relevant to your PKI.
  • CP/CPS development and maintenance: Confirm the provider develops the CP/CPS as part of the engagement, not as an optional add-on billed separately.
  • Offline root CA with documented ceremony: Ask to see or review the ceremony procedure. A provider operating a PKIaaS without a documented, witnessed, and logged root CA ceremony is not operating a PKI; they are operating a certificate machine.
  • Single-tenant infrastructure: Confirm whether your CA environment is single-tenant or multi-tenant beyond the HSM isolation boundary, and what the blast radius would be if another tenant’s environment were compromised.
  • PQC migration roadmap: Ask which NIST post-quantum algorithms (ML-KEM from FIPS 203, ML-DSA from FIPS 204, SLH-DSA from FIPS 205, all finalized August 2024) the platform supports today and what the migration path is for your existing RSA and ECDSA certificates. NIST IR 8547 guidance points toward deprecating RSA and ECC around 2030, with full disallowance by 2035.
  • CLM integration: Whether lifecycle automation is included in the managed service or is a separately purchased product, and which enrollment protocols are supported (ACME, EST, SCEP, CMP, REST API).
  • Availability SLA: A contractually committed SLA of 99.9% or higher for the CA and OCSP infrastructure, with documented remediation and compensation terms for breaches.

How the 47-Day Schedule and Post-Quantum Transition Affect This Decision

Two external pressures are changing the self-managed PKI vs. PKIaaS calculus in ways that favor PKIaaS more than they did three years ago.

The CA/Browser Forum’s Ballot SC-081v3 (approved April 2025) reduces maximum publicly trusted TLS certificate validity to 200 days as of March 15, 2026; 100 days as of March 15, 2027; and 47 days as of March 15, 2029. This schedule requires certificate lifecycle automation that is fully integrated with the CA layer. In self-managed PKI, this automation must be procured and operated separately. In PKIaaS, it is increasingly included or tightly coupled with the managed service. Organizations that have not yet built CLM automation are choosing not just between PKI models but also between whether they build or buy their automation layer.

The post-quantum transition compounds this. NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. NIST IR 8547 guidance points toward deprecating RSA and ECC around 2030. Migrating a CA hierarchy to post-quantum algorithms requires updates to CA software, HSM firmware, the CP/CPS, certificate profiles, and downstream systems. In self-managed PKI, this migration is your team’s complete responsibility. In PKIaaS, the provider manages the transition as part of the service.

Encryption Consulting’s PQC Readiness service and PQC Center of Excellence can help assess your current PKI’s quantum exposure and design the migration path regardless of which deployment model you operate.

How Encryption Consulting Can Help

Encryption Consulting is a vendor-neutral PKI and applied cryptography firm. We help organizations build, assess, and operate PKI across all three deployment models: fully self-managed, customer-hosted private CA, and PKI as a Service. We hold ISO/IEC 27001:2022 and SOC 2 certification and work across NIST, CMMC, FedRAMP, DORA, NIS2, PCI DSS, and HIPAA requirements.

  • PKI Assessment and Selection Advisory: Encryption Consulting can facilitate the five-dimension scoring exercise with your team, identify the decision factors specific to your regulatory environment, evaluate shortlisted providers against the requirements checklist, and produce a recommendation with supporting rationale. See our PKI Services overview.
  • PKI as a Service: A fully managed PKI with FIPS 140-3 HSM-backed CA keys, always-offline root CA with documented ceremony, CP/CPS development and maintenance, 24/7 monitoring, and customer-controlled key escrow. Details at PKI as a Service.
  • HSM as a Service: For organizations choosing the self-managed or customer-hosted model and needing dedicated FIPS 140-3 certified HSM capacity without capital expenditure. Details at HSM as a Service.
  • CertSecure Manager: A CA-agnostic CLM platform that integrates with self-managed CAs, cloud-native CAs, and PKIaaS deployments to provide unified certificate discovery, automated renewal via ACME, EST, and SCEP, and centralized policy enforcement. Relevant regardless of which PKI deployment model you choose. Details at CertSecure Manager.
  • PQC Readiness and Migration Planning: A structured assessment of your current PKI’s quantum exposure and a phased migration roadmap aligned to the NIST IR 8547 timeline. Start with the PQC Center of Excellence or PQC Readiness services.
  • PKI Design and Implementation: For organizations that score toward self-managed PKI and need expert assistance designing and building the CA hierarchy, conducting root CA ceremonies, and drafting CP/CPS. See PKI Services.

If you are working through this decision and want a structured conversation about which model fits your environment, reach out to Encryption Consulting.

Conclusion

Self-managed PKI and PKIaaS are not a quality hierarchy; they are two genuinely different operating models that fit different organizational situations. The right answer depends on whether your team has the staffing, expertise, capital, and compliance posture to sustain self-managed operations, or whether transferring operational burden to a specialist provider produces better security outcomes, faster deployment, and lower total cost.

