PKI Compliance Checklist
Comprehensive checklist for organizations to assess and maintain PKI compliance posture. Covers certificate inventory, key management, algorithm requirements, automation readiness, and regulatory awareness. Designed for quarterly reviews.
When to Use
- • Quarterly PKI compliance review
- • Preparing for security audit
- • Assessing organizational PKI maturity
- • After a certificate-related incident
Do NOT Use For
- • Emergency certificate replacement (use Emergency Runbook)
- • Single certificate installation (use platform-specific checklist)
Quick Reference (TL;DR)
- Maintain complete certificate inventory across all environments
- Automate expiration monitoring and renewal
- Use strong algorithms (RSA 2048+, SHA-256+, no SHA-1)
- Plan for 47-day certificate validity by 2029
1Certificate Inventory
Objective: Maintain complete visibility of all certificates in your organization
💡 Certificate Transparency logs (crt.sh) can help discover certificates issued for your domains
💡 Consider CLM tools like Venafi, Keyfactor, or DigiCert for automated discovery
2Expiration Management
Objective: Never be surprised by an expiring certificate
3Algorithm & Key Requirements
Objective: Ensure all certificates use secure, modern cryptography
💡 ECC P-256 provides equivalent security to RSA 3072 with better performance
💡 Post-quantum algorithms (ML-KEM, ML-DSA) are being standardized by NIST for 2024+
4Certificate Validity Periods
Objective: Stay ahead of shrinking certificate lifetimes
💡 March 2026: Maximum 200-day validity takes effect
💡 September 2026: Maximum 100-day validity takes effect
💡 March 2029: Maximum 47-day validity takes effect
5Private Key Security
Objective: Protect private keys throughout their lifecycle
6Certificate Authority Management
Objective: Maintain healthy CA relationships and redundancy
💡 CCADB (Common CA Database) at ccadb.org tracks CA status across all major root programs
💡 Entrust was distrusted in 2024; always have a backup CA relationship
7Certificate Transparency
Objective: Leverage CT for visibility and security
8Revocation Readiness
Objective: Be prepared to revoke certificates quickly when needed
9Automation & Certificate Agility
Objective: Be ready to replace all certificates quickly
10Documentation & Training
Objective: Ensure knowledge is captured and shared
11Regulatory & Compliance Tracking
Objective: Stay informed of industry requirements and deadlines