WebTrust-audited PKI for your organization ā without the dedicated infrastructure cost
Managed PKI Certificates is SSL’s shared private PKI service: a multi-tenant, WebTrust-audited platform that issues private certificates for your users, devices, and workloads. You get strict logical isolation, inherited audit evidence, and full lifecycle automation ā at a fraction of the cost of a dedicated CA hierarchy. Three subscription tiers scale from 500 to 100,000+ active certificates.
Managed PKI Certificates
WebTrust-audited private certificates on SSL's shared, multi-tenant platform. Strict logical isolation, predictable subscription pricing ā three tiers from $12,500/year.
Managed PKI Certificates vs. Dedicated PKI
| Managed PKI Certificates (Shared) | Dedicated PKI | |
|---|---|---|
| Infrastructure | Shared multi-tenant platform | Your own Root + Issuing CA(s) |
| WebTrust audit | Included | Included (High Assurance tier) |
| Root CA ownership | SSL retains Root CA | You own the Root CA hierarchy |
| Setup cost | None ā subscription only | $10,000 one-time Key Ceremony |
| Customization | Namespace vetting, policy per tenant | Full custom CPS, profiles, naming |
| Pricing | From $12,500/yr | From $20,000/yr + $10k setup |
| Best for | Cost-effective compliance PKI | Dedicated hierarchy, supply chain, IoT |
Choose Managed PKI Certificates if: you need WebTrust-audited private certificate infrastructure with predictable subscription pricing, and don’t need your own dedicated Root CA or custom Certificate Policy.
How shared infrastructure works safely
Namespace vetting
All CA private keys generated and stored in certified hardware ā never exportable in plaintext.
HSM-backed keys
SSL's PKI operations are independently audited ā the same audit covers your dedicated or shared hierarchy.
RBAC and audit logging
ACME (RFC 8555), SCEP, EST, REST API ā covers servers, devices, MDM, Kubernetes, CI/CD.
WebTrust audit
Same API used for public-trust certificates ā no separate integration required.