Skip to main content
NG Technologies

Public key infrastructure

A PKI is not a software project

It is a long-term commitment to key custody, continuity and the value of the evidence, carrying obligations that will outlast you. What you decide at scoping, you operate for a decade. That holds for a state’s root authority just as much as for a large group’s internal PKI or a CIO’s TLS estate.

Most of your estate isn’t where you’re looking

Control of the keys, traceability, continuity: the requirements don’t change from one scale to the next. What changes is what you lose when they give way.

  • States, regulators, certification authorities

    National and sovereign PKI

    A root authority operated in your name, on your territory, carrying the evidentiary weight the law grants it, not the weight a foreign vendor is willing to concede.

    • Offline root authority and a hierarchy of intermediate authorities
    • Certificate policy and certification practice statement
    • Digital identity for citizens and public officials
    • Digital public procurement and electronic invoicing
    • Skills transfer to national teams
    Learn more →
  • Banks, insurers, telecoms, energy, healthcare, industry

    Enterprise PKI

    An internal authority for your people, your applications and your devices. Your internal uses stop depending on a public authority’s calendar.

    • An internal authority for the uses that need not be public
    • Employee certificates, smart cards and strong authentication
    • Signing and sealing of business and document flows
    • Device, IoT and industrial certificates
    • A clean separation between internal and public trust
    Learn more →
  • CIOs, CISOs, platform and operations teams

    SSL/TLS and machine identity PKI

    The largest estate, the least inventoried, and the leading cause of avoidable outages. It gives no warning before it goes down.

    • Discovery and inventory of the existing certificate estate
    • A private authority for internal TLS, public for what is exposed
    • Automated renewal (ACME) and CI/CD integration
    • Expiry monitoring and alerting before an incident
    • Workload identity: containers, services, APIs
    Learn more →

Four steps, and nothing unplanned between them

  1. 01

    Scoping

    Policy and architecture

    The document that governs everything else: certificate policy, practice statement, authority hierarchy. We write it before anything is bought.

  2. 02

    Foundation

    Infrastructure and HSM

    Offline root, intermediate authorities and hardware security modules, on your territory or in your own data centres.

  3. 03

    Ceremony

    Key generation

    Conducted, recorded and documented, before the secret holders and appointed witnesses. This is the record your auditor will ask for.

  4. 04

    Operations

    Issuance and oversight

    Enrolment, issuance, revocation, CRL and OCSP, monitoring, then the handover of skills to your teams.

The expensive mistake is building the wrong PKI

A certification authority is operated for a decade. What you settle at scoping (hierarchy, certification level, platform) you carry for all of it. We come in before that, and we train the people who will hold the infrastructure afterwards.

Advisory

We work the decision before it costs anything: what the regulatory framework requires of you, what your existing estate already imposes, and what your teams will still be able to operate in five years.

  • Scoping study and authority architecture
  • Certificate policy and certification practice statement
  • Platform and HSM selection, with no vendor tie
  • Inventory and audit of the existing certificate estate
  • Preparation for homologation and compliance audit

Training

A PKI your teams cannot operate is a PKI you are renting from someone. We train the people who will hold it, through to full handover.

  • PKI and electronic signature fundamentals
  • Day-to-day operation of a certification authority
  • Key ceremony: roles, secret holders, written record
  • Separate sessions for technical teams and for decision-makers
  • Skills transfer at the end of a programme

The facts, and where to check them

National programmes

  • Tunisia

    NGSIGN homologated by the National Electronic Certification Agency (ANCE) and certified as an eIDAS Qualified Trust Service Provider.

  • Chad

    PKI and electronic signature training and awareness workshop, run with ANSICE.

  • Mauritania

    Awareness and training workshop on PKI and electronic trust services.

  • Benin

    Deployment of the NGSIGN electronic signature platform at the Port Autonome de Cotonou (PAC).

  • Togo

    Hosted a Togolese delegation on a study mission covering the digitalisation of public procurement.

  • Burkina Faso

    NG Technologies’ first partnership convention in sub-Saharan Africa.

  • Libya

    Strategic partnership with Ebkar to bring digital trust services and PKI to the Libyan market, in line with Law No. 6 of 2022.

Large organisations

Banks, insurers, operators and public bodies run our products in production. These are the organisations whose certificate volumes and continuity requirements justify a dedicated infrastructure.

  • Banking
  • Insurance and reinsurance
  • Telecoms
  • Energy and hydrocarbons
  • Public health
  • Government and agencies
  • Ports and logistics
  • Registries and public procurement
  • Fintech
  • ATB, Arab Tunisian Bank
  • ANSICE, Tchad
  • Ministère de la Transition Numérique et de la Modernisation de l’Administration
  • Port Autonome de Cotonou
  • ASIN (Agence des Systèmes d’Information et du Numérique), Bénin
  • Obour, Electronic Payment Solutions
  • STAR Assurances
  • TUNEPS
  • STIR
  • Tunis Re
  • Ministère de l’Économie Numérique et de la Communication, Bénin
  • TunTrust
  • RNE, Registre National des Entreprises
  • OMV
  • ANSUT
  • Dataxion
  • ETAP
  • HAICOP
  • CNAM
  • CIMF, Centre Informatique du Ministère des Finances
  • CCT, Compagnie des Comptables de Tunisie
  • Carte Assurances
  • Maghrebia
  • Orange
  • Agil, SNDP
  • UBCI, Groupe BNP Paribas
  • UIB

No vendor agreement steers our recommendation

We are tied to no vendor. The platform we recommend follows from the programme’s constraints: sovereignty, certification level, existing estate, cost of operation. We stay accountable for the result in production whichever product is chosen. The choice follows the requirement, never the other way round.

Standards we build to

The standards that make evidence hold up.

  • eIDAS (UE) n° 910/2014
  • ETSI EN 319 411-1 / 411-2
  • ETSI EN 319 421 / 319 422
  • ETSI EN 319 142 (PAdES)
  • X.509 · RFC 5280
  • Common Criteria (HSM)

Let’s talk about your programme before we talk about product.

Tell us the regulatory framework and the scale you’re aiming at. We’ll tell you what actually needs building, including if it turns out to be less than you thought.