Startup Diligence
Diligence report Cybersecurity Growth equity / private 2026-07-10

Keyfactor

Trust Infrastructure Platform — Strong Strategic Momentum, Wide Valuation Band

Keyfactor appears to be a strong private trust-infrastructure asset with real enterprise and government proof, repeated sponsor validation, and broad product relevance—but public evidence still leaves enough ARR, retention, margin, concentration, and structure gaps that the right call is research-more with strict price discipline rather than an unconditional buy.

Cover facts

2026 Growth Investment 01
$1B+ (Jul 2026) [CO015]
2023 EV Anchor 02
~$1.3B [CO011]
Customers 03
2,500+ [CO020]
Employees 04
540+ [CO030]
FedRAMP 05
Moderate Authorized [CO017]
Founded 06
2001 [CO001]

Company profile

Keyfactor is a Cleveland-based cybersecurity company that helps enterprises and government agencies manage machine identities, cryptographic assets, certificate lifecycles, private PKI, and digital signing workflows. Its portfolio combines Keyfactor Command for lifecycle automation and governance, EJBCA Enterprise for private PKI and certificate authority operations, SignServer Enterprise for software and document signing, and managed cloud PKI and government delivery options. Public customer proof includes ServiceNow, Siemens, OVHcloud, SK ID Solutions, GRENKE, M&T Bank, Schneider Electric, and the Netherlands Ministry of Justice and Security. The company positions this portfolio as a unified Trust Control Plane for the AI and quantum era, and public evidence shows repeated sponsor support from Insight Partners, Sixth Street, and Summit Partners.

Website
www.keyfactor.com
Founded
2001-01-01
Founders
Kevin von Keyserling
Founding location
Cleveland, Ohio, USA
Headquarters
Cleveland, Ohio, USA
Product
Keyfactor delivers a layered trust-infrastructure stack: Command for certificate lifecycle automation and machine-identity governance; EJBCA Enterprise for private PKI and certificate authority workflows; SignServer Enterprise for code, firmware, container, document, and other signing use cases; and cloud-delivered PKI plus government-focused certificate lifecycle automation for customers that want managed delivery. The company increasingly frames these capabilities as one Trust Control Plane spanning cryptographic discovery, issuance, governance, signing, and post-quantum readiness.
Customers
Large enterprises, regulated industries, financial services, software and cloud platforms, industrial and device-security organizations, digital-identity providers, and government agencies; served through enterprise direct sales, partner ecosystems, and managed-delivery motions.
Business model
Enterprise software and managed-service model spanning certificate lifecycle management, private PKI, digital signing, and managed cloud deployment; likely sold through multi-year contracts with quote-led pricing, support, and possible services or implementation layers.
Stage
Private growth-stage / sponsor-backed
Funding status
$77M Insight growth round in January 2019; significant minority investment from Sixth Street in October 2023 at approximately $1.3B enterprise value; $1B+ Summit-led strategic growth investment in July 2026 with Insight and Sixth Street retaining significant ownership.
[CO001, CO011, CO015, CO024, CO028, CO030]

Executive summary

Top strengths

  • Strong category urgency: machine identity sprawl, shorter certificate lifetimes, post-quantum migration, and regulatory pressure all support structural demand for trust infrastructure
  • Reference-grade customer proof across software, industrial, financial-services, infrastructure, digital-identity, and government segments supports real production adoption rather than logo-only marketing
  • Broad product stack spanning CLM, private PKI, signing, cloud delivery, and Trust Control Plane positioning gives Keyfactor a wider platform story than a narrow certificate tool
  • Repeat sponsor validation from Insight, Sixth Street, and Summit supports strategic quality and financing access
  • FedRAMP Moderate authorization and regulated-customer proof strengthen public-sector and high-assurance credibility
  • Open-source roots in EJBCA and SignServer strengthen practitioner credibility and ecosystem depth

Top risks

  • Public evidence does not disclose ARR, NRR, gross margin, concentration, or 2026 round structure, limiting precision on valuation and downside underwriting
  • Trust contradiction risk is real: a serious security, reliability, or compliance failure would directly undermine the company’s core value proposition
  • Bundle pressure from larger security and identity platforms could compress renewal quality, pricing power, or eventual exit appetite
  • Regulated-segment growth depends on maintaining certifications, support quality, and procurement credibility in government and banking
  • Implementation, upgrade, and HSM or hybrid-environment complexity can drive services intensity and operational burden
  • Public customer proof is strong but skewed toward large reference accounts, leaving concentration risk unresolved

Open gaps

  • Current ARR, revenue mix, gross margin, and cash flow are not publicly disclosed
  • Net retention, churn, contract duration, and top-customer concentration remain private
  • Primary versus secondary mix, preference stack, and dilution terms for the 2026 transaction are not public
  • Recent win-loss data versus bundled competitors is not public
  • Independent uptime, implementation-effort, and support-SLA data are not publicly available
  • The exact economics of managed services versus software subscription revenue remain unclear

Contents

Chapter 01

01Company Overview

1.1 Identity, Footprint, and Operating Focus

Keyfactor’s canonical corporate history is unusually important because the company’s present positioning sits on top of a long PKI operating history rather than a newly formed AI-security startup narrative. The business was founded in 2001 as Certified Security Solutions (CSS), then rebranded as Keyfactor in November 2018 as management shifted the story from consulting roots toward a software-led digital identity platform. By 2026 the company describes itself as the leader in trust infrastructure for AI and machines and frames its core problem as enterprise control over machine identities, certificates, cryptographic assets, and post-quantum transition planning. Product pages show that the operating center of gravity is a portfolio rather than a single point tool: Keyfactor Command for certificate lifecycle automation, EJBCA Enterprise for PKI, SignServer Enterprise for signing workflows, and cloud-delivered PKI and government-specific offerings. Scale claims also matter because they anchor later market, customer, and valuation analysis. The July 2026 Summit transaction announcement says Keyfactor manages billions of machine identities each year for more than 2,500 customers worldwide and serves over 40% of the Fortune 100, 50% of the largest banks in the U.S. and Europe, and 80% of leading U.S. retailers. The January 2026 Michael Volanoski appointment adds a separate operating-footprint datapoint: 540+ employees across 12 countries. [CO001, CO002, CO003, CO007, CO008, CO018]

Snapshot KPI Table (publicly disclosed metrics as of runDate)
MetricValue / StatusWhen statedConfidenceSource / caveat
Founded20012018-2019 disclosureshighRebrand and Insight funding releases
Current brandKeyfactor (formerly CSS)2018highRebrand announcement
Employees540+2026-01mediumVolanoski appointment release
Countries with staff122026-01mediumVolanoski appointment release
Customers>2,500 worldwide2026-07mediumSummit-led investment announcement
Fortune 100 penetration>40%2026-07mediumCompany-claimed in 2026 investment materials
Largest U.S./Europe banks served50%2026-07mediumCompany-claimed in 2026 investment materials
Leading U.S. retailers served80%2026-07mediumCompany-claimed in 2026 investment materials
2019 growth round$77M2019-01-22highInsight investment release
2023 enterprise value~$1.3B2023-10-24highSixth Street investment release
2026 strategic growth capital$1B+2026-07-06highSummit-led transaction release
FedRAMP statusModerate authorization for Government CLAaaS2026-05-19highOfficial authorization release
Absolute ARR / revenueNot publicly disclosedCurrent gaplowManagement disclosed growth and profitability signals but not denominators

Public KPI strip mixes verified transaction facts with company-claimed operating scale. Absolute ARR, revenue, cash, and debt remain undisclosed.

[CO001, CO002, CO008, CO009, CO011, CO015]
FO002: Company snapshot logic

Keyfactor’s trust-infrastructure thesis links legacy PKI assets and product modules to regulated buyers, automation outcomes, and new growth capital.

[CO002, CO015, CO024, CO027, CO028, CO029]
FO003: Snapshot KPIs

Publicly disclosed KPIs emphasize customers, enterprise penetration, employee footprint, and financing milestones, while absolute revenue remains undisclosed.

[CO008, CO015, CO020, CO023]

1.2 Leadership Bench and Governance Evolution

Public governance visibility is partial rather than complete, but the available record is enough to establish who currently drives strategy and where disclosure remains thin. Jordan Rackie is the current CEO in the 2023 and 2026 financing announcements, while Ted Shorter appears as CTO in federal and platform-launch announcements and remains the most visible technical spokesperson on trust infrastructure, certificate automation, and post-quantum migration. In January 2026 Keyfactor added a major go-to-market executive, appointing Michael Volanoski as President and Chief Revenue Officer to run sales, marketing, and channel functions. That release matters for more than biography: management used it to say the company had nearly doubled ARR in less than two years and expanded to 540+ employees across 12 countries, implying a scaling inflection that likely required a broader executive layer. Board evolution can also be inferred from financing events. Sixth Street’s 2023 minority investment brought Bo Stanley and Alex Katz onto the board, while the July 2026 Summit-led transaction added managing directors Andy Collins and Colin Mistele. What remains undisclosed is equally relevant: the company does not publicly publish a full current board roster, ownership percentages, protective provisions, or any formal statement on secondaries or debt covenants. That limits outside assessment of control dynamics even though the public record clearly shows investor influence rising with each growth transaction. [CO003, CO004, CO005, CO006, CO007, CO008]

Leadership and founder table
PersonRole / relevancePublic evidenceGovernance significance
Jordan RackieChief Executive OfficerQuoted in 2023 and 2026 financing announcementsPrimary public operator and financing spokesperson
Ted ShorterChief Technology OfficerQuoted in FedRAMP and Trust Control Plane announcementsCore technical voice on federal, PKI, and PQC strategy
Michael VolanoskiPresident & Chief Revenue OfficerAppointed January 2026Signals scaled global GTM operating model
Bo StanleySixth Street board representativeJoined board with 2023 investmentRepresents minority growth capital governance
Alex KatzSixth Street board representativeJoined board with 2023 investmentAdds investor oversight and capital-markets perspective
Andy Collins & Colin MisteleSummit Partners directorsJoin board after July 2026 transactionBoard influence increases with latest growth capital

Public sources identify major executives and investor-appointed directors, but do not disclose the full live board roster, committee structure, or ownership percentages.

[CO003, CO004, CO005, CO014, CO017, CO040]

1.3 Funding History, Capital Formation, and Traction Signals

Keyfactor’s financing history shows a company that moved from software growth equity to large-cap strategic capital while keeping existing sponsors involved. In January 2019 the company closed a $77 million growth round from Insight Venture Partners shortly after its rebrand, and management used that announcement to say Keyfactor had doubled revenue year over year and was securing more than 500 million certificates for Global 2000 clients. In October 2023 Keyfactor announced a significant minority investment from Sixth Street Growth at an enterprise value of approximately $1.3 billion; management additionally claimed more than 1,500 organizations used its solutions and that three-year revenue CAGR exceeded 70%. The next and most important step arrived on July 6, 2026, when Summit Partners led a $1B+ strategic growth investment and existing investors Insight Partners and Sixth Street Growth retained significant ownership. The company described the business as scaling from a position of strong profitability and accelerating year-over-year revenue growth, but it still did not disclose absolute ARR, revenue, cash, debt, or transaction structure beyond the strategic growth framing. That omission is critical for later financial and valuation work: public capital milestones are clear, but underwriting still depends on management access for revenue quality, margin structure, and cap-table detail. [CO009, CO010, CO011, CO012, CO013, CO014]

Stakeholder or investor map
StakeholderRoleEconomic / control importancePublic signalDiligence ask
Insight Partners2019 lead growth investor; remains significant owner in 2026Longstanding sponsor with likely major governance rights$77M round in 2019; retained ownership in 2026Confirm ownership %, board seat, preferences, and any secondary liquidity
Sixth Street Growth2023 strategic minority investorCapital provider that priced company at ~$1.3B EV and joined boardBo Stanley and Alex Katz joined boardConfirm instrument type, liquidation preferences, and step-up rights
Summit Partners2026 strategic growth leadLatest large-capital sponsor and new board influence$1B+ transaction in July 2026Clarify primary vs secondary mix, use of proceeds, and any control provisions
U.S. federal agenciesRegulated end-market stakeholderFedRAMP authorization expands procurement relevanceGovernment CLAaaS got FedRAMP Moderate in May 2026Size current federal ARR and agency concentration
Large regulated enterprisesReference customers in banking, retail, telecom, healthcareProof of scale and renewal qualityCompany claims deep Fortune 100, bank, and retailer penetrationBreak out logo count from paying production accounts
Open-source EJBCA communityTechnology ecosystem stakeholderSupports adoption funnel and transparency narrativeEJBCA community site cites 23 years of history and active downloadsQuantify open-source to enterprise conversion and support attach rates

This is a hybrid investor/stakeholder map because public evidence is richer on sponsor chronology than on precise cap-table economics or customer concentration.

