PKI · DIGITAL TRUST PRODUCT / SOLUTION PROFILE

Trusted PQC PKI
Controlled pilot

Design and pilot classical, hybrid and target-state certificate services across Root CA, Issuing CA, RA and validation.

CUSTOMER PROBLEM

Design and pilot classical, hybrid and target-state certificate services across Root CA, Issuing CA, RA and validation.

CA ecosystems must migrate policies, profiles, HSMs, enrollment, revocation and relying parties together; changing only the signature algorithm is insufficient.

Controlled pilot
Portfolio class
Digital trust product / solution profile
Public profile
2026.07
Version rule
Confirmed in quotation / release record

PRODUCT-SPECIFIC IMPLEMENTATION FLOW

How Trusted PQC PKI operates from input to evidence.

CA/RA, HSM, enrollment, OCSP/CRL, relying parties and project governance. CP/CPS impact record, certificate samples, issuance/path-validation tests and cutover plan.

01

Define trust model and transition target

Root and issuing CA target architecture

02

Approve CP/CPS and certificate profiles

Classical, hybrid and target-state certificate profiles

03

Enroll subject through RA controls

RA/enrollment and approval workflow

04

Issue inside protected CA boundary

OCSP/CRL and path-validation profile

05

Publish status through OCSP/CRL

CP/CPS and OID impact analysis

06

Validate coexistence and cutover

Cutover, coexistence and rollback plan

NAMED COMPONENTS AND RESPONSIBILITIES

What Trusted PQC PKI contains and what each component does.

The descriptions below state concrete technical behaviour rather than generic support language.

01

Root and issuing CA target architecture

Designs offline Root CA, online Issuing CA, subordinate and recovery roles with separate algorithm profiles, key ceremonies and assurance objectives.

02

Classical, hybrid and target-state certificate profiles

Defines classical, hybrid and target-state X.509 profiles, OIDs, extensions, key usages, policy identifiers and relying-party interpretation.

03

RA/enrollment and approval workflow

Preserves identity proofing, approval, issuance, renewal and revocation controls while introducing new key and certificate types.

04

OCSP/CRL and path-validation profile

Updates OCSP, CRL, path building and validation policy so status and chain processing remain deterministic during coexistence.

05

CP/CPS and OID impact analysis

Records every CP/CPS, profile, OID, HSM, enrollment and relying-party impact before issuing a production certificate.

06

Cutover, coexistence and rollback plan

Provides phased cutover, dual-chain or dual-certificate patterns, rollback triggers and retirement evidence for the legacy hierarchy.

CUSTOMER OUTCOMES
  • Algorithm and certificate policy
  • Profile and OID strategy
  • Controlled issuance and path validation
INTEGRATION BOUNDARY

CA/RA, HSM, enrollment, OCSP/CRL, relying parties and project governance.

DEPLOYMENT PATTERNS

On-premises trust service

CA, signing, TSA or release components run in a customer-controlled trust boundary with protected keys.

Dedicated private platform

Service components run in a dedicated private-cloud or appliance topology with HSM/QSCD integration.

Coexistence migration

Classical and target profiles are introduced in phases with relying-party testing, evidence and rollback gates.

EVIDENCE REQUIRED
  • CP/CPS impact record, certificate samples, issuance/path-validation tests and cutover plan.
  • Version and configuration manifest for: CA/RA, HSM, enrollment, OCSP/CRL, relying parties and project governance.
  • Negative, failure and recovery tests for “Publish status through OCSP/CRL” and “Validate coexistence and cutover”.
  • Signed acceptance record, accountable owner, published limitations and next review date.
STANDARDS & PROFILES
  • X.509 / PKIX
  • OCSP / CRL
  • CA/B or sector profiles where applicable
  • FIPS 203 / 204 / 205 profiles when approved

PRODUCT-SPECIFIC BOUNDARIES

Conditions that must remain true for Trusted PQC PKI.

These points come from the product profile, not from a shared disclaimer.

NEXT STEP

Define a controlled pilot: Trusted PQC PKI

Select one application, exact versions, measurable acceptance criteria and rollback.