
Make certificates, wildcards and self-signed certificates visible
Blackfort PKI Assessment
We make your certificate landscape visible: internal CAs, self-signed certificates, wildcard certificates, expiry risks, ownership gaps and regulatory action areas – before they turn into operational or audit risks.
Grown-over-time certificate landscapes are the rule, not the exception
Most organisations operate a certificate landscape that has grown over years and that no one fully oversees: self-signed certificates on servers, appliances and internal applications; wildcard certificates protecting several external services at once; an installed but underused internal Microsoft Certificate Authority; unclear ownership for renewals; and no single source of truth for expiry dates, algorithms or intended usage.
In regulated environments this translates into a twofold risk. Operationally, an undetected expired certificate can trigger a production incident. From an audit angle, DORA, NIS2, ISO 27001 and the relevant BSI requirements expect documented, traceable management of cryptographic identities. Auditors accept neither informal spreadsheets nor "we know our most important certificates".
The Blackfort PKI Assessment addresses exactly this gap. It is delivered as a productised fixed-price offering – not as an open-ended consulting mandate. Within four to eight weeks you receive a robust decision basis: what is in use, what carries risk, what is the next step.
Where governance meets technical execution
Blackfort does not just rate individual certificates – we assess your overall machine identity and PKI governance: technically, organisationally and against regulatory requirements. Connecting regulatory guidance with technical execution is the core positioning of Blackfort Technology, and it is particularly relevant in a PKI assessment because the most common findings sit precisely on the seam between technology and accountability.
In practice, this means we combine certificate discovery and ADCS template review with the question of who in the organisation owns renewal, revocation and algorithm migration – and where these responsibilities are currently missing or unclear. Both perspectives produce a prioritised action plan that is workable in the technical team and presentable in the steering committee.
The assessment is vendor-neutral. We work with what is in place – Microsoft ADCS, EJBCA, cloud PKI, commercial CAs, ACME automation – and recommend additional tooling only where it demonstrably closes a gap.
Scope of work
The scope is tiered across the three packages, but follows the same methodology throughout: capture, assessment, prioritisation, roadmap. We bring the methodology and tooling, you provide the contacts and access to the relevant systems.
Depending on the selected package the assessment covers: an inventory of existing certificate sources; analysis of internal and external TLS certificates; identification of self-signed certificates; evaluation of wildcard certificates; review of Microsoft ADCS, EJBCA or cloud PKI structures; analysis of expiry, operational and ownership risks; and a review of cryptography, validity periods and certificate profiles.
On top of the technical findings we map results against DORA Art. 8, NIS2 Art. 21, ISO 27001:2022 Annex A.8.24 and the applicable BSI requirements. From there we build a roadmap for Certificate Lifecycle Management with a clean separation between short-term hardening measures and medium-term architectural decisions.
Deliverables
Every PKI Assessment closes with a defined set of deliverables that feeds directly into internal decision-making and audit processes. We do not deliver a 200-page PDF that no one reads – we deliver focused documents written for clearly identified audiences.
Concretely you receive a certificate risk overview of the identified findings, a management summary for IT leadership, the CISO and (where relevant) the DORA programme owner, a technical findings list per certificate or CA configuration, a prioritised action roadmap with effort indication, and a target picture for PKI and Certificate Lifecycle Management.
On request we extend the written deliverables with a presentation for IT leadership, the CISO or the DORA programme – including a short Q&A with the assessment team.
Deliverables
- Certificate risk overview
- Management summary
- Technical findings list
- Prioritised action roadmap
- Target picture for PKI and Certificate Lifecycle Management
- Optional: presentation for IT leadership, CISO or DORA programme
Our Services
- Inventory of all existing certificate sources
- Analysis of internal and external TLS certificates
- Identification of self-signed certificates
- Evaluation of wildcard certificates
- Review of Microsoft ADCS, EJBCA, cloud PKI
- Assessment of cryptography, validity and certificate profiles
- Mapping against DORA, NIS2, ISO 27001 and BSI
- Roadmap for Certificate Lifecycle Management
Your Benefits
- Transparency over the real certificate landscape
- Prioritised actions instead of a finding-by-finding list
- Decision-ready output for IT leadership and the CISO
- Lower operational and audit risk
- Plug-in basis for DORA, NIS2 and ISO 27001 initiatives
Packages
Three fixed-price variants – matched to your environment
The PKI Assessment is offered as a productised fixed-price service in three variants. The middle variant is the appropriate entry point for the majority of regulated mid-sized organisations.
PKI Quick Assessment
Purpose
Entry-level engagement with a management summary and initial risk assessment – without deep technical discovery.
Best fit
Smaller environments, pre-checks ahead of a larger programme, budget scoping or scoping before a DORA or NIS2 initiative.
PKI Assessment
Purpose
Standard package with full discovery, risk evaluation, regulatory mapping and roadmap.
Best fit
Regulated organisations with an internal Microsoft CA, external TLS certificates, wildcards and self-signed certificates.
Enterprise Certificate Intelligence Assessment
Purpose
In-depth analysis for complex environments including cloud, Kubernetes, load balancers, multiple CAs and extended discovery.
Best fit
Large or hybrid environments with multiple networks, multiple CAs and elevated discovery and reporting needs.
Not sure which certificates are actually in use across your environment?
Then the PKI Assessment is the fastest route to transparency, prioritised actions and a defensible decision basis.
Request PKI AssessmentFrequently Asked Questions
Is the PKI Assessment a tool or a consulting engagement?
It is a productised assessment. Depending on the package we can use automated discovery methods, but the output is an evaluated decision basis with a management summary and a roadmap – not the raw output of a scanner.
Do we need to operate a PKI already?
No. The assessment is particularly valuable for organisations running many self-signed certificates, wildcards or only partially used internal CAs. That starting position is often where the assessment delivers the largest insight.
Is this relevant for DORA?
Yes. Certificates are part of technical dependencies, operational stability, access control and ICT risk management. Lack of visibility creates operational and audit risk. The assessment delivers the data basis for a DORA-compliant certificate register.
Can Microsoft ADCS and EJBCA be assessed?
Yes. Blackfort evaluates existing Microsoft ADCS, EJBCA, cloud PKI and hybrid PKI architectures – including template configuration, ESC patterns, HSM usage, CRL/OCSP reachability and cryptographic policy.
What happens after the assessment?
Depending on the findings Blackfort can support with target architecture, CLM selection, Microsoft ADCS hardening, EJBCA design, ACME automation or regulatory documentation. The assessment is explicitly not a sales pitch – the roadmap remains usable if implementation runs internally or with another partner.
Kontakt aufnehmen
Ready for the next step?
Talk to us about your security requirements – concrete, without obligation and at eye level.