[CO009, CO011, CO014, CO015, CO016, CO017]

1.4 Portfolio Breadth and Reference-Quality Customer Evidence

The company overview chapter must establish enough product and customer ground truth to support later technical and commercial chapters without importing foreign claim IDs. Product evidence shows a layered architecture. Command is a CA-agnostic control plane for discovery, governance, and lifecycle automation across SSH, TLS, and client certificates. EJBCA Enterprise is the underlying scalable PKI platform with cloud, on-prem, self-managed, and as-a-service deployment options. SignServer Enterprise extends the portfolio into code, document, container, firmware, and ePassport signing with centralized HSM-backed key control. Cloud PKI as-a-Service and the government-focused CLAaaS offer managed deployment options for buyers that want faster time-to-value or lighter operational lift. Customer proof is also stronger than generic logo pages. Siemens reports an 85% reduction in PKI deployment time with automated EJBCA deployment. ServiceNow says EJBCA enabled dynamic certificate issuance across services and workloads while removing dozens of engineering hours of manual work. OVHcloud uses EJBCA to centralize PKI for a sovereign cloud footprint that supports 1.5+ million developers and 10K+ certificates. SK ID migrated 20 million certificates and reports zero PKI incidents since rollout, while the Netherlands Ministry of Justice and Security cites 15+ years of PKI operations on EJBCA. These are material proof points because they show regulated, infrastructure-heavy, and national-scale use cases rather than only pilot customers. [CO024, CO025, CO026, CO027, CO028, CO029]

1.5 Milestones, Federal Validation, and Adverse Context

The milestone record supports a view of Keyfactor as a maturing category leader, but it also surfaces the kinds of adverse evidence an investor cannot ignore. Positive milestones are substantial: the 2018 rebrand formalized the software pivot, the 2019 Insight round funded expansion, the 2023 Sixth Street investment pushed the company to a disclosed $1.3 billion enterprise value, May 2026 brought FedRAMP Moderate authorization for Government CLAaaS, June 2026 introduced the Trust Control Plane narrative, and July 2026 delivered a Summit-led $1B+ strategic growth investment. Yet the adverse record is not zero. Keyfactor’s support portal lists a May 2026 EJBCA MPIC compliance issue and multiple 2025 SignServer advisories, while OpenCVE aggregates security findings that include historical Keyfactor Command SQL injection and access-control issues as well as several SignServer vulnerabilities. None of these sources indicate a catastrophic public breach, but they do show that Keyfactor operates in a product category where trust claims are continuously tested by implementation defects, compliance edge cases, and patch-management discipline. The right framing is therefore not “no risk,” but rather “enterprise platform with real proof and real attack surface,” which is exactly the balance later risk and valuation chapters need to preserve. [CO015, CO017, CO024, CO025, CO038, CO039]

Milestone table
DateEventTypeAmount / statusParticipantsImplication
2001Company founded as Certified Security SolutionsfoundingEstablishedFounders not fully disclosed in current public materialsShows long PKI operating history
2018-11-01CSS rebrands as KeyfactorgovernanceBrand and software-platform pivotKevin von Keyserling and Keyfactor managementResets narrative around digital identity software
2019-01-22Insight-led growth roundfinancing$77MKeyfactor, Insight Venture PartnersFunds expansion after rebrand
2023-10-24Sixth Street minority investmentfinancing~$1.3B enterprise valueKeyfactor, Sixth Street, InsightEstablishes unicorn-scale valuation benchmark
2025-11-18ABI Research ranks Keyfactor first in enterprise PKIscaleMarket leader designationABI ResearchIndependent validation of category position
2026-01-05Michael Volanoski appointed President & CROgovernanceExecutive expansionKeyfactorSignals scaled GTM motion
2026-02SignServer 7.6 adds PQ features and fixes multiple security issuesadversePatch releaseKeyfactor SignServer teamShows active product hardening and non-zero attack surface
2026-05-16 to 2026-05-19EJBCA MPIC compliance issue disclosed; Government CLAaaS earns FedRAMP ModerateregulatoryMixed adverse and positive trust signalsKeyfactor support and product teamsTrust claims strengthened by authorization but tested by compliance edge cases
2026-06-09Trust Control Plane launchedproductNew platform operating modelKeyfactorUnifies discovery, orchestration, and governance narrative
2026-07-06Summit Partners leads strategic growth investmentfinancing$1B+Summit, Insight, Sixth Street, KeyfactorPositions company for acquisitions and global expansion

Milestone chronology intentionally combines positive and adverse trust events because both matter for later risk and valuation work.

[CO001, CO002, CO009, CO011, CO015, CO017]
FO001: Keyfactor milestone timeline

Keyfactor’s public chronology runs from a 2001 founding through the 2018 rebrand, 2019 and 2023 financing steps, and a 2026 sequence of FedRAMP, Trust Control Plane, and Summit-led growth capital milestones.

[CO001, CO002, CO009, CO011, CO015, CO024]

1.6 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary and What Counts as the Addressable Problem

Keyfactor’s market should not be defined so narrowly that it ignores adjacent spend, nor so broadly that it collapses into generic cybersecurity or identity software. The core budget line is certificate lifecycle management (CLM): software that automates issuance, renewal, monitoring, and governance for TLS, code-signing, email, and client certificates across enterprise infrastructure. The Business Research Company’s 2026 market framing is useful because it explicitly includes deployment models, organization sizes, and regulated verticals where Keyfactor is strongest, while excluding unrelated human-identity workflows. That core CLM layer sits inside a broader enterprise PKI and machine identity management problem. AppViewX’s educational material and CyberArk’s machine identity messaging both describe the same underlying challenge: machines, workloads, containers, APIs, applications, and IoT devices all authenticate with certificates, keys, secrets, or related cryptographic identities that must be discovered, governed, and renewed. Keyfactor’s own messaging pushes even further into “trust infrastructure,” adding crypto-agility, cryptographic discovery, and post-quantum readiness. The right boundary, therefore, is a layered one: core CLM spend today, broader machine identity control-plane spend around it, and PQC migration budget as the fastest-growing adjacency rather than the present-day revenue core. [CM001, CM002, CM003, CM010, CM022, CM023]

Market definition table
SegmentIncluded spendExcluded spendTypical buyer / payerWhy it matters for Keyfactor
Core CLM softwareCertificate discovery, issuance, renewal, monitoring, policy orchestration, reportingHuman IAM, endpoint AV, generic SIEMCISO, PKI ops, infrastructure securityDirect product-market fit for Keyfactor Command
Enterprise PKIPrivate CA software, HSM-linked issuance, internal trust services, device/workload identityPublic-web CA revenue without enterprise management softwarePKI architects, platform engineering, security architectureDirect fit for EJBCA and managed PKI offerings
Machine identity managementCertificates, keys, secrets, workload identities, SSH and device trust controlsPure workforce identity and HR-backed IAM flowsIdentity security, platform security, DevOps, zero-trust ownersExpands Keyfactor beyond classic PKI admin tooling
PQC readiness / crypto-agilityCryptographic discovery, migration planning, hybrid certificates, algorithm governanceGeneral AI security not tied to cryptographySecurity leadership, regulators, federal contractorsFastest-growing adjacency shaping new budget urgency

Boundary logic intentionally separates today’s revenue core from adjacent spend buckets that influence future demand but are not fully interchangeable with CLM revenue.

[CM001, CM002, CM010, CM024, CM025, CM034]
FM001: Market sizing lens

Keyfactor’s addressable opportunity is best viewed as nested layers: CLM core spend today, broader machine identity governance around it, and PQC readiness as the fastest-growing adjacency.

[CM004, CM007, CM024, CM025]

2.2 Sizing Lenses: Core CLM Today, PQC and Machine Identity as Adjacencies

The most defensible published sizing lens for Keyfactor’s near-term category is the CLM software market, not the entire cybersecurity stack. The Business Research Company estimates the category at $6.19 billion in 2026, up from $5.23 billion in 2025, and projects growth to $11.05 billion by 2030. That framing is broad enough to include the certificate types and verticals Keyfactor targets, but still narrower than the full machine identity problem. A second, adjacent lens is post-quantum cryptography. MarketsandMarkets projects the PQC market from $0.42 billion in 2025 to $2.84 billion by 2030 at 46.2% CAGR; that spend is not yet interchangeable with CLM revenue, but it directly influences Keyfactor’s category narrative because migration projects begin with certificate inventories, cryptographic discovery, and governance. A third lens is operational urgency rather than revenue size. CyberArk’s 2025 Identity Security Landscape says machine identities outnumber humans by 82 to 1, 42% have sensitive or privileged access, and 87% of surveyed organizations experienced at least two successful identity-centric breaches in the prior year. Those numbers do not define TAM on their own, but they explain why CLM, PKI, and machine identity tooling have moved from niche PKI admin pain into board-level resilience and compliance budgets. [CM004, CM005, CM006, CM007, CM008, CM009]

TAM / SAM / sizing lens table
LensPublisher / sourceYearValueMethod / unitConfidenceLimitation
Certificate lifecycle management software marketThe Business Research Company2026$6.19BGlobal market revenuemediumBroad category; includes vendors with different product mixes
Certificate lifecycle management software marketThe Business Research Company2030$11.05BGlobal market revenue forecastmediumForecast rather than current spend
PQC marketMarketsandMarkets2025$0.42BGlobal market revenuemediumAdjacency, not CLM core
PQC marketMarketsandMarkets2030$2.84BGlobal market revenue forecastmediumForecast assumes rapid standard and policy adoption
Machine identities per humanCyberArk202582:1Survey ratiomediumOperational intensity proxy, not direct market value
Organizations with at least two identity-centric breachesCyberArk202587%Survey sharemediumSurvey-based pain indicator, not buyer conversion

The table preserves multiple lenses instead of forcing a false single TAM. Keyfactor’s commercial opportunity spans CLM core spend plus machine identity and PQC adjacency.

[CM004, CM005, CM007, CM013, CM016]
FM002: Market estimate range

Low-to-high ranges capture the most important market quantities without forcing incompatible definitions into a single TAM number.

Units stay consistent within each row. Some rows compare current and forecast endpoints because public sources frame the category that way.

[CM004, CM005, CM007, CM013, CM028]

2.3 Who Buys, Who Uses, and How Adoption Typically Starts

The buyer journey for this market is cross-functional even when budget authority ultimately sits with security leadership. Certificate, PKI, and machine identity platforms are usually championed by PKI architects, certificate operations teams, security engineering, or platform engineering groups that feel the operational pain directly. Budget approval typically routes through the CISO organization, infrastructure leadership, or government/compliance owners in regulated environments. Product pages from DigiCert, Sectigo, CyberArk, and Keyfactor all point to the same multi-stakeholder adoption path: first discover and inventory what exists, then centralize policy and visibility, then automate issuance and renewal, and finally extend governance into cloud workloads, developer tooling, device identity, and post-quantum preparation. Vertical demand also clusters in predictable places. TBRC explicitly lists finance, healthcare, government, IT/telecom, and manufacturing as major CLM industries. Keyfactor’s own customer proof maps cleanly onto those segments, and CyberArk’s 2025 survey suggests AI, cloud, and workload growth are pushing security teams to revisit machine identities even outside classical PKI-heavy sectors. The market therefore behaves less like discretionary tooling and more like infrastructure modernization with compliance, outage prevention, and cryptographic agility attached. [CM003, CM015, CM017, CM020, CM021, CM022]

Segment / buyer map
SegmentPrimary buyerPrimary userPayer / budget ownerAdoption triggerTypical workflow
Large regulated enterpriseCISO / security architecturePKI operations, platform engineeringSecurity and infrastructure budgetOutage avoidance, audit pressure, CA sprawlDiscover → centralize policy → automate renewals
Federal and public sectorProgram owner / cyber leadershipPKI admins, compliance teamsAgency modernization and compliance budgetFedRAMP, zero trust, PQC mandateCompliance-led deployment with long procurement cycles
Cloud / SaaS platform operatorPlatform security leaderSRE, DevOps, service ownersPlatform engineering plus securityCertificate volume growth and workload automationAPI-first issuance, rotation, alerting
Manufacturing / IoTProduct security / device identity ownerEmbedded security, manufacturing opsProduct security and engineeringDevice authentication and lifecycle trustPrivate PKI plus firmware / device signing
Financial servicesCISO / infrastructure securityPKI team, app security, IAMSecurity, compliance, resilience budgetCrypto-agility, certificate scale, long-lived sensitive dataHybrid PKI modernization and governance
Developer-heavy software organizationSecurity engineeringDevelopers, release engineeringSecurity tools and platform budgetCode signing, secrets, CI/CD trustSelf-service issuance with policy guardrails

Budget authority is often shared, but security leadership usually becomes the payer once outages, compliance, or cryptographic change reach materiality.

[CM003, CM020, CM022, CM023, CM029, CM030]
FM003: Buyer / segment map

The market is bought by security leaders but used by PKI, platform, DevOps, and compliance teams across regulated enterprise, government, and cloud-native segments.

[CM014, CM017, CM029, CM031]
FM004: Adoption funnel

Most buyers move from visibility problems to automation and finally into governance and PQC readiness rather than buying all functionality at once.

[CM022, CM023, CM030, CM031]

2.4 Growth Drivers, Constraints, and the Most Important Market Gaps

Four demand accelerants stand out across vendor, analyst, and policy sources. First, certificate lifetime compression is now a hard timetable, not an abstract possibility: DigiCert, Sectigo, and GlobalSign all describe the CA/Browser Forum schedule that cuts maximum TLS validity to 200 days in 2026, 100 days in 2027, and 47 days in 2029. Second, machine identity sprawl is accelerating with AI, cloud, containers, and APIs. Third, PQC has shifted from thought leadership to procurement planning after the White House’s June 2026 executive order, which Federal News Network says sets 2030 and 2031 federal transition deadlines and extends pressure into contractors and critical infrastructure. Fourth, regulatory and audit expectations increasingly require continuous visibility rather than periodic spreadsheet-based inventory. The constraints are equally important. The 2024 Keyfactor PKI report says 80% of respondents are concerned about adapting to cryptographic change, 84% cite growing certificate volumes as operational headaches, and 36% still planned to delay quantum-readiness work until after standards releases. AppViewX’s market education still describes spreadsheets, email-based renewals, and weak storage practices as live status-quo substitutes, which implies that buyer education, talent scarcity, and migration complexity remain meaningful adoption brakes. The unresolved gap is the missing SAM/SOM consensus: public sources size the category, but they do not isolate how much of that spend is realistically open to an independent vendor like Keyfactor versus bundled public CA, PAM, or platform security alternatives. [CM010, CM011, CM012, CM013, CM015, CM016]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationEvidence / diligence ask
TLS certificate validity shrinks to 200 days in 2026 and 47 days by 2029DriverImmediate through 2029Makes manual renewal operationally untenableDigiCert, Sectigo, and GlobalSign all describe the schedule
Machine identities outnumber humans 82:1DriverCurrentExpands certificate and secret inventory faster than legacy controlsCyberArk 2025 survey
PQC executive order deadlines for 2030/2031DriverCurrent policy cyclePulls demand into federal, contractor, and critical-infrastructure buyersFederal News Network and Palo Alto policy analysis
AI and cloud workloads multiply ephemeral identitiesDriverCurrentRaises discovery and automation valueCyberArk, AppViewX, Keyfactor materials
PKI talent scarcity and migration complexityConstraintCurrentSlows deployments and elongates services-heavy sales cyclesKeyfactor 2024 report and product materials
Status quo spreadsheets / email / siloed CAsConstraintCurrentShows why buyer education is still requiredAppViewX and Keyfactor managed PKI pages
Bundled competition from CA, PAM, and platform vendorsConstraintCurrentCan compress standalone CLM budgets or drive consolidationABI ranking plus CyberArk/Venafi and DigiCert/Sectigo offerings
SAM / SOM ambiguityConstraintPersistentMakes exact share capture hard to prove from public sourcesNeed management-level pipeline and segmentation data

The most important market dynamic is convergence: the same forces that increase category urgency also increase implementation complexity.

