Skip to main content
Category: Cryptography & Key Management

Public Key Infrastructure

Also known as:
Simply put

Public Key Infrastructure (PKI) is the combination of technologies, policies, and processes used to create and manage the digital certificates and cryptographic keys that secure data and verify identities. It provides the foundation for encrypting information and confirming that parties in a digital exchange are who they claim to be. In practice, PKI is what allows secure communications, such as encrypted web traffic and authenticated systems, to work reliably.

Formal definition

PKI is a framework of roles, policies, hardware, software, and procedures used to create, manage, distribute, use, store, and revoke digital certificates and their associated public-private key pairs. It administers public key encryption by binding public keys to verified identities through certificates issued and governed under defined policies, enabling confidentiality, authentication, and integrity for data transfers and system access. Effective PKI depends on the surrounding governance, certificate policies, issuance and revocation processes, and platform administration, rather than on cryptographic algorithms alone.

Why it matters

PKI underpins much of the trust that digital systems rely on. It provides the mechanism for encrypting data in transit and for verifying that the parties in a digital exchange are who they claim to be, which is what allows secure communications such as encrypted web traffic and authenticated system access to function reliably. Without a working PKI, organizations lack a scalable way to bind cryptographic keys to verified identities, and the guarantees of confidentiality, authentication, and integrity that businesses depend on begin to erode.

A point experienced practitioners emphasize is that the security of PKI depends on the surrounding governance rather than on the strength of cryptographic algorithms alone. Certificate policies, issuance and revocation processes, key storage, and platform administration determine whether a PKI actually delivers trust. Weaknesses in these processes, such as poorly controlled certificate issuance or ineffective revocation, can undermine the entire framework even when the underlying encryption is sound. This is why PKI is best understood as a combination of technologies, policies, and processes, not simply a set of tools.

For security leaders, PKI is a governance and risk topic as much as a technical one. Decisions about how certificates are issued, who is accountable for their lifecycle, and how key material is protected carry organizational risk that extends well beyond the systems administrators who operate the platforms. Treating PKI purely as an operational or technical concern, rather than as an area requiring policy, oversight, and defined ownership, is a common mistake that leaves gaps in accountability.

Who it's relevant to

Security and IT Leaders
Those responsible for security strategy and governance need to understand PKI as a framework requiring defined policies, ownership, and lifecycle management, not just a technology deployment. Decisions about certificate issuance, revocation, and key protection carry organizational risk and require executive-level oversight, since accountability for these decisions typically remains with the organization.
Virtual and Fractional CISOs
In advisory engagements, a virtual or fractional CISO may help a client establish or improve the policies and processes that govern PKI, such as certificate policies, issuance and revocation procedures, and defined ownership, as part of broader risk management and program development. Hands-on administration of certificate platforms is typically outside the scope of such an engagement unless explicitly contracted, and the value of the guidance depends on organizational maturity and access to the relevant stakeholders.
Systems and Infrastructure Administrators
Practitioners who operate the server platforms, software, and workstations involved in PKI are responsible for the day-to-day tasks of creating, distributing, storing, and revoking certificates and keys. Their work is where certificate policies and issuance and revocation processes are put into practice, making disciplined administration essential to the trust the framework provides.
Organizations Securing Data and Communications
Any organization that relies on encrypted communications, authenticated systems, or secure data transfers depends on PKI to bind public keys to verified identities. Understanding that PKI's reliability rests on governance and process, not cryptographic algorithms alone, helps these organizations avoid gaps that could undermine confidentiality, authentication, and integrity.

Inside PKI

Certificate Authority (CA)
The trusted entity that issues, signs, and vouches for digital certificates. A CA may be an internal (private) authority operated by the organization or a publicly trusted commercial CA, and the choice affects trust scope and management overhead.
Registration Authority (RA)
The component or role that verifies the identity of entities requesting certificates before the CA issues them. The RA handles vetting and enrollment; it does not itself sign certificates, which remains the CA's function.
Digital Certificates
The credentials that bind a public key to an identity such as a user, device, or service. Certificates carry validity periods, issuing CA information, and usage constraints that define what the certificate may legitimately be used for.
Public and Private Key Pairs
The asymmetric cryptographic keys underpinning PKI. The public key is distributed within the certificate while the private key must remain protected by its owner; compromise or mishandling of private keys undermines the entire trust model.
Certificate Revocation Mechanisms
Methods such as Certificate Revocation Lists (CRLs) and the Online Certificate Status Protocol (OCSP) used to signal that a certificate should no longer be trusted before its natural expiration, for example after key compromise.
Certificate Lifecycle and Policy
The processes and governing documents (often expressed as a Certificate Policy and Certification Practice Statement) covering issuance, renewal, rotation, and expiration. These define how the PKI is operated and what practices govern trust decisions.

