Service data sheet · 01 of 05Cryptographic infrastructure · SP-SVC-01
PKI & HSM Engineering, Post-Quantum Migration
A certificate hierarchy your auditors can trace, keys that never leave FIPS 140-3 hardware, and a dated plan to be off RSA-2048 and P-256 before NIST deprecates them in 2030.
How it runs
01
Cryptographic inventory — CBOM across code, config, HSM partitions and certificates; every algorithm and key length located.
02
Architecture — offline root, issuing CAs, CP/CPS, ceremony scripts under M-of-N control; hybrid ML-KEM / ML-DSA transition design.
03
Build and ceremony — HSM commissioning on Thales Luna, Entrust nShield or Utimaco; witnessed key generation with signed ceremony record.
04
Handover — runbooks, ACME lifecycle automation, WebTrust / ETSI EN 319 411 audit preparation, and a 12-month check-in.
What you get
- Cryptographic bill of materials (CBOM) with PQC risk ranking
- Signed root and issuing CA ceremony record with witness attestations
- CP/CPS, key-custody policy and operational runbooks
- Hybrid PQC migration plan against NIST IR 8547 and CNSA 2.0 dates
- Subordination or cross-sign path under SSL.com where public trust is required
Methodology
FIPS 203 / 204 / 205
RFC 5280 · 6960 · 8555 · 3161
CA/Browser Forum BR
ETSI EN 319 411 · WebTrust
Typical scope
Enterprise PKI, device and workload identity, S/MIME, document and code signing, TLS termination estate, secrets management, custom protocol review.
Not included
Operating your CA after handover (available as a managed service). Public-trust root inclusion. Hardware procurement. Application changes required to consume new certificates.
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com