[CM010, CM011, CM012, CM013, CM018, CM019]

2.5 Exhibits

Chapter 03

03Competitors

3.1 Landscape: direct peers, incumbents, adjacencies, and substitutes

The buyer can solve Keyfactor’s job in at least five ways, which is why a narrow “Venafi versus Keyfactor” frame is insufficient. First are direct enterprise PKI and CLM peers: Entrust, DigiCert, Sectigo, AppViewX, and historically Venafi. Second are broader identity-security incumbents like CyberArk, which now owns Venafi and can bundle certificate and machine identity controls into a larger privileged-access narrative. Third are cloud-native and developer-led adjacencies such as HashiCorp Vault PKI and Smallstep, which excel in short-lived certificates, API workflows, and device or workload identity. Fourth are infrastructure-provider substitutes like AWS Private CA and Microsoft Active Directory Certificate Services, which can satisfy a meaningful portion of private CA and internal certificate needs without buying a full independent control plane. Fifth is the status quo itself: spreadsheets, siloed CA consoles, and manual certificate handling inside platform or infrastructure teams. ABI Research’s 2025 ranking is useful because it recognizes the field’s breadth: Keyfactor, Entrust, and DigiCert lead; Garantir, Sectigo, and AppViewX follow; and CyberArk, GlobalSign, Ascertia, eMudhra, and HID remain mainstream. That is not a winner-take-all market. It is a layered market where buyer context determines what “good enough” looks like. [CP001, CP002, CP003, CP004, CP005, CP006]

Competitor profile table
Competitor / substituteCategoryTarget segmentDifferentiationLimitation
KeyfactorDirect peerLarge enterprise, government, regulated hybrid environmentsIndependent CA-agnostic CLM + PKI + signing + PQC narrativePricing and deep financial disclosure are private
EntrustDirect peer / incumbentLarge regulated enterprisesBroad PKI platform and consultancy depthLess visible public product detail and likely heavier services model
DigiCertDirect peer / public-CA incumbentEnterprise and public-trust buyersGlobal trust brand plus Trust Lifecycle ManagerPotential bundling bias toward DigiCert ecosystem
SectigoDirect peer / public-CA incumbentEnterprise CLM buyers seeking CA-agnostic automationCloud-first CLM, 50+ integrations, public CA servicesVendor-authored comparison claims need triangulation
AppViewXDirect peer / CLM specialistSecurity teams focused on discovery and policy controlStrong machine identity education and CLM depthLess obvious breadth beyond CLM than Keyfactor bundle
CyberArk / VenafiIncumbent / bundleIdentity-security and machine-identity buyersBroader identity suite and large enterprise channelMay be more complex and bundle-driven for narrower PKI use cases
HashiCorp Vault PKIAdjacent / internal buildCloud-native platform teamsDynamic short-lived certs and deep API / protocol supportNot a full enterprise CLM governance suite by default
SmallstepAdjacent / specialistZero Trust, device identity, AI-workload programsHardware-backed, short-lived device and machine identityLess evidence of broad classic enterprise PKI governance
AWS Private CASubstituteAWS-centric teamsManaged private CA with AWS-native integrationNot an independent cross-estate trust control plane
Microsoft AD CSStatus quo / substituteWindows-heavy enterprisesBuilt-in PKI role and policy integrationOperational burden rises in heterogeneous or multi-CA estates
ManageEngine Key Manager PlusValue competitorCost-sensitive enterprise IT and security teamsFast deployment with certificate and SSH/PGP managementLower apparent strategic breadth than trust-infrastructure platforms

The profile table mixes direct rivals, bundled incumbents, and substitutes because buyers routinely compare them inside the same purchasing process.

[CP001, CP008, CP009, CP010, CP011, CP012]
FP001: Competitive positioning map

The field separates along two practical axes: breadth of trust-platform coverage and degree of bundled distribution power.

[CP001, CP008, CP010, CP011, CP012, CP015]

3.2 Direct peer profiles and strategic directions

The direct-peer set is differentiated more by operating model and channel than by the basic idea of certificate automation. ABI says Keyfactor wins on flexibility, CA agnosticism, PKI-IoT applications, and cryptographic discovery. Entrust is presented as the broadest platformized incumbent with deep integrations and consultancy. DigiCert brings public-trust PKI heritage, global scale, and a modern Trust Lifecycle Manager pitch built around discovery, governance, and automation across any CA or trust store. Sectigo emphasizes a CA-agnostic CLM layer, public CA services, 50+ integrations, and cloud-first deployment. AppViewX frames machine identity management as certificates and keys across devices, workloads, applications, and IoT, highlighting the operational risk of expired certificates and manual management. CyberArk’s machine identity security platform moves even further upstack by combining secrets, certificates, workload identities, and SSH keys, while the 2024 Venafi acquisition shows it can now sell those capabilities inside a larger identity-security suite. HashiCorp and Smallstep should not be ignored just because their starting points are more developer-centric. Vault’s PKI engine supports dynamic issuance, short TTLs, and standard issuance protocols, while Smallstep’s hardware-backed device identity and AI-agent messaging point to a strong fit with modern Zero Trust and cloud-native programs. [CP002, CP003, CP004, CP005, CP006, CP008]

Feature / capability matrix
Buying criterionKeyfactorCyberArk/VenafiDigiCertSectigoHashiCorp VaultMicrosoft AD CS
CA-agnostic certificate discoveryYesYesYesYesPartialNo
Enterprise private PKIYesYesYesYesYesYes
Code / document signingYesUnknownPartialUnknownNoNo
Short-lived cert automationYesYesYesYesYesPartial
Cloud-managed deployment optionYesYesYesYesSelf-managed patternsNo
Public-CA distribution advantageNoNoYesYesNoNo
Broader secrets / workload identity bundlePartialYesPartialPartialPartialNo
PQC / crypto-agility narrativeYesYesYesYesLimited public emphasisYes

Unsupported cells are marked Partial or Unknown rather than guessed. The matrix compares public evidence, not private roadmap claims.

[CP009, CP010, CP011, CP012, CP014, CP015]
FP002: Feature breadth / capability map

Relative breadth differs most on signing, secrets/workload identity, and deployment flexibility rather than basic certificate renewal.

[CP017, CP018, CP019, CP020, CP021, CP023]

3.3 Capability breadth, packaging opacity, and distribution power

Across the field, headline capability overlap is high, but packaging and distribution are not. Keyfactor combines CLM, enterprise PKI, code/document signing, and managed/cloud deployment options in one independent portfolio. DigiCert and Sectigo have the advantage of public-CA relationships, installed trust, and broader certificate procurement channels. CyberArk/Venafi can sell machine identity security inside broader identity programs and cross-sell through privileged-access relationships. HashiCorp, AWS, and Microsoft have strong embedded positions because platform teams may already standardize on Vault, AWS, or AD CS for adjacent reasons. Public pricing is generally opaque among enterprise vendors: Keyfactor, DigiCert, Sectigo, CyberArk/Venafi, Entrust, and Smallstep all drive buyers to demos, sales calls, or tailored proposals. That makes price competition hard to benchmark externally. The clearest substitute economics come from infrastructure-native options such as AWS Private CA, whose appeal is operational integration, and from lower-friction products like ManageEngine Key Manager Plus, which emphasizes rapid deployment, SaaS or on-prem availability, and bundled certificate plus SSH/PGP key management. The net result is that competition is often won through channel access, incumbent trust, deployment fit, and total-operating-model simplicity rather than a visible per-certificate list price. [CP009, CP010, CP011, CP014, CP015, CP016]

Pricing / packaging comparison
VendorPublic pricing visibilityContract / packaging signalIncluded capabilitiesImplication
KeyfactorLowDemo / contact salesCLM, PKI, signing, managed deploymentEnterprise packaging likely solution-led rather than per-cert retail
CyberArk / VenafiLowSuite-led enterprise salesMachine identity plus broader identity-security platformCross-sell power may outweigh product-level price transparency
DigiCertLowTiered TLM packagingDiscovery, governance, automation, support tiersPricing likely tied to complexity and assurance level
SectigoLowPlatform plus public CA servicesCLM, public/private certs, integrationsCan blend software and CA economics
HashiCorp VaultMediumSelf-managed platform economicsDynamic PKI plus broader secrets platformMay look cheaper on license but costlier in internal operating effort
AWS Private CAMediumUsage-oriented managed servicePrivate CA hierarchy inside AWSSubstitute is attractive where AWS footprint dominates
ManageEngineMediumSaaS or on-prem with bundled key managementCertificate plus SSH/PGP managementCompetes on time-to-value and operational simplicity

Public pages rarely provide apples-to-apples pricing. This table captures packaging posture and commercial implications rather than invented list prices.

[CP014, CP016, CP020, CP021, CP022, CP029]
FP003: Moat / readiness KPIs

Competitive durability depends on where Keyfactor is strong enough to hold value as automation becomes table stakes.

[CP021, CP024, CP025, CP027, CP028, CP032]

3.4 Switching costs, multi-homing, and moat durability

Keyfactor’s moat is real but conditional. It is strongest where buyers need an independent control plane that spans discovery, CA diversity, signing, private PKI, and crypto-agility without forcing them into a single public CA or broader identity suite. Reference customers like Siemens, ServiceNow, and OVHcloud support that story because they show Keyfactor winning in automation-heavy, regulated, and sovereignty-sensitive environments. Switching costs become meaningful after the platform is integrated into issuance workflows, alerting, HSMs, DevOps pipelines, and policy governance; at that point, replacing the control plane is not just a license decision but an operational migration. Even so, multi-homing remains possible at the certificate issuance layer because many buyers already use multiple CAs or trust sources. That is why the real strategic battle is shifting upward from issuance into discovery, governance, and post-quantum readiness. This also creates the main displacement risk. As certificate lifetimes shrink and baseline automation becomes mandatory, commoditization pressure falls hardest on simple renewal tooling. Vendors with broader bundles, stronger distribution, or embedded platform positions can compress the value of point CLM unless Keyfactor continues to differentiate on visibility, orchestration breadth, and trust-infrastructure governance. [CP024, CP025, CP026, CP027, CP028, CP031]

Moat durability / competitive risk register
Moat claimThreatSeverityWhy it mattersMitigation / diligence ask
Independent CA-agnostic control planeBundled suites from CyberArk/Venafi and DigiCert narrow standalone budgetshighPlatform vendors can amortize CLM inside broader identity or CA relationshipsTest win rates against bundled alternatives and verify attach rates
Breadth across CLM + PKI + signingCertificate automation commoditizes as shorter lifetimes force all vendors to automatehighSimple renewal workflows may stop differentiatingVerify discovery, signing, and PQC modules drive measurable expansion
Open-source and flexible deployment heritageCloud-native buyers choose Vault, Smallstep, or AWS-native substitutesmediumDeveloper-led teams may favor embedded tools over full enterprise suitesAssess cloud-native feature velocity and developer adoption
Government and regulated credibilityIncumbents add the same compliance messaging or public-sector channelsmediumRegulatory posture can be copied faster than deep product integrationTrack federal pipeline quality and certification maintenance costs
Reference-quality customersCompetitors also display large-logo proof and broader distributionmediumLogo counts alone do not secure future shareRequest cohort retention and expansion versus top rivals

The main threat is not one superior feature, but convergence: competitors are broadening into each other’s territory while buyers demand more automation by default.

[CP021, CP024, CP025, CP026, CP027, CP028]

3.5 Exhibits

Chapter 04

04Financials

4.1 Revenue model points to recurring software plus managed trust services

Keyfactor’s public product portfolio supports a recurring enterprise software revenue model with layered monetization rather than a one-product SKU story. Command is the operating layer for certificate lifecycle automation and machine identity governance. EJBCA Enterprise monetizes private PKI deployment and administration across self-managed, managed, and cloud delivery patterns. SignServer expands monetization into code, firmware, document, and container signing, while Cloud PKI as-a-Service and the government cloud certificate lifecycle automation offering add managed-service revenue on top of software. This matters because the business is unlikely to depend on one narrow certificate-renewal workflow; it is selling a broader control plane for trust infrastructure. Public pricing remains opaque, so the exact split between subscription, support, services, and managed operations is not visible. Even so, the product surface, the FedRAMP-authorized government option, and the TEI study’s cost-saving narrative all point to a platform sold through multi-year, high-touch enterprise contracts rather than self-serve seat pricing. The most defensible public conclusion is that revenue quality is likely recurring and enterprise-led, but the exact mix and realized pricing remain undisclosed. [CI001, CI002, CI003, CI004, CI005, CI006]

Revenue streams table
Revenue streamMechanismUnitCurrent statusQuality signalDiligence ask
CommandEnterprise software for certificate lifecycle and machine identity managementAnnual / multi-year contractActive core productLikely recurring software revenueRequest ARR contribution, renewal rate, and attach by module
EJBCA EnterprisePrivate PKI software delivered self-managed or as-a-servicePlatform contract / deploymentActive core productSupports recurring platform and support revenueRequest mix of self-managed versus managed deployment
SignServer EnterpriseCode, firmware, container, document, and ePassport signingModule or platform expansionActive productSupports expansion revenue beyond CLMRequest ACV and cross-sell penetration into installed base
Cloud PKI as-a-ServiceManaged cloud-delivered private PKISubscription / managed serviceActive productAdds recurring managed-service layerRequest gross margin and hosting / HSM cost profile
Government CLAaaS / FedRAMP offeringCompliance-heavy cloud certificate lifecycle automationContracted serviceActive in 2026Potentially sticky public-sector recurring revenueRequest federal pipeline size and certification maintenance costs

Public sources support the presence of multiple revenue streams, but not the exact revenue mix, contract length, or realized pricing by stream.

[CI001, CI002, CI003, CI004, CI005, CI026]
Pricing / monetization table
OfferPrice / unit / contractList versus realized pricingPublic evidenceImplication
Keyfactor platform productsQuote-led enterprise contractRealized pricing unknownContact-sales product pagesCommercial flexibility likely exists, but public benchmarking is weak
Managed cloud PKIContracted managed-service pricingRealized pricing unknownCloud PKI and government pagesService layer may improve stickiness but can affect gross margin
TEI value propositionROI and cost savingsNot company pricingCommissioned 2026 TEI resultsROI framing supports enterprise willingness to pay but not actual ASP
AWS Private CA substituteUsage-oriented public pricingPublic list pricing visibleAWS pricing pageTransparent substitute economics can frame buyer negotiations
Government offeringLikely tailored contract pricingRealized pricing unknownFedRAMP and government pagesPublic-sector revenue may carry procurement friction and compliance cost

This table distinguishes monetization posture from observable price points. Keyfactor does not publish a public list price for its core offerings in the reviewed sources.

[CI006, CI024, CI026, CI036, CI037]
FI001: Revenue model bridge

Keyfactor converts trust-infrastructure workflows into revenue through a layered software-plus-managed-services model.

