MediumChecklist

PKI Compliance Checklist

Comprehensive checklist for organizations to assess and maintain PKI compliance posture. Covers certificate inventory, key management, algorithm requirements, automation readiness, and regulatory awareness. Designed for quarterly reviews.

1-2 hours (initial), 30 min (quarterly)
Last Updated: December 2025
Progress: 0/86 complete0%

When to Use

  • Quarterly PKI compliance review
  • Preparing for security audit
  • Assessing organizational PKI maturity
  • After a certificate-related incident

Do NOT Use For

  • Emergency certificate replacement (use Emergency Runbook)
  • Single certificate installation (use platform-specific checklist)

Quick Reference (TL;DR)

  1. Maintain complete certificate inventory across all environments
  2. Automate expiration monitoring and renewal
  3. Use strong algorithms (RSA 2048+, SHA-256+, no SHA-1)
  4. Plan for 47-day certificate validity by 2029

1Certificate Inventory

Objective: Maintain complete visibility of all certificates in your organization

💡 Certificate Transparency logs (crt.sh) can help discover certificates issued for your domains

💡 Consider CLM tools like Venafi, Keyfactor, or DigiCert for automated discovery

2Expiration Management

Objective: Never be surprised by an expiring certificate

3Algorithm & Key Requirements

Objective: Ensure all certificates use secure, modern cryptography

💡 ECC P-256 provides equivalent security to RSA 3072 with better performance

💡 Post-quantum algorithms (ML-KEM, ML-DSA) are being standardized by NIST for 2024+

4Certificate Validity Periods

Objective: Stay ahead of shrinking certificate lifetimes

💡 March 2026: Maximum 200-day validity takes effect

💡 September 2026: Maximum 100-day validity takes effect

💡 March 2029: Maximum 47-day validity takes effect

5Private Key Security

Objective: Protect private keys throughout their lifecycle

6Certificate Authority Management

Objective: Maintain healthy CA relationships and redundancy

💡 CCADB (Common CA Database) at ccadb.org tracks CA status across all major root programs

💡 Entrust was distrusted in 2024; always have a backup CA relationship

7Certificate Transparency

Objective: Leverage CT for visibility and security

8Revocation Readiness

Objective: Be prepared to revoke certificates quickly when needed

9Automation & Certificate Agility

Objective: Be ready to replace all certificates quickly

10Documentation & Training

Objective: Ensure knowledge is captured and shared

11Regulatory & Compliance Tracking

Objective: Stay informed of industry requirements and deadlines