simpl.
Cybersecurity GRC 14 items

PKI & Certificate Lifecycle Management

Assesses public key infrastructure and certificate lifecycle governance covering CA security, issuance, inventory, renewal automation, and revocation.

NIST 800-57CA/Browser ForumNIST 800-53

Free PDF · enter your email to download.

CA Governance & Security

  • Is the offline root CA kept air-gapped and physically secured? *
  • Are CA private keys protected in an HSM meeting FIPS 140-2/3 Level 3? *
  • Is a Certificate Policy (CP) and Certification Practice Statement (CPS) documented and maintained? *
  • Are CA administrator roles separated with dual control for sensitive operations? *

Issuance & Policy

  • Are certificate templates restricted to approved key usages and validity periods? *
  • Do TLS certificates conform to CA/Browser Forum baseline requirements (max validity, key size)? *
  • Is domain/identity validation enforced before certificate issuance? *
  • Are weak algorithms (SHA-1, RSA <2048, deprecated curves) prohibited? *

Inventory & Renewal

  • Is a complete inventory of issued certificates maintained with owners and expiry dates? *
  • Are expiry alerts and automated renewal (e.g., ACME) used to prevent outages? *
  • Are private keys generated and stored securely, never shared across systems? *

Revocation & Monitoring

  • Are CRL and/or OCSP services available and monitored for freshness? *
  • Is there a documented, tested process to revoke compromised certificates promptly? *
  • Is Certificate Transparency monitored to detect mis-issued certificates for owned domains?

Download the full PKI & Certificate Lifecycle Management checklist

Get it as a clean, printable PDF — free.