[CI001, CI002, CI003, CI004, CI005, CI034]

4.2 GTM motion appears enterprise-led, with public scale signals stronger than P&L disclosure

Keyfactor’s public operating signals point to a classic enterprise security GTM motion. The company appointed a President and CRO in January 2026 with explicit responsibility for sales, marketing, and channel, which is consistent with a scaled, quota-carrying field organization rather than a product-led motion. The same release said Keyfactor nearly doubled ARR in less than two years, expanded to more than 540 employees across 12 countries, and entered 2026 after the strongest year in company history. Earlier disclosures add a longer growth arc: the 2023 Sixth Street investment announcement cited three-year revenue CAGR above 70% and more than 1,500 organizations on the platform, while the July 2026 investment announcement said the company serves more than 2,500 customers and manages billions of machine identities each year. Those are meaningful scale signals, but they are still proxies. They do not disclose current ARR, gross retention, net revenue retention, sales efficiency, or customer concentration. The public evidence therefore supports growth momentum and installed-base breadth, but not precise sales-efficiency underwriting. [CI009, CI010, CI011, CI012, CI013, CI014]

Unit economics table
MetricValue / statusConfidenceWhy it mattersPublic proxyDiligence ask
ARR growthNearly doubled in less than two yearsmediumConfirms demand momentumJanuary 2026 CRO releaseRequest exact ARR bridge by quarter
Three-year revenue CAGR>70% disclosed in 2023mediumUseful historical growth anchor2023 Sixth Street announcementRequest revenue base, CAGR period, and normalization
ROI / customer payback356% ROI, payback under six months for composite customermediumSupports buyer value and sales narrative2026 commissioned TEI resultsRequest raw customer references and realized deployment costs
Gross marginNot publicly disclosedlowCore revenue-quality inputManaged-service and software mix onlyRequest gross margin by product and services line
CAC / paybackNot publicly disclosedlowCore sales-efficiency inputCRO appointment and global expansion are only proxiesRequest CAC, payback, and S&M spend history
Net retention / churnNot publicly disclosedlowTests installed-base durabilityCustomer logo and growth signals onlyRequest cohort retention and expansion by segment

Keyfactor discloses persuasive growth proxies, but not the private-company unit economics needed for full underwriting.

[CI006, CI007, CI008, CI009, CI010, CI011]
FI002: Unit economics bridge

Public unit-economics evidence is strongest on customer ROI and weakest on company margin and CAC disclosure.

[CI006, CI020, CI023, CI031, CI037]
FI003: Financial estimate range

The only public quantified unit-economics range is customer-side value from the commissioned TEI framework, not company P&L.

[CI006, CI007, CI037]

4.3 Capital adequacy looks strong, but cash, burn, and margin structure are still private

The capital story is clearer than the operating model, but still incomplete. Keyfactor raised $77 million from Insight in 2019, brought in Sixth Street Growth at an approximately $1.3 billion enterprise value in 2023, and then announced a $1 billion-plus strategic growth investment led by Summit Partners in July 2026 while keeping Insight and Sixth Street as significant shareholders. Those events strongly suggest the company is not capital constrained in the near term, especially because management and investors framed the 2026 transaction around product innovation, geographic expansion, team building, and strategic acquisitions rather than emergency balance-sheet repair. The public releases also describe accelerating revenue growth and record profitability, which is directionally positive. However, none of the capital announcements disclose cash on hand, monthly burn, debt covenants, runway, or free cash flow. Cost structure also remains inferred rather than disclosed. This business should be less capex-intensive than hardware or payment infrastructure businesses, but it still may carry meaningful costs in customer success, compliance, cloud hosting, HSM-backed operations, partner support, and public-sector delivery. The result is a favorable capital-adequacy signal paired with a still-material opacity around true margin structure and cash conversion. [CI012, CI014, CI015, CI016, CI017, CI019]

Capital adequacy table
Capital questionPublic answerSignalWhy it mattersDiligence ask
Cash on handNot disclosedunknownDetermines actual self-funded runwayRequest latest balance sheet and post-close cash balance
Financing supportBacked by Insight, Sixth Street, and Summit across 2019, 2023, and 2026strongSignals access to follow-on capital and sponsor backingRequest investor rights, preferences, and governance terms
Planned use of fundsInnovation, geographic expansion, team building, and strategic acquisitionsstrongSuggests offensive use of capital rather than rescue financingRequest operating plan and M&A reserve allocation
Monthly burn / runwayNot disclosedunknownKey input for downside protectionRequest budget, burn, and runway under base/downside cases
Debt or project-finance obligationsNo material obligations disclosed in reviewed public sourcesmediumDebt can constrain flexibility even in growth softwareRequest debt schedule, leases, and contingent obligations

Public capital events support near-term adequacy, but the underlying cash and obligation stack is still private.

[CI012, CI014, CI016, CI017, CI019, CI027]
FI004: Capital intensity / cash-flow map

Capital intensity appears light to moderate, with the largest public cost pressures likely in people, compliance, hosting, and M&A rather than plant or inventory.

[CI011, CI016, CI026, CI029, CI035]

4.4 Public verdict: strong strategic momentum, but incomplete underwriting package

On publicly available evidence alone, Keyfactor screens as a strong private cybersecurity asset with recurring enterprise demand, sponsor support, and credible signs of operating scale. The public case is strongest on category tailwinds, capital access, product breadth, and enterprise relevance. It is materially weaker on the inputs an investor would need to underwrite the next five years of financial performance: current ARR, net revenue retention, gross margin by product line, services mix, CAC, payback, partner economics, concentration, and cash generation. The TEI study is helpful because it shows why enterprise buyers may fund the purchase, but it is commissioned customer ROI evidence, not company income-statement evidence. Public substitute pricing from AWS also shows that part of the broader trust market exposes buyers to more transparent infrastructure-native economics, which can put a ceiling on how much opaque enterprise pricing can expand without clear ROI. The correct public verdict is therefore neither bearish nor fully underwritten. Keyfactor appears financially healthy and strategically well-funded, but there are still enough disclosure gaps that an investor should treat valuation confidence as conditional on management data-room support. [CI006, CI020, CI021, CI024, CI028, CI031]

Public financial gaps table
Missing private metricImpactWhy it blocks underwritingExact diligence path
Current ARR / revenuehighPrevents precise growth and multiple analysisObtain monthly ARR, revenue bridge, and current quarter run-rate
Gross margin by product linehighCannot distinguish software quality from managed-service dragObtain gross margin split for software, support, and managed services
NRR, churn, and expansionhighCannot test durability of installed baseReview cohort retention and top-50 account expansion history
CAC, payback, and partner economicshighCannot assess GTM efficiency or channel leverageReview S&M spend, sourced pipeline, and partner attach economics
Concentration and cash generationhighCannot assess downside sensitivity or financing dependencyReview top-customer concentration, cash flow, burn, and post-close cash balance

These missing metrics do not negate the strategic case; they limit how precisely an outsider can underwrite it.

[CI020, CI021, CI028, CI031, CI038]

4.5 Exhibits

Chapter 05

05Product & Technology

5.1 Product stack maps to real trust-infrastructure workflows

Keyfactor’s product definition is best understood as a workflow stack, not a single SKU. Customers use Command to discover, automate, and govern machine identities and certificates across enterprise estates. EJBCA Enterprise anchors certificate authority and private PKI workflows, while SignServer Enterprise addresses adjacent but strategically important signing workflows such as code signing, document signing, timestamping, firmware signing, and other artifact-trust use cases. Cloud PKI as-a-Service and the government-focused certificate lifecycle automation offering reduce infrastructure burden for customers that do not want to run the underlying PKI stack themselves. The newer Trust Control Plane narrative attempts to unify these surfaces into one control layer for machine identities, cryptographic assets, and trust systems. That matters in customer workflow terms because the buyer problem is rarely “issue a certificate” in isolation; it is usually discover what exists, automate issuance and renewal, preserve signing trust, migrate cryptography safely, and keep policy control as environments grow more hybrid and AI-driven. The stack therefore spans both operational trust plumbing and higher-level governance. [CE001, CE002, CE003, CE004, CE005, CE006]

Product module / asset matrix
Module / assetPrimary userStatus / maturityDifferentiationDiligence gap
CommandPKI and security operationsMature core platformCA-agnostic certificate lifecycle automation and policy controlNeed public reference architecture for largest-scale deployments
EJBCA EnterprisePKI architects and CA operatorsMature core platformPrivate PKI depth with open-source roots and enterprise supportNeed independent benchmark on upgrade burden and performance
SignServer EnterpriseSecurity engineering and signing teamsMature but actively evolvingExtends stack into code, document, and artifact trustNeed public proof on enterprise signing throughput and policy complexity
Cloud PKI as-a-ServiceInfrastructure and security teamsCommercially activeReduces operational burden for PKI deliveryNeed public SLA and margin / hosting detail
Government CLAaaSFederal and public-sector security teamsCommercially active in 2026FedRAMP-backed delivery optionNeed public deployment detail beyond authorization milestone
Trust Control PlaneSecurity leadership and trust governanceNew umbrella narrative in 2026Unifies machine identity, cryptographic assets, and trust systemsNeed deeper public decomposition of module boundaries and workflows

The matrix distinguishes older, well-proven product layers from the newer control-plane framing that sits above them.

[CE001, CE002, CE003, CE005, CE006, CE020]
Workflow / use-case table
User jobCurrent workflowKeyfactor solutionMeasurable benefitLimitation
Discover machine identitiesManual inventory or fragmented toolsCommand / Trust Control Plane discoveryBetter visibility into certs and crypto assetsPublic benchmark detail is limited
Operate private PKIInternal CA administration and manual controlsEJBCA Enterprise or Cloud PKICentralized issuance and lifecycle managementUpgrade and app-stack dependencies remain material
Automate certificate renewalManual renewal and outage-prone operationsCommand workflows and policy automationReduced operational overhead and incident riskNeeds strong integration discipline
Secure digital signingSeparate code or document signing toolingSignServer Enterprise / SignumPolicy-driven artifact trust with HSM supportPublic throughput and reference architecture details are sparse
Serve regulated public sectorOn-prem or fragmented compliance approachGovernment CLAaaS and FedRAMP-backed deliveryLower modernization friction for agenciesMarketplace detail is still sparse publicly

The use-case table is intentionally workflow-based rather than feature-list-based because buyers purchase around operational trust jobs.

[CE002, CE003, CE005, CE020, CE021, CE023]
FE001: Product architecture map

Keyfactor’s stack layers governance, lifecycle automation, PKI, signing, and managed delivery over common trust infrastructure needs.

[CE001, CE002, CE003, CE005, CE006, CE030]
FE002: Customer workflow / operating flow

The operating workflow moves from asset discovery to issuance, automation, signing, and ongoing governance.

[CE002, CE003, CE005, CE006, CE023, CE032]

5.2 Architecture relies on open-source foundations, commercial layers, and external dependencies

Keyfactor’s architecture shows a deliberate combination of open-source community surfaces and commercial enterprise layers. The EJBCA and SignServer community repositories make clear that community editions are intended for learning, testing, and prototyping rather than production; enterprise editions add higher-assurance features, certifications, SLAs, auditability, and operational support. That is strategically useful because it gives Keyfactor a top-of-funnel developer and partner surface while preserving a paid enterprise boundary. The technical stack is concrete rather than hand-wavy. Public materials show Java-based application delivery, container and Helm deployment paths, software and SDK ecosystems around EJBCA, and HSM-oriented integrations in signing workflows. Recent release notes also show ongoing platform evolution: EJBCA Community 9.0 moved to newer application-server and Java prerequisites, while SignServer 7.6 added composite certificates, CloudHSM migration support, and new security fixes. Those details support real product maturity, but they also reveal dependency risk. Customers depend on app-server compatibility, Java runtime changes, HSM support, cloud integrations, and deployment discipline. That creates real implementation and upgrade burden even in a mature product family. [CE007, CE008, CE009, CE010, CE011, CE012]

Technology / operating architecture table
Layer / componentRoleDependencyRisk
Java / JVM application stackRuntime base for EJBCA and SignServerJava version supportRuntime upgrades can add migration burden
Application server layerEnterprise deployment baseWildFly / JBoss EAP compatibilityStack changes can complicate upgrades
HSM integrationKey protection and signing trustCloudHSM and enterprise HSM environmentsHardware and crypto-token integration complexity
Container / Helm deliveryModern deployment pathKubernetes and container environmentsOperational maturity shifts to customer platform teams
Community repositories and SDKsDeveloper and partner extension surfaceGitHub maintenance and docsCommunity does not guarantee enterprise support

This architecture table uses only public evidence from docs and community repositories; it avoids guessing undocumented internals.

[CE007, CE008, CE009, CE010, CE011, CE016]
FE003: Critical dependency map

Reliability depends on runtime, HSM, cloud, compliance, and patch-management dependencies as much as on core product code.

[CE007, CE008, CE013, CE018, CE020, CE028]
FE004: Product maturity / capability map

Core trust engines appear mature, while newer control-plane and SaaS motions are earlier in public articulation.

[CE006, CE010, CE011, CE012, CE026, CE029]

5.3 Trust, quality, and security controls are visible, but so are patching obligations

Keyfactor’s trust posture is unusually observable for a private company because it exposes multiple quality-control surfaces. The company has a public security-advisories section, public product documentation, public community repositories, and a public FedRAMP announcement for its government offering. Those are meaningful controls because they show a product organization willing to document issues and operational guardrails rather than hiding all evidence behind sales channels. At the same time, the same transparency also reveals technical risk. The security-advisory page lists multiple 2025 and 2026 issues affecting EJBCA and SignServer, including the EJBCA MPIC compliance issue and several SignServer vulnerabilities. OpenCVE also aggregates disclosed issues across Command, SignServer, EJBCA, and AWS Orchestrator. This does not prove product weakness relative to peers—serious infrastructure software will always carry vulnerability management obligations—but it does show that customers need disciplined upgrade and patch operations. In other words, Keyfactor’s trust posture is credible partly because the company discloses risk, but the disclosed risk is real and should be treated as part of implementation and support cost. [CE013, CE014, CE019, CE020, CE021, CE028]

Trust / quality / compliance table
Control / certificationStatusScopeGap
FedRAMP Moderate authorizationAnnounced in 2026Government cloud certificate lifecycle automationMarketplace detail is not richly readable in this run
Public security advisoriesActiveEJBCA and SignServer issues and fixesCustomers still need disciplined patch management
OpenCVE footprintActiveCommand, SignServer, EJBCA, AWS Orchestrator disclosuresNo independent benchmark against peer vuln rates
Enterprise-versus-community boundaryClearly documentedProduction assurance, SLAs, and supportPublic SLA specifics are still sparse
Public docs and release notesActiveSignServer and open-source release detailDoes not fully replace independent performance or resilience testing

Visible controls strengthen trust, but they also expose the maintenance obligations customers inherit when running trust infrastructure at scale.