Common questions

Answers to the questions practitioners most commonly ask about PKI.

Does a virtual CISO manage the organization's PKI day to day, including issuing and rotating certificates?
Generally no. A virtual CISO typically provides strategy and governance for a PKI program, such as defining certificate lifecycle policies, trust models, and roles, but hands-on operational tasks like issuing, rotating, or revoking certificates and administering the certificate authority are usually out of scope unless explicitly contracted. In many engagements those operational duties remain with internal teams or a dedicated service provider. Conflating a vCISO with the operational owner of PKI is a common mistake an expert would correct.
Isn't PKI purely a technical control that a security leader can delegate entirely to engineers?
Not in practice. While PKI has significant technical components, it is also a governance and business risk function. Decisions about trust anchors, certificate policy, key custody, and acceptable cryptographic standards carry organizational risk and often accountability that remains with the client's officers. A virtual CISO typically frames PKI as a governance concern, advising and directing policy while engineers handle implementation. Treating it as a purely technical matter tends to leave policy, ownership, and risk decisions undefined.
How can a virtual CISO help establish PKI governance in an organization with low security maturity?
In lower-maturity organizations, a virtual CISO often starts by defining foundational elements: who owns certificate issuance, what a certificate policy and certification practice statement should cover, and how keys are stored and protected. The value of this work typically depends on client cooperation, access to stakeholders, and clarity of scope. A vCISO advises and directs rather than executing the buildout, so the pace and depth generally vary with the organization's existing capabilities and resources.
Where does PKI fit when a virtual CISO supports readiness for frameworks like ISO 27001 or SOC 2?
PKI often supports control objectives related to cryptography, access management, and secure communications. A virtual CISO can help map PKI practices to relevant control requirements and support readiness efforts. It is important to distinguish supporting readiness from asserting certification, however. A vCISO engagement does not itself certify an organization or guarantee a passing audit; certification depends on the auditor, evidence, and the organization's actual implementation.
Who should be accountable for key management decisions when a vCISO is engaged?
Accountability for key management decisions usually remains with the client organization and its officers, even when a virtual CISO advises on the approach. A vCISO may recommend controls such as separation of duties for key custody, hardware-backed key storage, or defined rotation intervals, but legal and organizational accountability typically stays with the client unless a contract specifies otherwise. Clarifying this distinction between advisory responsibility and organizational accountability early in the engagement helps avoid misaligned expectations.
What common pitfalls should an organization watch for when implementing PKI under vCISO guidance?
Frequently observed issues include undefined ownership of certificate lifecycle tasks, expired certificates causing outages, unclear key custody, and assuming the vCISO or a managed provider handles operations that were never explicitly scoped. A virtual CISO can help surface and document these gaps, but resolving them typically depends on defined scope, client cooperation, and access to the teams performing the operational work. Engagement value tends to diminish where these dependencies are not met.

Common misconceptions

PKI is primarily a technical tooling concern that can be delegated entirely to the operations team.
PKI involves governance, policy, and trust decisions that are business risk matters, not purely technical ones. A virtual CISO typically advises on PKI strategy, policy, and lifecycle governance while accountability for those decisions generally remains with the client organization and its officers. Hands-on administration of certificates and CA infrastructure is usually out of scope for a vCISO unless explicitly contracted.
Deploying PKI or issuing certificates makes an organization compliant with frameworks such as ISO 27001, SOC 2, or PCI DSS.
PKI can support readiness for controls addressed by these frameworks, but implementing it does not by itself assert or guarantee compliance or certification. Compliance depends on how controls are designed, operated, evidenced, and assessed, and this may vary by provider and engagement scope.
Once certificates are issued, PKI runs itself and no longer needs attention.
PKI requires ongoing lifecycle management including renewal, rotation, revocation, and private key protection. Neglected expirations or compromised keys can break trust or create exposure, so effective value depends on defined processes, organizational maturity, and continued stakeholder cooperation.

Best practices

Establish clear governance documents, such as a Certificate Policy and Certification Practice Statement, that define how certificates are issued, renewed, rotated, and revoked before scaling deployment.
Protect private keys with strong controls and clearly assign ownership, treating private key compromise as a scenario that requires prompt revocation.
Maintain and monitor certificate revocation mechanisms such as CRLs or OCSP so that compromised or retired certificates can be distrusted before expiration.
Track certificate lifecycles proactively to avoid unexpected expirations, defining renewal and rotation responsibilities across the relevant teams.
Decide deliberately between internal (private) and publicly trusted CAs based on trust scope, management overhead, and organizational maturity rather than defaulting to one approach.
Clarify in any advisory or virtual CISO engagement which PKI responsibilities are strategic and governance-related versus hands-on operational, and confirm that accountability for security decisions remains defined within the client organization.