For most enterprises evaluating this decision today, the five-dimension matrix produces scores above 3.0. Limited PKI staffing, no existing HSM investment, compliance requirements that a provider can simplify, and an urgent timeline all push in the same direction. The organizations that genuinely belong in self-managed PKI are those with existing investment, dedicated staff, and written regulatory requirements that demand direct key custody. Everyone else is paying for infrastructure complexity they do not need.

Either way, the CLM layer is not optional. The CA/Browser Forum’s 47-day validity schedule and the post-quantum transition both require automation and crypto-agility that are distinct from the CA infrastructure itself. Choose your PKI model and then make sure your CLM automation is designed to scale with it.

This post is reviewed on a six-month cadence and immediately when NIST updates FIPS 140-3 transition guidance, the CA/Browser Forum updates the Ballot SC-081v3 schedule, or NIST IR 8547 PQC deprecation timelines are revised.

Frequently Asked Questions

What is the main difference between self-managed PKI and PKIaaS?

In self-managed PKI, your team designs, builds, and operates the full CA infrastructure including hardware, HSMs, root CA ceremonies, CP/CPS, and 24/7 monitoring. In PKIaaS, a specialist provider handles all of that while you retain ownership of root CA keys through customer-controlled escrow and focus on using the PKI to issue and manage certificates. The core tradeoff is operational control versus operational burden.

Which model gives me more control over my PKI?

Self-managed PKI gives you the most direct, granular control over every aspect of your CA infrastructure. PKIaaS gives you governance control over what certificates are issued and to whom, while the provider controls the underlying infrastructure. For most enterprises, PKIaaS governance control is sufficient. The cases that genuinely require self-managed infrastructure are typically those with strict data sovereignty requirements, classified environments, or highly unusual CA hierarchy requirements.

Is PKIaaS more expensive than self-managed PKI?

Not necessarily when total cost of ownership is calculated. Self-managed PKI has high upfront capital costs (HSMs, servers, software) and ongoing staffing costs (2 to 3 senior PKI FTEs for full operational coverage). PKIaaS converts these to a predictable subscription with no capital expenditure. For organizations without existing PKI infrastructure and staff, PKIaaS is typically less expensive overall.

Can I keep control of my root CA keys with PKIaaS?

Yes, with the right provider. A properly designed PKIaaS service includes customer-controlled key escrow, where a copy of your root CA cryptographic materials is held by a trusted third party or is recoverable by you under documented procedures without requiring provider cooperation. This is a non-negotiable requirement when evaluating providers.

Which model deploys faster?

PKIaaS deploys significantly faster. A self-managed PKI build typically requires 3 to 9 months for procurement, infrastructure setup, CA software installation, root CA ceremony, CP/CPS drafting, and testing. A PKIaaS deployment with a provider that has pre-built CP/CPS templates and established security infrastructure can reach production readiness in 2 to 6 weeks.

What PKI expertise does my team need for each model?

Self-managed PKI requires at least one full-time staff member with deep PKI expertise covering CA hierarchy design, HSM administration, CP/CPS authoring, key ceremony procedures, and ongoing CA operations. PKIaaS requires PKI knowledge to define requirements, evaluate providers, configure certificate profiles, and govern the service, but transfers the operational specialist burden to the provider.

Which model is better for compliance and audit?

PKIaaS simplifies compliance significantly because the provider maintains SOC 2 Type II certification, FIPS 140-2/3 HSM validation, and ISO/IEC 27001:2022 for the infrastructure and operations, and typically develops and maintains the CP/CPS as part of the service. In self-managed PKI, all of these are your team’s responsibility to build, maintain, and produce evidence for at audit time.

What is a customer-hosted private CA and when does it make sense?

A customer-hosted private CA is a middle-ground model where you deploy CA software in your own cloud or on-premises environment and connect it to a managed CLM service for governance and lifecycle automation, while retaining direct key custody. It suits organizations that need CA keys to stay within their own cloud tenancy for data sovereignty reasons but want to avoid full self-managed operations.

Which model handles the CA/Browser Forum 47-day certificate schedule better?

PKIaaS providers typically include certificate lifecycle automation as part of the managed service, which is what the 47-day CA/Browser Forum Ballot SC-081v3 schedule (effective March 2029) actually requires. Self-managed PKI can support the 47-day schedule but requires your team to procure, deploy, and operate CLM automation separately.

How does the choice affect post-quantum cryptography migration?

PKIaaS providers that manage the full PKI stack are positioned to migrate CA hierarchies and certificate profiles to NIST-finalized post-quantum algorithms (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA, finalized August 2024) as part of the managed service. Self-managed PKI puts the full PQC migration burden on your team. NIST IR 8547 guidance points toward deprecating RSA and ECC around 2030, with full disallowance by 2035.