[CE010, CE011, CE013, CE014, CE019, CE020]

5.4 Differentiation comes from breadth and crypto-agility, while public gaps remain around benchmarked performance

The strongest technical differentiation is breadth under one operating umbrella. Keyfactor can credibly argue that it spans certificate lifecycle automation, private PKI, signing, managed deployment, government delivery, and crypto-agility rather than merely offering a narrow renewal engine. The open-source project surfaces for EJBCA and SignServer strengthen that argument because they show ecosystem depth and a practitioner on-ramp that most purely proprietary vendors do not have. Product materials also indicate active work around post-quantum readiness, composite certificates, CloudHSM-backed signing, SaaS delivery, and tighter integration between discovery and lifecycle automation. Those are sensible roadmap directions given certificate-lifetime compression and the need to modernize legacy PKI estates. The biggest public gaps are not basic existence or category fit, but independent evidence on performance, uptime, and implementation effort at scale. There is no public architecture benchmark proving throughput or deployment times across the stack, and there is no detailed public reference architecture for Trust Control Plane that resolves how much customers must still integrate themselves. So the product story is mature and credible, but not fully benchmarked for diligence purposes. [CE015, CE022, CE024, CE025, CE027, CE029]

Roadmap / release / development-stage table
Date / stageFeature / milestoneStatusImplicationSource
2026Trust Control Plane launchAnnouncedMoves product story toward unified trust governanceKeyfactor press release
2026SignServer 7.6 composite certificates and CloudHSM improvementsReleasedSupports PQC transition and HSM-centered signing workflowsKeyfactor Docs release notes
2025-2026Security fixes and CVE remediation across SignServer / EJBCAOngoingShows active maintenance cadence and patch obligationsSupport advisories / OpenCVE
2024-2025 community to 2026 enterprise cadenceEJBCA 9 technology-stack upgradeReleased in community lineSignals continuing core-platform modernizationGitHub releases
CurrentPartner-led expansion and ecosystem motionActiveSuggests broader deployment and integration reachPartners / IBM pages

The roadmap table emphasizes observable release and partnership motion rather than private roadmap promises.

[CE006, CE007, CE008, CE009, CE012, CE022]

5.5 Exhibits

Chapter 06

06Customers

6.1 Customer base spans regulated enterprise, software, infrastructure, and government

Keyfactor’s public customer story is broad enough to support a category platform thesis rather than a niche point-solution thesis. Company materials say Keyfactor serves more than 2,500 customers globally and has deep penetration in financial services, banking, technology, healthcare, telecom, retail, and U.S. federal environments. The named-customer proof fits that segmentation. ServiceNow represents large-scale software and platform operations. Siemens and Schneider Electric show industrial and device-trust use cases. OVHcloud and SK ID Solutions show infrastructure-heavy and sovereign or digital-identity contexts. M&T Bank and GRENKE demonstrate financial-services relevance, while the Netherlands Ministry of Justice and Security shows long-duration public-sector trust. In buyer terms, the payer is usually the security or infrastructure organization, the user is typically PKI, platform, DevOps, or signing teams, and the budget rationale is outage prevention, compliance, zero-trust readiness, or trust-platform modernization. This breadth matters because it suggests Keyfactor can land through multiple operational pain points, not only through one vertical-specific use case. [CU001, CU002, CU003, CU004, CU005, CU006]

Customer segmentation table
SegmentBuyer / user / payerUse caseScale signalStrategic valueGap
Large software / SaaSSecurity + platform teamsAPI-driven issuance and renewalServiceNow millions of certsValidates cloud-scale automationNo contract-value disclosure
Industrial / manufacturingProduct security + PKI teamsDevice identity, zero trust, signingSiemens and Schneider proofSupports OT / device-trust narrativeNo public retention metric
Cloud / infrastructureSecurity + infrastructureSovereign private PKI and controlOVHcloud 1.5M+ developersShows infrastructure credibilityNo independent SLA benchmark
Digital identity / trust servicesPKI operations + service deliveryNational or regulated identity trustSK ID and Ministry proofSupports high-assurance environmentsPublic economics are absent
Financial servicesSecurity + infrastructure + complianceCertificate visibility, compliance, outage preventionM&T and GRENKE proof plus company claimsLarge regulated expansion pathConcentration and procurement speed unknown
Government / public sectorAgency security and identity teamsPKI for identity, documents, modernizationMinistry + FedRAMPHigh-stakes reference qualityMarketplace details are sparse publicly

This segment map uses named proof and company-wide claims rather than generic logo enumeration.

[CU001, CU002, CU004, CU005, CU006, CU007]
Customer growth / adoption trajectory table
MetricValueDateSourceConfidenceImplicationMissing denominator
Customers worldwide2,500+2026-07-06Investment releasemediumLarge installed baseUnknown ARR per customer
Organizations served1,500+2023-10-24Sixth Street announcementmediumShows growth before 2026 scale claimUnknown overlap with current count
ARR growth signalNearly doubled in <2 years2026-01-14Volanoski PRmediumAdoption is growing with revenueNo exact ARR base
Employee footprint540+ employees in 12 countries2026-01-14Volanoski PRmediumSuggests support and customer-coverage scaleNo customer-success staffing split
Penetration claim>40% of Fortune 1002026-07-06Investment releasemediumHigh-quality enterprise reference baseNo revenue concentration detail
Penetration claim50% of largest U.S. and European banks2026-07-06Investment releasemediumStrong financial-services relevanceNo named bank roster

Trajectory evidence is directionally strong but still mixes customer counts, penetration claims, and growth proxies.

[CU001, CU002, CU003, CU022]
FU001: Customer journey map

Customers typically begin with a trust pain point and expand into broader automation, PKI control, and signing or compliance workflows.

[CU004, CU010, CU011, CU012, CU013, CU023]

6.2 Named customer proof is unusually specific and production-oriented

The most persuasive part of Keyfactor’s customer evidence is not the count of logos; it is the specificity of the outcomes. ServiceNow describes millions of certificates issued across services and workloads with API-driven issuance and renewal. Siemens reports an 85% reduction in deployment time after automating PKI as code with EJBCA and Ansible. OVHcloud says it achieved full internal PKI control while supporting more than 1.5 million developers and 10,000-plus certificates. SK ID Solutions says it migrated 20 million certificates across more than 20 countries with zero incidents since implementation. The Netherlands Ministry of Justice and Security highlights 15-plus years of PKI operations supported by EJBCA across passports, visas, internal IT services, and digital health certificates. GRENKE reports 25,000-plus centrally managed active certificates, provisioning in under five minutes, and zero certificate-related outages. Schneider Electric reports a 10x reduction in software-signing cost, an 80% drop in key-ceremony cost, and support for more than one million signing events annually. M&T Bank reports 350,000-plus active certificates managed enterprise-wide and more than ten years of partnership. These are production-like outcomes, not pilot narratives. [CU010, CU011, CU012, CU013, CU014, CU015]

Named customer proof table
CustomerSegmentDeployment / use caseProduction vs pilotOutcomeLimitation
ServiceNowSoftware / platformCentralized modern PKI with API-based issuanceProductionMillions of certificates; 100% API-driven issuance and renewalNo contract duration disclosed
SiemensManufacturing / industrialPKI as code with EJBCA + AnsibleProduction85% reduction in deployment timeNo certificate-volume disclosure
OVHcloudCloud infrastructureCentralized sovereign PKI on EJBCAProduction100% internal PKI control; 10K+ certs; 1.5M+ developersNo financial impact disclosed
SK ID SolutionsDigital identityLegacy PKI replacement with EJBCAProduction20M certificates migrated; 20+ countries; zero incidentsNo contract size disclosed
Netherlands Ministry of Justice and SecurityGovernmentNational identity and document verification PKIProduction15+ years of PKI operations supportedNo current spend or seat count disclosed
GRENKEFinancial servicesCertificate visibility and self-service workflows with CommandProduction25,000+ certs; <5 min provisioning; zero outagesNo renewal economics disclosed

All rows reflect production-oriented use, not vague logo attribution.

[CU005, CU006, CU007, CU008, CU009, CU010]
Additional customer proof table
CustomerSegmentDeployment / use caseProduction vs pilotOutcomeLimitation
Schneider ElectricIndustrial / device securityUnified PKI, firmware signing, and software signingProduction10x lower software-signing cost; 80% lower key-ceremony cost; 1M+ signing eventsNo exact implementation duration disclosed
M&T BankFinancial servicesCloud-based PKI visibility and lifecycle automationProduction350,000+ active certificates; 50% reduction in self-signed certificates; 10+ year partnershipNo pricing disclosure
ServiceNowSoftware / platformAuditability and API-based issuanceProductionDozens of engineering hours saved through automationSavings not annualized
OVHcloudCloud infrastructureSovereign PKI controlProductionSupports compliance and crypto change at scaleNo explicit renewal duration disclosed
Schneider ElectricIndustrial / software integrityGlobal signing operationsProductionAudit-ready compliance and PQC preparation narrativeCompliance outcomes are customer-stated

This table adds measurable proof for customers with especially detailed operational outcomes.

[CU016, CU017, CU018, CU019, CU020, CU021]
FU002: Adoption / deployment funnel

The customer path is usually operational pain to modernization, then to broader trust control and expansion.

[CU010, CU011, CU012, CU014, CU022, CU023]
FU003: Customer proof matrix

Reference quality is high across the named sample, but financial durability disclosure is low.

[CU010, CU011, CU012, CU013, CU014, CU015]

6.3 Expansion logic is clear, but retention and satisfaction are largely undisclosed

The public record suggests a strong land-and-expand motion even though classical SaaS retention metrics are absent. Several customer stories begin with one operational wedge—certificate visibility, PKI modernization, code signing, public-sector identity verification, or compliance modernization—and then expand into broader automation, governance, or future crypto-agility needs. M&T Bank’s more-than-ten-year relationship and the Netherlands Ministry’s 15-plus years of PKI operations are the clearest duration signals in the public record. OVHcloud’s case explicitly references open-source affinity and enterprise support, which is useful evidence that Keyfactor can convert community-compatible buyers into enterprise relationships. ServiceNow, Siemens, SK ID, Schneider, and GRENKE all describe operational integration deep enough that replacement would likely be difficult once workflows, policy, and trust anchors are centralized. Still, the public record does not disclose NRR, GRR, renewal rates, churn, contract length, or customer satisfaction metrics. That means durability is best inferred from workflow depth and relationship length rather than measured retention disclosure. [CU022, CU023, CU024, CU025, CU026, CU027]

Retention / repeat usage / satisfaction table
MetricValue / nullSegmentConfidenceWhy it mattersDiligence ask
Relationship duration: M&T Bank10+ yearsFinancial servicesmediumSuggests durability and repeat trustRequest ACV trend and module expansion history
Relationship duration: Netherlands Ministry15+ yearsGovernmentmediumSuggests long-term operational dependenceRequest renewal structure and current contract scope
Workflow stickinessHigh but qualitativeEnterprise / infrastructuremediumDeep PKI and signing integration raises switching costRequest replacement case studies and renewal rates
NRR / GRRNot publicAll segmentslowBest quantitative test of installed-base durabilityRequest cohort retention and expansion by segment
Customer satisfaction / NPSNot publicAll segmentslowHelps separate referenceability from real sentimentRequest NPS, CSAT, support SLAs, and escalation metrics

Public customer proof is strong, but retention-quality measurement remains mostly inferential.

[CU023, CU024, CU025, CU026, CU027, CU028]

6.4 Public customer quality is strong, but concentration and procurement risk remain open questions

The same evidence that makes Keyfactor attractive also highlights what outsiders still cannot see. Public proof skews toward large, reference-grade organizations, which supports enterprise credibility but also raises the possibility that revenue concentration, long sales cycles, and procurement complexity matter more than the public record shows. Keyfactor’s vertical concentration looks strongest in regulated environments: financial services, public sector, infrastructure, manufacturing, and large software estates. Those are strong segments, but they often bring compliance scrutiny, renewal rigor, and slower procurement. Government and large-bank opportunities can be sticky and high-value, yet they can also create dependence on certification maintenance, partner ecosystems, and heavyweight implementation resources. The partner surface also implies that some expansion may rely on channel and integration relationships rather than purely direct self-propelled demand. Because public sources do not reveal top-customer exposure, cohort economics, or contract structure, the correct customer verdict is positive but incomplete: Keyfactor has better public production proof than many private cybersecurity peers, but concentration and renewal quality still need direct diligence. [CU031, CU032, CU033, CU034, CU035, CU036]

Expansion and concentration risk table
Expansion driverConcentration / procurement riskImpactDiligence path
Broader trust workflow from discovery to signingLarge customers may represent outsized revenue sharehighRequest top-10 customer concentration and ACV distribution
Regulated vertical relevanceBanking and government cycles can be long and compliance-heavyhighReview pipeline aging and procurement blockers by segment
Partner and ecosystem motionSome expansion may depend on channel or integration partnersmediumRequest sourced-pipeline share and partner attach rates
Community-to-enterprise conversionOpen-source affinity may not always convert to high ACVmediumReview community-origin account conversion and support attach
Cross-sell into managed and government deliveryCertification maintenance and delivery overhead may slow scalingmediumRequest services capacity, FedRAMP maintenance cost, and implementation lead times
Reference-grade logosPublic references may overweight best-fit customersmediumAsk for anonymized churn cases and lost renewals

The public record supports expansion logic, but not concentration safety.

[CU029, CU030, CU031, CU032, CU033, CU034]

6.5 Exhibits

Chapter 07

07Risks

7.1 Top risks are ranked around trust failures, regulated delivery, and execution opacity

Keyfactor’s risk profile is unusual because the company sells directly into the operational fabric of digital trust. That means a failure in its own product security, upgrade process, or compliance posture would not be treated like a minor software bug by customers; it would be interpreted as a contradiction of the company’s core promise. Public evidence shows that the risk surface is real. The company maintains an active security-advisories program, OpenCVE aggregates multiple disclosed vulnerabilities across Command, SignServer, EJBCA, and AWS Orchestrator, and NVD records several medium-to-high severity issues across recent versions. None of that is automatically thesis-breaking—serious infrastructure software always requires patching—but it does make security execution the first risk family to underwrite. The second family is regulated-delivery risk: FedRAMP and public-sector positioning expand the opportunity but create ongoing certification and operational obligations. The third family is evidence opacity. Public sources do not disclose the customer concentration, retention, cash, or reliability detail needed to bound downside precisely. As a result, Keyfactor can look strategically strong while still carrying under-measured residual risk. [CR001, CR002, CR003, CR004, CR005, CR006]

FR001: Risk heatmap

Residual risk is highest where product-security execution, regulated delivery, and evidence opacity intersect.

