Trust Boundaries and Scope
We identify security-relevant dependencies in the existing PKI.
- Record CA structure and relying systems
- Document administrative boundaries
- Prioritise critical uses
- Agree test approvals and limits
Architecture, implementation and traceable evidence
ADVISORI reviews selected security boundaries of an existing PKI.
The service assesses an existing PKI within an agreed scope. We examine who can obtain trusted certificates or change sensitive settings, and how misuse is detected and handled. Initial CA implementation, device rollout and routine certificate administration are separate scopes. A review is not a complete certification or regulatory examination.
ADVISORI reviews selected security boundaries of an existing PKI. Administrative access, certificate issuance, key protection and incident procedures are assessed against concrete evidence and prioritised actions.
6 service modules
Bookable individually or as an end-to-end programme.
We identify security-relevant dependencies in the existing PKI.
We assess who can request and approve which certificates.
We assess protective measures using available evidence.
We test whether agreed events are visible and actionable.
We assess readiness for suspected misuse.
We connect observations to verifiable improvements.
5 phases
Inputs include architecture, roles, certificate profiles and authorised examples of operating evidence. Tests have agreed owners, boundaries and stop conditions. The report separates observation, assessment, evidence and action. Untested components remain visible. A review assignment alone does not authorise changes to production keys or trust relationships.

Your contact
Sarah Richter
Head of Information Security, Cyber Security
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Consider the impact of a compromised requester or administrator. A technically valid certificate may still have been issued without proper authorisation through a flawed approval process.
7 QUESTIONS, BRIEFLY ANSWERED
The review examines agreed trust and access boundaries in an existing PKI, potentially including issuance, profiles, administrative rights, key protection and incident procedures. Evidence and untested areas are identified. The result does not automatically establish the security of every application using certificates.
We compare permitted requesters, profiles and approval rules with concrete records. An authorised test can examine whether an improper request is rejected. Production permissions are not changed without separate approval. A correctly signed certificate is not by itself proof that issuance was authorised.
Monitoring can reveal defined events such as unusual requests or administrative changes. We test the source, rule and response path. A successful alert proves the tested case, not detection of every attack. Certificate Transparency is not assumed to provide a complete inventory of a private PKI.
A scenario identifies decision-makers, affected certificates, dependent applications and possible responses. Revocation, trust changes and replacement require coordinated steps. We assess documented procedures and evidence within scope. Automatic recovery without considering trust consequences is not promised.
No. Protection depends on the module, operating mode, integration and administrative procedures. Product evidence is assessed against its actual scope. Even protected keys can coexist with excessive issuance rights or incorrect trust decisions. These are separate control objectives in the review.
Findings identify the event source, observation, potential consequence and accountable team. Alerts have agreed owners and escalation routes. Actions receive verifiable closure criteria. Implemented improvements, open work and later retest results are reported separately.
We identify intermittently connected devices, update capabilities and identity handling during replacement or loss. The review examines actual status-checking and trust behaviour. A general PKI design does not establish the security of every device platform. Future cryptographic changes require a separate dependency and compatibility assessment.










Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance