When you need it
Certificates expire without warning and take services down. Nobody is sure who runs the internal CA, which templates anyone can enrol for, or whether revocation works. Public TLS certificates now last at most 200 days, falling to 100 days in March 2027, so manual renewal will not keep up.
What sets the quote
- One CA hierarchy of up to 4 CAs, on AD CS, AWS Private CA, Google Cloud Certificate Authority Service or HashiCorp Vault.
- A certificate inventory from up to 3 sources, such as AWS Certificate Manager, Azure Key Vault, Google Cloud Certificate Manager, cert-manager or Certificate Transparency logs.
- TLS settings on up to 10 key endpoints that you name.
- A revocation check of CRL and OCSP publication.
- Larger hierarchies, more sources or more endpoints are quoted after sizing.
What changes
- You know which certificates could expire and cause an outage, and who owns each one.
- Every finding is rated red, amber or green with evidence, so your team can act without investigating again.
- You know whether revocation works and whether your CA keys and templates are protected against misuse.
- You have a roadmap ordered by risk and effort, ready for your backlog.
What you get
- Report rated red, amber or green for the CA hierarchy, key protection, issuance, revocation and TLS, with evidence and a fix for each finding
- Certificate inventory from the agreed sources, as a CSV file
- Expiry risk list ordered by expiry date and impact, with the owner and renewal method of each certificate
- TLS results per endpoint covering protocol versions, cipher suites, certificate chain and key strength
- Revocation results for every CRL distribution point and OCSP responder
- Roadmap ordered by risk and effort
- A 90-minute readout with your team
What we cover on each platform
| Platform | What we check |
|---|---|
| AD CS | Offline root, CA key protection, certificate templates and enrolment permissions against the published escalation paths (ESC1 and later), CRL and AIA publication |
| AWS Private CA | Hierarchy and CA mode, key algorithms, IAM and resource policies, CRL and OCSP settings, audit reports |
| Google Cloud Certificate Authority Service | CA pools and tiers, issuance policies, certificate templates, IAM on CA pools, CRL publication |
| HashiCorp Vault | PKI mounts and roles, allowed domains and TTLs, policies that can issue, CRL and OCSP settings |
Not included
- Fixing the findings (quoted separately, often as the private PKI and certificate automation package)
- Penetration testing, including any attempt to exploit AD CS (we can refer you to a certified partner)
- Formal CA audits, such as WebTrust, or compliance opinions
What we need from you
- Read-only access to the CA platform: SecurityAudit and ViewOnlyAccess in AWS, Viewer and Security Reviewer in Google Cloud, a read-only token for the Vault PKI mounts, or a read-only domain account plus CA configuration exports for AD CS.
- Read-only access to the inventory sources, such as Key Vault Reader in Azure or read access to cert-manager resources in Kubernetes.
- The list of key endpoints, and a jump host or VM inside your network for scanning internal endpoints.
- One 60-minute interview with whoever owns your PKI.
How it works
Free 30-minute call, then a written fixed quote once the hierarchy, sources and endpoints are agreed.
Read-only collection of CA settings and the certificate inventory, plus TLS scans and the revocation check.
Interview to confirm owners, renewal methods and priorities.
Report, expiry risk list, roadmap and a 90-minute readout.
At a glance
- Duration
- 1 week
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
Domain and external attack surface check
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Microsoft 365 security baseline
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.
Identity modernisation
Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.