[CR001, CR009, CR016, CR019, CR026, CR034]

7.2 Legal, regulatory, and customer risks center on compliance posture and reference-account exposure

Keyfactor’s public legal and regulatory profile is not dominated by known litigation, but that should not be confused with low exposure. The company’s privacy policy makes clear that it handles personal and business data across website, event, marketing, and service interactions, which creates baseline privacy and cross-border processing obligations. The government and regulated-enterprise positioning creates a second layer of exposure. FedRAMP authorization is a valuable signal, yet it also becomes a monitorable dependency: if the authorization posture deteriorates or supporting controls weaken, the company could lose credibility in exactly the customer set it wants to deepen. On the customer side, public proof is concentrated in large, reference-grade organizations across banks, government agencies, industrial groups, and platform providers. That is strategically positive, but it also implies potential concentration, heavy procurement, and demanding support expectations. Public evidence is insufficient to determine whether the customer base is diversified enough to absorb a major renewal loss. In that sense, legal and customer risk are linked: the more Keyfactor leans into regulated buyers, the more trust, documentation, and certification maintenance become revenue-critical obligations. [CR009, CR010, CR011, CR012, CR016, CR017]

Regulatory / legal risk register
Rule / case / obligationJurisdictionStatusLikelihoodSeverityMitigationResidual exposureDiligence path
FedRAMP authorization maintenanceU.S. federalActive authorization pathmediumhighFedRAMP Moderate announcement and government offeringLoss or slippage would damage public-sector credibilityVerify marketplace status, control ownership, and annual maintenance workload
Privacy-policy and data-handling obligationsMulti-jurisdictionPublic privacy policy in forcemediummediumDocumented privacy commitmentsUnknown service-data processing and cross-border exposure detailReview DPA, subprocessors, breach notice obligations, and data-locality terms
Regulated-sector compliance obligationsBanking / government / industrialOngoingmediummediumProduct positioning and customer evidence in regulated sectorsSales cycles and renewal dependence can rise with compliance burdenRequest segment-specific compliance matrices and audit findings
Public-sector procurement dependencyU.S. and EuropeOngoingmediummediumGovernment references and FedRAMP postureLong procurement cycles can slow growth and amplify certification setbacksReview pipeline aging and procurement drop-off by segment

Rows are ranked by severity to customer trust and revenue transmission rather than by abstract legal complexity alone.

[CR009, CR010, CR011, CR017, CR024, CR032]

7.3 Operational and dependency risks arise from upgrades, HSMs, clouds, partners, and hybrid complexity

The public technical record shows that Keyfactor’s architecture is mature but not simple. Recent EJBCA and SignServer materials document Java and application-server upgrades, composite-certificate support, CloudHSM improvements, and continuing release work around migration and automation. Those are positive roadmap indicators, but they also reveal operational failure modes: stack upgrades can break deployments, HSM integration can slow or complicate rollouts, and hybrid customer estates magnify the consequences of misconfiguration. Customer case studies themselves underscore how complex the starting environment often is: multiple PKI systems, legacy platforms, self-signed certificates, distributed CAs, or siloed signing tools. That complexity is one reason customers buy Keyfactor, but it also means implementation quality and support maturity are fundamental risk mitigants. Partner and ecosystem motion adds another layer. If key integrations, partner workflows, or cloud dependencies weaken, the platform may still function but lose deployment speed, referenceability, or go-to-market leverage. The presence of open-source community editions further complicates the picture: they are a powerful adoption surface, yet they also create support-boundary and self-managed deployment risk when customers underinvest in enterprise operational discipline. [CR007, CR008, CR013, CR014, CR015, CR018]

Operational / quality / security risk register
Failure modeLikelihoodSeverityMitigation maturityResidual exposureUnresolved gap
Product vulnerability in core trust softwaremediumhighmediumA serious exploit would directly damage trust narrativeNeed incident history and patch-SLA evidence
Customer patching / upgrade laghighhighmediumDisclosed fixes still require customer adoptionNeed upgrade compliance and support telemetry
Compliance issue in certificate-validation logicmediumhighmediumCA/B-related issue can harm customer complianceNeed scope and remediation adoption data
Stack-upgrade disruptionmediummediummediumJava or app-server changes can slow enterprise upgradesNeed version adoption and failed-upgrade statistics
Trust-platform incident / outagelow-mediumhighunknownNo public uptime benchmark to bound impactNeed SRE metrics and incident reviews

Security execution is the most direct operational risk because the company’s value proposition is itself trust and automation.

[CR001, CR002, CR003, CR004, CR005, CR006]
Partner / dependency risk register
DependencyCounterpartyRoleConcentrationFailure scenarioSeverityMitigationResidual exposure
Cloud HSM / HSM ecosystemsAWS CloudHSM and enterprise HSM vendorsKey protection and signing workflowsmediumMigration friction or incompatibility slows deploymentsmediumDocumented support improvements and enterprise servicesStill dependent on customer environment and hardware choices
Application-server and runtime stackJava / WildFly / JBoss ecosystemsCore deployment basehighVersion shifts create upgrade or compatibility frictionmediumActive release maintenanceCustomer environments remain heterogeneous
Partner / channel ecosystemIntegration and channel partnersGo-to-market and deployment accelerationmediumWeak partner motion can slow expansion or implementationmediumBroad partner surfaceNo public sourced-pipeline mix
Regulated reference customersGovernment and banking accountsRevenue credibility and segment leadershipunknownReference loss or failed renewal damages signal valuehighStrong installed proofTop-customer exposure is private
Competitive bundle pressureCyberArk/Venafi, DigiCert, cloud-native substitutesPricing and renewal pressuremediumStandalone budget narrows as bundles winhighBreadth and independence narrativeActual win-loss data is private

The biggest dependency risks are not single suppliers, but external platforms and counterparties that can slow adoption or compress budgets.

[CR014, CR016, CR018, CR021, CR027, CR033]
People / execution risk register
Role / functionDependency or gapLikelihoodSeverityMitigationDiligence path
Product and engineeringMust sustain security fixes, PQC roadmap, and release quality simultaneouslymediumhighVisible release cadence and advisory programRequest engineering headcount mix, vuln-response SLA, and roadmap resourcing
Customer success / supportComplex deployments require strong implementation and patch guidancemediumhighLarge employee footprint and enterprise support modelRequest support staffing, escalation performance, and install-base health metrics
Go-to-market leadershipAggressive scaling after strongest year increases execution expectationsmediummediumCRO hire and sponsor backingReview sales productivity, partner coverage, and quota attainment
Integration / M&A executionAcquired capabilities must translate into cohesive platform valuemediummediumPlatform narrative and sponsor capitalRequest acquisition integration milestones and revenue contribution
International coordination12-country footprint adds process and compliance complexitymediummediumGlobal operating footprint already presentReview management layers, regional support ratios, and local compliance ownership

Execution risk is meaningful because the product promise spans security, compliance, support, and strategic platform integration at once.

[CR022, CR023, CR030, CR037, CR039]
FR002: Risk transmission map

Security and compliance failures transmit quickly into customer trust, renewals, margin, and valuation.

[CR001, CR007, CR008, CR025, CR031, CR034]
FR003: Dependency map

Key dependencies sit across regulators, runtime ecosystems, HSMs, partners, and flagship customer segments.

[CR014, CR021, CR024, CR027, CR032, CR033]

7.4 Financial and investment risk hinges on opacity, bundle pressure, and measurable kill triggers

The financial-model risk is less about imminent insolvency and more about what public evidence still cannot verify. Sponsor backing from Insight, Sixth Street, and Summit reduces immediate capital-risk anxiety, but public sources do not disclose ARR, NRR, churn, cash, burn, gross margin, or top-customer exposure. That is important because bundle pressure from CyberArk/Venafi, DigiCert, and cloud-native substitutes can affect pricing power, implementation scope, and renewal economics before it shows up in top-line headlines. In a trust-infrastructure business, a single major security incident, certification setback, or marquee-customer renewal failure can also transmit disproportionately into valuation because the market reads those events as product-trust failures, not ordinary SaaS noise. The correct investment posture is therefore to convert the broad risk list into measurable triggers: material breach or exploited vulnerability, FedRAMP slippage, sharp slowdown in regulated-vertical wins, contraction in sponsor support, or evidence that expansion depends on services-heavy custom work rather than scalable product leverage. Those are the risk events most likely to break the thesis, not generic macro softness alone. [CR018, CR019, CR020, CR028, CR031, CR034]

Mitigation and kill criteria table
RiskMonitorable triggerThreshold / eventAction implication
Security execution failureExploit or emergency advisoryCritical exploited CVE in flagship product or repeated severe advisoriesPause or re-price investment until remediation maturity is proven
Certification / public-sector slippageFedRAMP or government control issueLoss, downgrade, or delayed maintenance of key authorizationReduce public-sector growth assumptions and reassess segment thesis
Customer concentrationMarquee account lossLoss or major contraction of a flagship bank, government, or industrial customerReassess durability and concentration exposure
Model opacityData-room shortfallManagement cannot provide reliable ARR, NRR, margin, and concentration dataDo not underwrite premium valuation without sharper entry discipline
Bundle pressureWin-loss deteriorationRising losses to bundled competitors in core regulated segmentsCut growth and multiple assumptions
Execution stretchServices-heavy expansionImplementation or support intensity rises faster than product leverageReassess margin path and capital needs

Kill criteria are phrased as monitorable events so the risk chapter can feed directly into investment discipline.

[CR034, CR035, CR036, CR037, CR038, CR040]

7.5 Exhibits

Chapter 08

08Valuation

8.1 Recommendation: constructive, but only with strict entry discipline

Keyfactor’s public evidence supports a positive company-quality view and a qualified valuation view. The bullish side is clear: the company operates in a category with structural urgency, has a repeat-sponsor capital stack, shows strong reference-quality customers, and owns a broader trust-infrastructure story than a simple certificate-renewal tool. The anti-thesis is also clear: public evidence still does not reveal the company’s current ARR, net retention, margin structure, concentration, or the exact terms of the 2026 transaction. That means the right recommendation is not a blanket “invest” but a conditional one: invest or lean in only if price, structure, and diligence outputs compensate for the still-missing underwriting inputs. Put differently, this is not a question of whether Keyfactor is strategically relevant. It is. The question is whether an investor is being asked to pay as if the company’s growth durability, margin path, and concentration are already proven. Public evidence does not justify that kind of blind premium. A disciplined investor should stay constructive on the asset, but insist on sharper valuation support and downside protections before underwriting a top-of-range outcome. [CV001, CV002, CV003, CV004, CV005, CV006]

Recommendation summary table
RecommendationConfidenceRisk ratingValuation stanceDecision implication
Constructive / conditional investMediumMedium-HighPrice-sensitive; do not underwrite top-of-range outcome without more dataProceed only with tighter diligence, structure protection, and valuation discipline
Watch / track if price is aggressiveMediumHighPass on purely narrative premiumIf public-evidence gaps remain unresolved, prefer monitoring over chasing momentum

The summary table distinguishes company quality from price discipline.

[CV001, CV004, CV006, CV007, CV010]
Thesis / anti-thesis table
ArgumentDirectionWhat would change the view
Category tailwinds in machine identity, shorter certificate lifetimes, and PQC readiness support durable demandThesisEvidence of slowing ARR or weak regulated-segment pipeline would weaken it
Reference-grade customers and product breadth support platform relevanceThesisProof that expansion is services-heavy or customer concentration is extreme would weaken it
Sponsor validation from Insight, Sixth Street, and Summit supports strategic qualityThesisUnfavorable round structure or preference overhang would weaken it
Missing ARR, NRR, margin, and concentration data make precision difficultAnti-thesisA strong data room with durable cohorts and software-heavy margins would improve confidence
Bundle pressure from larger security platforms can compress budgets and exitsAnti-thesisSustained win rates in regulated segments versus bundled rivals would reduce concern

The anti-thesis is primarily evidence-quality and scaling-risk driven, not market-denial driven.

[CV002, CV003, CV005, CV006, CV008, CV023]
FV001: Recommendation logic

Recommendation flows from category strength and proof into price discipline through unresolved economics and risk.

[CV001, CV002, CV003, CV006, CV007, CV010]
FV004: Investment KPIs

Keyfactor scores well on strategic quality but only moderately on evidence completeness and valuation precision.

[CV002, CV003, CV006, CV007, CV010, CV033]

8.2 Financing context supports a step-up from 2023, but not unlimited optimism

Public financing anchors imply meaningful value creation since 2023, but they do not produce a clean mark for 2026. The clearest disclosed anchor is the October 2023 Sixth Street transaction at an approximately $1.3 billion enterprise value. By July 2026, Keyfactor announced a $1 billion-plus strategic growth investment led by Summit Partners, with existing investors remaining significant holders and management describing accelerating growth and record profitability. That combination strongly suggests that the 2026 round happened from a position of strength, not distress. It does not, however, disclose post-money valuation, primary versus secondary mix, liquidation preferences, governance changes beyond board seats, or the revenue base against which a new price should be judged. Comparable market context helps but does not solve the problem. CyberArk’s $1.54 billion acquisition of Venafi shows strategic buyer appetite for machine identity and trust assets. Public cloud-security and identity names such as CyberArk, Okta, Rubrik, Palo Alto Networks, Zscaler, CrowdStrike, and SentinelOne all carry large public-equity values in July 2026, but they are not apples-to-apples references for a private trust-infrastructure company with undisclosed unit economics. So the financing context supports a higher 2026 value than 2023, but only within a wide confidence band. [CV011, CV012, CV013, CV014, CV015, CV016]

Comparable valuation table
ComparableMetricMultiple / valuation / statusRelevanceLimitation
Keyfactor 2023 Sixth Street transactionEnterprise value~$1.3B EVBest disclosed company-specific anchorHistorical and pre-2026 growth step-up
CyberArk acquisition of VenafiM&A valuation~$1.54B deal valueDirectly relevant machine-identity and certificate-management compStrategic M&A is not the same as minority growth pricing
CyberArk public market capPublic equity value$20.63BShows how the market values scaled identity-security platformsNot a direct revenue or margin multiple for Keyfactor
Okta public market capPublic equity value$24.34BRelevant identity-security reference for premium software sentimentDifferent product mix and scale
Rubrik public market capPublic equity value$17.31BCloud-security comp with enterprise profileDifferent data-protection category
Palo Alto Networks public market capPublic equity valueLarge-cap platform benchmarkShows upper-bound platform premium contextFar larger and more diversified than Keyfactor
Zscaler public market capPublic equity valueLarge-cap cloud-security benchmarkShows premium market appetite for security growthDifferent architecture and GTM
SentinelOne public market capPublic equity valueEndpoint-security growth benchmarkHelps frame private-security pricing contextCategory mismatch and different maturity

These are valuation anchors and sentiment references, not direct apples-to-apples pricing formulas for Keyfactor.

