Blackfort Technology
Blackfort PKI Assessment

Make certificates, wildcards and self-signed certificates visible

Blackfort PKI Assessment

We make your certificate landscape visible: internal CAs, self-signed certificates, wildcard certificates, expiry risks, ownership gaps and regulatory action areas – before they turn into operational or audit risks.

Grown-over-time certificate landscapes are the rule, not the exception

Most organisations operate a certificate landscape that has grown over years and that no one fully oversees: self-signed certificates on servers, appliances and internal applications; wildcard certificates protecting several external services at once; an installed but underused internal Microsoft Certificate Authority; unclear ownership for renewals; and no single source of truth for expiry dates, algorithms or intended usage.

In regulated environments this translates into a twofold risk. Operationally, an undetected expired certificate can trigger a production incident. From an audit angle, DORA, NIS2, ISO 27001 and the relevant BSI requirements expect documented, traceable management of cryptographic identities. Auditors accept neither informal spreadsheets nor "we know our most important certificates".

The Blackfort PKI Assessment addresses exactly this gap. It is delivered as a productised fixed-price offering – not as an open-ended consulting mandate. Within four to eight weeks you receive a robust decision basis: what is in use, what carries risk, what is the next step.

Where governance meets technical execution

Blackfort does not just rate individual certificates – we assess your overall machine identity and PKI governance: technically, organisationally and against regulatory requirements. Connecting regulatory guidance with technical execution is the core positioning of Blackfort Technology, and it is particularly relevant in a PKI assessment because the most common findings sit precisely on the seam between technology and accountability.

In practice, this means we combine certificate discovery and ADCS template review with the question of who in the organisation owns renewal, revocation and algorithm migration – and where these responsibilities are currently missing or unclear. Both perspectives produce a prioritised action plan that is workable in the technical team and presentable in the steering committee.

The assessment is vendor-neutral. We work with what is in place – Microsoft ADCS, EJBCA, cloud PKI, commercial CAs, ACME automation – and recommend additional tooling only where it demonstrably closes a gap.

Scope of work

The scope is tiered across the three packages, but follows the same methodology throughout: capture, assessment, prioritisation, roadmap. We bring the methodology and tooling, you provide the contacts and access to the relevant systems.

Depending on the selected package the assessment covers: an inventory of existing certificate sources; analysis of internal and external TLS certificates; identification of self-signed certificates; evaluation of wildcard certificates; review of Microsoft ADCS, EJBCA or cloud PKI structures; analysis of expiry, operational and ownership risks; and a review of cryptography, validity periods and certificate profiles.

On top of the technical findings we map results against DORA Art. 8, NIS2 Art. 21, ISO 27001:2022 Annex A.8.24 and the applicable BSI requirements. From there we build a roadmap for Certificate Lifecycle Management with a clean separation between short-term hardening measures and medium-term architectural decisions.

Deliverables

Every PKI Assessment closes with a defined set of deliverables that feeds directly into internal decision-making and audit processes. We do not deliver a 200-page PDF that no one reads – we deliver focused documents written for clearly identified audiences.

Concretely you receive a certificate risk overview of the identified findings, a management summary for IT leadership, the CISO and (where relevant) the DORA programme owner, a technical findings list per certificate or CA configuration, a prioritised action roadmap with effort indication, and a target picture for PKI and Certificate Lifecycle Management.

On request we extend the written deliverables with a presentation for IT leadership, the CISO or the DORA programme – including a short Q&A with the assessment team.

Deliverables

  • Certificate risk overview
  • Management summary
  • Technical findings list
  • Prioritised action roadmap
  • Target picture for PKI and Certificate Lifecycle Management
  • Optional: presentation for IT leadership, CISO or DORA programme

Our Services

  • Inventory of all existing certificate sources
  • Analysis of internal and external TLS certificates
  • Identification of self-signed certificates
  • Evaluation of wildcard certificates
  • Review of Microsoft ADCS, EJBCA, cloud PKI
  • Assessment of cryptography, validity and certificate profiles
  • Mapping against DORA, NIS2, ISO 27001 and BSI
  • Roadmap for Certificate Lifecycle Management

Your Benefits

  • Transparency over the real certificate landscape
  • Prioritised actions instead of a finding-by-finding list
  • Decision-ready output for IT leadership and the CISO
  • Lower operational and audit risk
  • Plug-in basis for DORA, NIS2 and ISO 27001 initiatives

Get in Touch

Meet our security experts.

Request Consultation

Packages

Three fixed-price variants – matched to your environment

The PKI Assessment is offered as a productised fixed-price service in three variants. The middle variant is the appropriate entry point for the majority of regulated mid-sized organisations.

PKI Quick Assessment

from €4,900 net

Purpose

Entry-level engagement with a management summary and initial risk assessment – without deep technical discovery.

Best fit

Smaller environments, pre-checks ahead of a larger programme, budget scoping or scoping before a DORA or NIS2 initiative.

Request Quick Assessment
Recommended

PKI Assessment

€9,900 net

Purpose

Standard package with full discovery, risk evaluation, regulatory mapping and roadmap.

Best fit

Regulated organisations with an internal Microsoft CA, external TLS certificates, wildcards and self-signed certificates.

Request assessment

Enterprise Certificate Intelligence Assessment

on request
typically €14,900–19,900 net

Purpose

In-depth analysis for complex environments including cloud, Kubernetes, load balancers, multiple CAs and extended discovery.

Best fit

Large or hybrid environments with multiple networks, multiple CAs and elevated discovery and reporting needs.

Request Enterprise variant

Not sure which certificates are actually in use across your environment?

Then the PKI Assessment is the fastest route to transparency, prioritised actions and a defensible decision basis.

Request PKI Assessment

Frequently Asked Questions

Is the PKI Assessment a tool or a consulting engagement?

It is a productised assessment. Depending on the package we can use automated discovery methods, but the output is an evaluated decision basis with a management summary and a roadmap – not the raw output of a scanner.

Do we need to operate a PKI already?

No. The assessment is particularly valuable for organisations running many self-signed certificates, wildcards or only partially used internal CAs. That starting position is often where the assessment delivers the largest insight.

Is this relevant for DORA?

Yes. Certificates are part of technical dependencies, operational stability, access control and ICT risk management. Lack of visibility creates operational and audit risk. The assessment delivers the data basis for a DORA-compliant certificate register.

Can Microsoft ADCS and EJBCA be assessed?

Yes. Blackfort evaluates existing Microsoft ADCS, EJBCA, cloud PKI and hybrid PKI architectures – including template configuration, ESC patterns, HSM usage, CRL/OCSP reachability and cryptographic policy.

What happens after the assessment?

Depending on the findings Blackfort can support with target architecture, CLM selection, Microsoft ADCS hardening, EJBCA design, ACME automation or regulatory documentation. The assessment is explicitly not a sales pitch – the roadmap remains usable if implementation runs internally or with another partner.

Kontakt aufnehmen

Ready for the next step?

Talk to us about your security requirements – concrete, without obligation and at eye level.