Public key infrastructure
A PKI is not a software project
It is a long-term commitment to key custody, continuity and the value of the evidence, carrying obligations that will outlast you. What you decide at scoping, you operate for a decade. That holds for a state’s root authority just as much as for a large group’s internal PKI or a CIO’s TLS estate.
Most of your estate isn’t where you’re looking
Control of the keys, traceability, continuity: the requirements don’t change from one scale to the next. What changes is what you lose when they give way.
States, regulators, certification authorities
National and sovereign PKI
A root authority operated in your name, on your territory, carrying the evidentiary weight the law grants it, not the weight a foreign vendor is willing to concede.
- Offline root authority and a hierarchy of intermediate authorities
- Certificate policy and certification practice statement
- Digital identity for citizens and public officials
- Digital public procurement and electronic invoicing
- Skills transfer to national teams
Banks, insurers, telecoms, energy, healthcare, industry
Enterprise PKI
An internal authority for your people, your applications and your devices. Your internal uses stop depending on a public authority’s calendar.
- An internal authority for the uses that need not be public
- Employee certificates, smart cards and strong authentication
- Signing and sealing of business and document flows
- Device, IoT and industrial certificates
- A clean separation between internal and public trust
CIOs, CISOs, platform and operations teams
SSL/TLS and machine identity PKI
The largest estate, the least inventoried, and the leading cause of avoidable outages. It gives no warning before it goes down.
- Discovery and inventory of the existing certificate estate
- A private authority for internal TLS, public for what is exposed
- Automated renewal (ACME) and CI/CD integration
- Expiry monitoring and alerting before an incident
- Workload identity: containers, services, APIs
Four steps, and nothing unplanned between them
- 01
Scoping
Policy and architecture
The document that governs everything else: certificate policy, practice statement, authority hierarchy. We write it before anything is bought.
- 02
Foundation
Infrastructure and HSM
Offline root, intermediate authorities and hardware security modules, on your territory or in your own data centres.
- 03
Ceremony
Key generation
Conducted, recorded and documented, before the secret holders and appointed witnesses. This is the record your auditor will ask for.
- 04
Operations
Issuance and oversight
Enrolment, issuance, revocation, CRL and OCSP, monitoring, then the handover of skills to your teams.
The expensive mistake is building the wrong PKI
A certification authority is operated for a decade. What you settle at scoping (hierarchy, certification level, platform) you carry for all of it. We come in before that, and we train the people who will hold the infrastructure afterwards.
Advisory
We work the decision before it costs anything: what the regulatory framework requires of you, what your existing estate already imposes, and what your teams will still be able to operate in five years.
- Scoping study and authority architecture
- Certificate policy and certification practice statement
- Platform and HSM selection, with no vendor tie
- Inventory and audit of the existing certificate estate
- Preparation for homologation and compliance audit
Training
A PKI your teams cannot operate is a PKI you are renting from someone. We train the people who will hold it, through to full handover.
- PKI and electronic signature fundamentals
- Day-to-day operation of a certification authority
- Key ceremony: roles, secret holders, written record
- Separate sessions for technical teams and for decision-makers
- Skills transfer at the end of a programme
The facts, and where to check them
National programmes
Tunisia
NGSIGN homologated by the National Electronic Certification Agency (ANCE) and certified as an eIDAS Qualified Trust Service Provider.
Chad
PKI and electronic signature training and awareness workshop, run with ANSICE.
Mauritania
Awareness and training workshop on PKI and electronic trust services.
Benin
Deployment of the NGSIGN electronic signature platform at the Port Autonome de Cotonou (PAC).
Togo
Hosted a Togolese delegation on a study mission covering the digitalisation of public procurement.
Burkina Faso
NG Technologies’ first partnership convention in sub-Saharan Africa.
Libya
Strategic partnership with Ebkar to bring digital trust services and PKI to the Libyan market, in line with Law No. 6 of 2022.
Large organisations
Banks, insurers, operators and public bodies run our products in production. These are the organisations whose certificate volumes and continuity requirements justify a dedicated infrastructure.
- Banking
- Insurance and reinsurance
- Telecoms
- Energy and hydrocarbons
- Public health
- Government and agencies
- Ports and logistics
- Registries and public procurement
- Fintech
No vendor agreement steers our recommendation
We are tied to no vendor. The platform we recommend follows from the programme’s constraints: sovereignty, certification level, existing estate, cost of operation. We stay accountable for the result in production whichever product is chosen. The choice follows the requirement, never the other way round.
Standards we build to
The standards that make evidence hold up.
- eIDAS (UE) n° 910/2014
- ETSI EN 319 411-1 / 411-2
- ETSI EN 319 421 / 319 422
- ETSI EN 319 142 (PAdES)
- X.509 · RFC 5280
- Common Criteria (HSM)
Let’s talk about your programme before we talk about product.
Tell us the regulatory framework and the scale you’re aiming at. We’ll tell you what actually needs building, including if it turns out to be less than you thought.


