[CV011, CV015, CV016, CV017, CV018, CV019]
FV002: Valuation sensitivity

Valuation confidence is most sensitive to the still-missing private metrics rather than to market-size narrative alone.

[CV006, CV007, CV008, CV028, CV031, CV033]
FV003: Valuation / return range

Public evidence supports a wide valuation band anchored by the 2023 mark and a stronger 2026 strategic context, not a single precise number.

[CV011, CV014, CV023, CV024, CV025, CV027]

8.3 Bull/base/bear cases depend more on evidence quality than on market size alone

The valuation debate should be scenario-led because public evidence quality is uneven across the most important drivers. The bull case assumes that Keyfactor’s trust-infrastructure platform becomes a category-defining control plane for regulated enterprises and governments, that ARR growth remains strong, and that customers expand from PKI modernization into signing, discovery, and post-quantum programs. In that case, a valuation well above the 2023 anchor is easy to rationalize. The base case assumes continued strategic relevance but still treats retention, margin, and concentration as unresolved diligence items; that case supports a measured step-up rather than an aggressive re-rating. The bear case is not “the market disappears.” It is that bundle pressure, services intensity, or evidence gaps prove that Keyfactor is less scalable and less durable than the sponsor narrative implies, which could leave valuation support closer to the 2023 mark than headline excitement suggests. This is why recommendation confidence must stay moderate rather than high. The downside is driven less by category demand than by what diligence could still reveal about economics and customer mix. [CV023, CV024, CV025, CV026, CV027, CV028]

Bull / base / bear scenario table
ScenarioAssumptionsValuation / return logicKey risksProbability signal
BullARR growth remains strong, NRR is robust, trust-control-plane expansion works, regulated demand acceleratesSupports valuation materially above 2023 anchor and strong strategic premiumBundle pressure or security incident could break the casePossible but dependent on high-quality hidden metrics
BaseGrowth stays healthy, but public evidence gaps partly persist and margins / concentration are only moderateSupports a measured step-up from $1.3B rather than an unconstrained re-ratingRetention or margin could disappointMost consistent with current public evidence
BearGrowth quality is weaker than sponsor narrative, services intensity is high, or concentration is elevatedValuation support drifts back toward the last disclosed EV anchorMultiple compression and renewal pressureCannot be ruled out without data-room proof

Scenario logic is framed around what diligence could still discover, not just around market-size optimism.

[CV011, CV014, CV023, CV024, CV025, CV026]
Thesis-break and kill triggers table
TriggerThresholdTransmission to thesisAction implication
Security trust failureCritical exploited platform vulnerability or repeated severe advisoriesUndermines trust-infrastructure thesisPause or materially re-price
Retention / concentration disappointmentNRR or top-customer exposure materially worse than expectedReduces quality of growth and exit logicLower target entry valuation or walk away
Regulated-growth slowdownMeaningful slippage in government / banking pipeline or authorization postureWeakens the strongest reference segmentsReduce bull-case probability
Structure overhangPreference stack or round terms materially worse than implied by headline narrativeCuts common-equity upsideDemand structural protection or pass
Bundle pressureWin-loss deterioration against strategic suitesCompresses valuation ceilingLower base-case multiple and exit confidence
Services-heavy scaleImplementation intensity rises faster than product leverageWeakens margin path and sponsor exit qualityRecast business closer to services-enabled software

These triggers translate the risk chapter into valuation discipline.

[CV026, CV027, CV028, CV032, CV036, CV037]

8.4 Exit paths are credible, but final underwriting still depends on missing core data

Exit logic is credible on both strategic and financial paths. A strategic buyer thesis exists because machine identity, certificate management, signing, and crypto-agility increasingly matter to larger security and infrastructure vendors. The Venafi acquisition proves that appetite. A sponsor-to-sponsor path is also plausible because Keyfactor already fits the profile growth-equity firms like to own: software-heavy, category tailwind, regulated-customer proof, and room for product expansion plus M&A. But exit readiness is not the same as underwriting readiness. Before an investor should bless a premium valuation, the diligence burden is straightforward: confirm current ARR and growth quality, quantify net retention and customer concentration, separate software margin from managed-service drag, and test whether the platform scales through product leverage or through services-heavy implementation. Until those questions are answered, the company may deserve attention and access, but not blind valuation generosity. The correct final ask is not “is this a good company?” It is “what exact price and structure convert strong strategic evidence into an investable risk-adjusted return?” [CV034, CV035, CV036, CV037, CV038, CV039]

Final diligence asks table
TopicMissing evidenceWhy it mattersOwner / diligence path
Current ARR and growth qualityLatest ARR, growth bridge, bookings, and revenue mixCore input for any price-to-growth judgmentFinance team / data room
Retention and concentrationNRR, GRR, churn, top-10 customer exposure, renewal calendarDetermines downside resilience and valuation durabilityFinance + RevOps / data room
Margin pathGross margin by software, support, managed service, and professional servicesSeparates scalable software economics from services dragFinance / data room
Round structurePrimary versus secondary, preference stack, governance rights, dilution termsDetermines actual investor outcome at a given headline priceLegal + finance / transaction docs
Competitive realityRecent win-loss records against bundled and CA incumbentsTests whether platform narrative holds in live dealsSales ops / field interviews
Security executionIncident history, patch adoption, support SLAs, and remediation cadenceTrust-infrastructure multiple depends on execution qualitySecurity + support diligence

These diligence asks are the minimum needed to convert strategic interest into a priced investment view.

[CV006, CV007, CV008, CV009, CV033, CV038]

8.5 Exhibits

Disclaimer

This report is a diligence research artifact produced by an AI-assisted research workflow. All financial estimates and valuation ranges are based on publicly available information and may not reflect actual company financials or transaction terms. Sources are cited and subject to the access dates noted in each chapter. This report does not constitute investment advice. Readers should conduct independent due diligence before making any investment decision.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Keyfactor was founded in 2001 as Certified Security Solutions (CSS). High SO001, SO002
CO002 Certified Security Solutions rebranded as Keyfactor on November 1, 2018 as the company emphasized a software-led digital identity platform narrative. High SO001, SO002
CO003 Jordan Rackie is the CEO named in Keyfactor’s 2023 and 2026 financing announcements. High SO005, SO007
CO004 Ted Shorter serves as CTO and is Keyfactor’s public technical spokesperson on government and trust-infrastructure topics. High SO012, SO013, SO018
CO005 Keyfactor appointed Michael Volanoski as President and Chief Revenue Officer in January 2026. Medium SO011
CO006 The Volanoski appointment expanded the executive scope covering sales, marketing, and channel under a single GTM leader. Medium SO011
CO007 Keyfactor said in January 2026 that it had nearly doubled ARR in less than two years. Medium SO011
CO008 Keyfactor said in January 2026 that it had expanded to more than 540 employees across 12 countries. Medium SO011
CO009 Keyfactor closed a $77 million growth funding round with Insight Venture Partners in January 2019. High SO002, SO003, SO004
CO010 At the time of the 2019 Insight round, Keyfactor said it had doubled revenue year over year and secured more than 500 million certificates for Global 2000 clients. High SO002, SO003
CO011 Keyfactor’s October 2023 Sixth Street Growth transaction valued the company at approximately $1.3 billion enterprise value. High SO005, SO006
CO012 Keyfactor said in the 2023 Sixth Street announcement that its solutions were trusted by more than 1,500 organizations. High SO005, SO006
CO013 Keyfactor said in October 2023 that its three-year revenue CAGR exceeded 70%. High SO005, SO006
CO014 Bo Stanley and Alex Katz joined Keyfactor’s board as part of the 2023 Sixth Street investment. High SO005, SO006
CO015 Keyfactor announced a $1B+ strategic growth investment led by Summit Partners on July 6, 2026. High SO007, SO008, SO009, SO010
CO016 Insight Partners and Sixth Street Growth retained significant ownership after the 2026 Summit-led transaction. High SO007, SO009
CO017 Andy Collins and Colin Mistele of Summit Partners joined Keyfactor’s board following the 2026 transaction. High SO007, SO008
CO018 Keyfactor described itself in July 2026 as scaling from a position of accelerating year-over-year revenue growth and strong profitability. High SO007, SO009
CO019 Keyfactor said in July 2026 that it issues and manages billions of machine identities globally each year. High SO007, SO008
CO020 Keyfactor said in July 2026 that it served more than 2,500 customers worldwide. High SO007, SO008, SO009
CO021 Keyfactor said in July 2026 that it supported 50% of the largest banks in the U.S. and Europe. High SO007, SO009
CO022 Keyfactor said in July 2026 that it supported 80% of leading U.S. retailers. High SO007, SO009
CO023 Keyfactor said in July 2026 that it supported more than 40% of Fortune 100 companies. High SO007, SO008
CO024 Keyfactor for Government CLAaaS achieved FedRAMP Moderate authorization in May 2026. High SO012, SO018
CO025 Keyfactor launched the Trust Control Plane on June 9, 2026 as a unified operating model for machine identities and cryptography. Medium SO013
CO026 The Trust Control Plane launch explicitly tied Keyfactor’s platform narrative to AI identity sprawl, shrinking certificate lifespans, and post-quantum migration pressure. High SO013, SO019
CO027 Keyfactor Command is presented as a CA-agnostic control plane for SSH identities, TLS certificates, and client certificates. Medium SO014
CO028 EJBCA Enterprise is built on widely used open-source PKI software and can be deployed in cloud, on-prem, self-managed, or as-a-service modes. Medium SO015, SO020
CO029 SignServer Enterprise centrally governs signing workflows for software, firmware, containers, documents, and ePassports using HSM-backed keys. Medium SO016
CO030 Keyfactor’s managed-cloud portfolio includes Cloud PKI as-a-Service for dedicated single-tenant private PKI operations. Medium SO017
CO031 Public governance disclosures identify investor-appointed directors from Sixth Street and Summit but do not provide a full current board roster or committee structure. Medium SO005, SO006, SO007, SO008
CO032 The Volanoski appointment release said Keyfactor had made strategic acquisitions of InfoSec Global and CipherInsights. Medium SO011
CO033 ServiceNow used Keyfactor EJBCA to issue certificates dynamically across services and workloads and cut dozens of hours of manual engineering effort. Medium SO022
CO034 Siemens said Keyfactor EJBCA reduced PKI deployment time from more than a week to one day. Medium SO021
CO035 OVHcloud said its Keyfactor EJBCA deployment supports 1.5+ million developers globally and more than 10,000 certificates. Medium SO023
CO036 SK ID said it migrated 20 million certificates to Keyfactor EJBCA and reported zero PKI-related incidents since implementation. Medium SO024
CO037 The Netherlands Ministry of Justice and Security said EJBCA has supported more than 15 years of PKI operations across passports, visas, government IT services, and digital health certificates. Medium SO025
CO038 OpenCVE lists historical Keyfactor Command SQL injection and access-control issues as well as multiple SignServer vulnerabilities. Medium SO027
CO039 Keyfactor’s support portal lists a May 2026 EJBCA MPIC compliance issue and several SignServer security advisories. High SO028, SO014
CO040 Keyfactor has not publicly disclosed absolute ARR, revenue, cash, debt, or detailed cap-table terms in the sources reviewed for this chapter. Medium SO007, SO011
CM001 The narrowest defensible core market for Keyfactor is certificate lifecycle management software rather than generic cybersecurity or workforce identity. Medium SM001, SM020
CM002 The CLM market definition used by The Business Research Company includes TLS, code-signing, email, and client certificates. Medium SM001
CM003 TBRC lists finance, healthcare, government, IT/telecom, and manufacturing as major CLM verticals. Medium SM001
CM004 The Business Research Company sizes the certificate lifecycle management software market at $6.19 billion in 2026. Medium SM001
CM005 The Business Research Company projects the certificate lifecycle management software market to reach $11.05 billion by 2030. Medium SM001
CM006 North America was the largest region in the CLM software market in 2025 according to TBRC. Medium SM001
CM007 MarketsandMarkets projects the global PQC market from $0.42 billion in 2025 to $2.84 billion by 2030 at 46.2% CAGR. Medium SM002
CM008 MarketsandMarkets says BFSI will account for the largest PQC vertical share during the forecast period. Medium SM002
CM009 MarketsandMarkets says Europe will grow at the highest CAGR in the PQC market. Medium SM002
CM010 The most commercially relevant market boundary for Keyfactor layers CLM core spend inside broader enterprise PKI and machine identity governance. Medium SM001, SM010, SM020, SM021
CM011 DigiCert says the maximum TLS certificate lifetime falls to 200 days in March 2026, 100 days in March 2027, and 47 days in March 2029. High SM005, SM006, SM007
CM012 DigiCert says domain validation reuse shrinks to 10 days by March 2029 under the new CA/Browser Forum schedule. High SM005, SM007
CM013 CyberArk’s 2025 Identity Security Landscape says there are 82 machine identities for every human in organizations worldwide. High SM003, SM004
CM014 CyberArk says 42% of machine identities have sensitive or privileged access. Medium SM003
CM015 CyberArk says 61% of surveyed organizations lack identity security controls for cloud infrastructure and workloads. Medium SM003
CM016 CyberArk says 87% of surveyed organizations experienced at least two successful identity-centric breaches in the prior 12 months. Medium SM003
CM017 CyberArk says 68% of organizations lack identity security controls for AI. Medium SM003
CM018 Federal News Network reports that the June 2026 executive order requires federal agencies to move key establishment for high-value and high-impact systems to PQC by December 31, 2030. High SM008, SM009
CM019 Federal News Network reports that the same executive order sets a December 31, 2031 deadline for PQC digital signatures. Medium SM008
CM020 Palo Alto Networks argues that the 2026 executive order extends urgency beyond federal agencies into contractors, critical infrastructure, and regulated industries. Medium SM009
CM021 Palo Alto Networks says cryptographic visibility must lead migration planning because inventory alone does not establish post-quantum readiness. Medium SM009
CM022 AppViewX defines machine identity management as governance of digital certificates and keys for devices, workloads, applications, containers, and IoT. Medium SM010
CM023 AppViewX says the machine identity lifecycle includes issuance, inventory, provisioning, monitoring, renewal, and revocation. Medium SM010
CM024 CyberArk positions machine identity security as protection across secrets, certificates, workload identities, and SSH keys rather than certificates alone. Medium SM011
CM025 Keyfactor’s market story extends beyond CLM into trust infrastructure, machine identities, and crypto-agility. High SM016, SM024
CM026 AppViewX describes expired certificates as a common cause of application outages and data breaches. Medium SM010
CM027 ABI Research says competition in enterprise PKI now spans Keyfactor, Entrust, DigiCert, Garantir, Sectigo, AppViewX, CyberArk, GlobalSign, Ascertia, eMudhra, and HID. Medium SM014
CM028 Keyfactor’s 2024 PKI & Digital Trust Report says 80% of respondents are concerned about adapting to cryptography changes. Medium SM015
CM029 The same Keyfactor report says 91% of respondents view PKI management as critical for defending against AI-related threats. Medium SM015
CM030 The same Keyfactor report says 84% of respondents view the growth of cryptographic keys and certificates as an operational headache. Medium SM015
CM031 The 2024 Keyfactor report says 36% of respondents would not start their quantum-readiness journey until after the first release of standards. Medium SM015
CM032 Keyfactor’s Trust Control Plane launch says AI agents, cloud workloads, and connected devices have multiplied machine identities far beyond what teams can track by hand. Medium SM016
CM033 Keyfactor’s government messaging frames zero trust, software supply chain security, and post-quantum requirements as active buyer pressure in the public sector. High SM017, SM018
CM034 The market boundary should exclude pure human IAM or endpoint categories unless they directly control certificates, keys, or machine identities. Medium SM001, SM010, SM011
CM035 The most common status-quo substitutes are spreadsheets, email ticketing, siloed CA consoles, and other manual certificate workflows. Medium SM010, SM017
CM036 Sectigo says the 47-day certificate lifespan makes manual renewals difficult to maintain and increases the importance of automated lifecycle management. High SM006, SM012
CM037 DigiCert positions Trust Lifecycle Manager as a multi-CA visibility, governance, and automation platform rather than a single-CA console. Medium SM013
CM038 The 2024 CyberArk acquisition of Venafi shows continued consolidation between certificate management and broader identity security platforms. High SM022, SM023
CM039 Keyfactor’s Spring 2026 update explicitly tied new product work to shorter certificate lifecycles, stricter validation expectations, and post-quantum urgency. Medium SM019
CM040 Public sources reviewed for this chapter do not provide a precise standalone SAM or SOM estimate for an independent vendor like Keyfactor after bundled-platform overlap is removed. Medium SM001, SM014, SM022, SM023
CP001 ABI Research ranks Keyfactor, Entrust, and DigiCert as the top three leaders in enterprise PKI. Medium SP001
CP002 ABI says Keyfactor secured the top spot because of flexible deployment models, CA agnosticism, PKI-IoT strength, and cryptographic discovery capabilities. Medium SP001
CP003 ABI says Entrust’s differentiation is widespread PKI application support, a large integration portfolio, and strong consultancy services. Medium SP001
CP004 ABI says DigiCert’s DigiCert ONE platform combines public-trust PKI and enterprise PKI with global reach and scalable certificate management. Medium SP001
CP005 ABI says Sectigo follows the top three with competitive automation capabilities rooted in public PKI. Medium SP001
CP006 ABI describes AppViewX as a leader and innovator in CLM and certificate discovery. Medium SP001
CP007 ABI places CyberArk in the mainstream category rather than among the top PKI leaders. Medium SP001
CP008 CyberArk completed the acquisition of Venafi for approximately $1.54 billion in 2024. High SP002, SP003
CP009 CyberArk’s machine identity platform covers secrets, certificates, workload identities, and SSH keys rather than certificate management alone. Medium SP004
CP010 DigiCert Trust Lifecycle Manager emphasizes import from any CA or trust store, discovery across networks, clouds, and endpoints, and policy-driven automation. Medium SP006
CP011 Sectigo positions Certificate Manager as a CA-agnostic, cloud-first CLM platform with 50+ integrations and both public and private certificate coverage. Medium SP008
CP012 HashiCorp Vault PKI issues dynamic X.509 certificates, supports short TTLs and ephemeral certificates, and exposes ACME, EST, CMPv2, and SCEP protocols. Medium SP010
CP013 Smallstep emphasizes hardware-backed, short-lived certificates for devices, workloads, AI agents, and MCP toolchains. Medium SP011
CP014 AWS Private CA provides managed root and subordinate private CA hierarchies for servers, users, devices, containers, and applications. Medium SP012, SP026
CP015 Microsoft AD CS remains a built-in PKI substitute with root and subordinate CAs, web enrollment, NDES, TPM attestation, and ML-DSA support. High SP013, SP025
CP016 ManageEngine Key Manager Plus automates certificate discovery, renewal workflows, and SSH/PGP key management from one interface. Medium SP014
CP017 Keyfactor Command is a CA-agnostic control plane for SSH identities, TLS certificates, and client certificates. Medium SP015
CP018 Keyfactor EJBCA Enterprise combines open-source PKI roots with cloud, on-prem, self-managed, and as-a-service deployment flexibility. Medium SP016
CP019 Keyfactor SignServer Enterprise handles signing for software, firmware, containers, documents, and ePassports. Medium SP017
CP020 Keyfactor offers cloud-delivered private PKI and a FedRAMP-authorized government CLAaaS option in addition to self-managed deployment paths. High SP018, SP019, SP020
CP021 CyberArk/Venafi and DigiCert hold distribution advantages because they can ride broader identity-security or public-CA buying motions. Medium SP002, SP004, SP006, SP008
CP022 HashiCorp Vault, AWS Private CA, and Microsoft AD CS are strongest as substitutes or internal-build anchors rather than full independent trust control planes. Medium SP010, SP012, SP013
CP023 Keyfactor, DigiCert, and Sectigo all market multi-CA or CA-agnostic management, while AWS Private CA and AD CS remain more environment-specific. Medium SP006, SP008, SP012, SP013, SP015
CP024 Switching cost rises materially once discovery, alerting, issuance, and policy governance are integrated across hybrid environments. Medium SP006, SP008, SP015, SP016
CP025 Keyfactor’s core competitive defense is independent breadth across CLM, enterprise PKI, signing, and crypto-agility rather than a single deployment mode or CA channel. Medium SP015, SP016, SP017, SP018, SP021
CP026 HashiCorp Vault and Smallstep appear strongest in developer-centric and short-lived certificate workflows rather than classic enterprise-wide certificate governance. Medium SP010, SP011
CP027 AWS Private CA and AD CS can satisfy meaningful slices of private PKI demand without replacing the need for broad multi-environment discovery and governance. Medium SP012, SP013
CP028 The field is converging because shorter certificate lifetimes and machine identity growth make baseline automation table stakes for every vendor. Medium SP005, SP007, SP009, SP021
CP029 Public pricing remains opaque across most enterprise vendors, pushing buyers into demo-led or negotiated commercial processes. Medium SP006, SP008, SP011, SP015, SP018, SP027
CP030 ManageEngine explicitly offers Key Manager Plus as both SaaS and on-prem software and emphasizes rapid deployment. Medium SP014
CP031 Sectigo uses its own website to claim better value and feature coverage than Venafi, AppViewX, and Keyfactor, but that is vendor-authored positioning rather than independent proof. Medium SP008
CP032 Keyfactor’s public customer proof includes ServiceNow, Siemens, and OVHcloud as enterprise-scale references. Medium SP022, SP023, SP024
CP033 CyberArk’s machine identity page highlights reference organizations including Southwest, Cisco, and DZ Bank. Medium SP004
CP034 Microsoft AD CS remains the most common Windows-native status-quo PKI substitute for enterprises that prefer to extend existing server tooling. Medium SP013, SP025
CP035 As automation becomes mandatory, value shifts away from simple renewal toward discovery, governance, signing, and PQC readiness. Medium SP007, SP009, SP015, SP021
CP036 The Venafi acquisition demonstrates ongoing consolidation between machine identity management and broader identity-security suites. High SP002, SP003
CP037 Despite clear leaders, enterprise PKI remains fragmented enough that buyers still compare direct peers, bundles, substitutes, and internal build paths in the same process. Medium SP001, SP010, SP012, SP013, SP014
CP038 Public sources still do not reveal comparable win rates, discount levels, or renewal economics across the competitor set. Medium SP006, SP008, SP014, SP015
CI001 Keyfactor publicly monetizes a portfolio that spans certificate lifecycle management, enterprise PKI, signing, and managed trust services rather than a single certificate tool. Medium SI011, SI012, SI013, SI014, SI017
CI002 Keyfactor Command is the company’s certificate lifecycle and machine identity control layer. Medium SI011
CI003 EJBCA Enterprise gives Keyfactor a private PKI revenue stream that can be sold as software, self-managed deployment, or service-backed delivery. Medium SI012, SI014
CI004 SignServer Enterprise extends monetization into software, firmware, container, document, and identity-document signing workflows. Medium SI013
CI005 Cloud PKI as-a-Service and the government CLAaaS offering imply recurring managed-service revenue alongside software subscriptions. Medium SI014, SI015, SI016, SI030
CI006 Keyfactor’s February 2026 TEI release says a commissioned Forrester study found 356% ROI and payback in under six months for a modeled enterprise deployment. Medium SI010, SI025, SI026, SI027
CI007 The same TEI release says the composite organization saw $12.7 million in risk-adjusted benefits versus $2.8 million in costs over three years. Medium SI010, SI025, SI026
CI008 Keyfactor’s TEI release says interviewed customers saved up to 12,000 hours on new certificate provisioning, avoided more than 6,600 hours of deployment effort, and reduced certificate-related incidents by 95%. Medium SI010, SI026, SI027
CI009 Keyfactor added a President and CRO in January 2026 with responsibility for sales, marketing, and channel. Medium SI009, SI028, SI029
CI010 Keyfactor said in January 2026 that it had nearly doubled ARR in less than two years. Medium SI009
CI011 The January 2026 CRO appointment release implies Keyfactor was already operating a sizable global commercial footprint, with 540+ employees across 12 countries supporting its growth push. Medium SI009
CI012 Keyfactor’s October 2023 minority investment from Sixth Street valued the company at approximately $1.3 billion. High SI005, SI006
CI013 Keyfactor said in October 2023 that market demand had driven three-year revenue CAGR above 70%. High SI005, SI006
CI014 Keyfactor announced a $1 billion-plus strategic growth investment led by Summit Partners on July 6, 2026. High SI001, SI002, SI003, SI004
CI015 Keyfactor said in July 2026 that it was scaling from a position of financial strength with accelerating year-over-year revenue growth and record profitability. Medium SI001, SI002
CI016 Keyfactor said the 2026 Summit capital would fund product innovation, geographic expansion, team building, and strategic acquisitions. High SI001, SI003, SI004
CI017 Keyfactor’s 2019 growth round with Insight was $77 million. High SI007, SI008
CI018 Keyfactor said in 2019 that revenue had doubled year over year and that it secured more than 500 million certificates for Global 2000 clients. High SI007, SI008
CI019 Across 2019, 2023, and 2026, Keyfactor’s public financing history shows repeat sponsorship from minority growth investors rather than frequent emergency recapitalization. Medium SI001, SI005, SI007
CI020 The reviewed public sources do not disclose Keyfactor’s current ARR, revenue, gross margin, or free cash flow. Medium SI001, SI005, SI009, SI010
CI021 The reviewed public sources do not disclose cash on hand, monthly burn, runway, or customer concentration. Medium SI001, SI005, SI007, SI009
CI022 Keyfactor’s public surface implies an enterprise direct-and-channel go-to-market motion rather than self-serve pricing. Medium SI009, SI011, SI014, SI015, SI028, SI029
CI023 The 2026 CRO appointment suggests Keyfactor is investing in scaled sales execution and partner leverage rather than relying solely on organic inbound demand. Medium SI009
CI024 Keyfactor does not publish a broad public list price for its core platform products in the reviewed sources. Medium SI011, SI012, SI013, SI014, SI015
CI025 Managed deployment, compliance-heavy delivery, and customer success requirements imply service-delivery costs that are not visible in public margin disclosures. Medium SI014, SI015, SI016
CI026 FedRAMP Moderate authorization and the government cloud certificate automation offering likely increase compliance overhead while widening public-sector revenue opportunity. Medium SI015, SI016, SI030
CI027 The 2026 growth investment implies Keyfactor is not obviously capital constrained in the near term. Medium SI001, SI002, SI003, SI004
CI028 Even after the July 2026 transaction, public sources still do not reveal Keyfactor’s cash balance, burn, or runway. Medium SI001, SI002, SI003, SI004
CI029 Strategic acquisitions are an explicit use of funds in 2026, indicating that inorganic growth remains part of the operating plan. High SI001, SI003, SI004
CI030 Board participation from Sixth Street and Summit indicates active sponsor governance around Keyfactor’s next phase of growth. Medium SI001, SI005, SI006
CI031 Keyfactor’s public financial package does not include gross margin, CAC, payback, net retention, or churn, which are core revenue-quality and efficiency inputs. Medium SI001, SI005, SI009, SI010
CI032 Keyfactor’s public disclosures show customer scale moving from more than 1,500 organizations in 2023 to more than 2,500 customers by July 2026. High SI001, SI005, SI006
CI033 The July 2026 claim of record profitability is directionally positive but not quantified in any reviewed public source. Medium SI001, SI002
CI034 The most plausible public reading of Keyfactor’s revenue quality is a subscription-led platform with support and managed-service layers rather than pure one-time license revenue. Medium SI011, SI012, SI013, SI014, SI015
CI035 Keyfactor appears less capital-intensive than hardware or transaction businesses, but compliance, hosting, HSM-backed operations, and support could still weigh on cash conversion. Medium SI014, SI015, SI016, SI017
CI036 Public substitute pricing from AWS Private CA shows that at least part of the broader trust market is benchmarked against transparent infrastructure-native economics rather than opaque enterprise contracts. Medium SI022, SI023
CI037 The TEI study is best treated as buyer-ROI evidence that can support sales efficiency, not as a substitute for direct disclosure of Keyfactor’s own unit economics. Medium SI010, SI031
CI038 Public evidence supports a positive strategic financial verdict for Keyfactor, but a precise underwriting view still depends on management data-room disclosure. Medium SI001, SI005, SI009, SI010, SI021, SI024
CE001 Keyfactor’s public product stack spans Command, EJBCA Enterprise, SignServer Enterprise, cloud-delivered PKI, government delivery, and Trust Control Plane positioning. Medium SE001, SE002, SE003, SE004, SE005, SE006
CE002 Command is Keyfactor’s certificate lifecycle and machine identity operations layer. Medium SE001
CE003 EJBCA Enterprise is Keyfactor’s enterprise private PKI and certificate authority layer. Medium SE002, SE023
CE004 Keyfactor positions EJBCA Enterprise as the production-grade counterpart to the open-source EJBCA community surface. Medium SE002, SE016, SE023
CE005 SignServer Enterprise extends the stack into signing workflows for software, documents, artifacts, and related trust operations. Medium SE003, SE018, SE024
CE006 Keyfactor introduced Trust Control Plane in June 2026 to unify machine identities, cryptographic assets, and trust systems under one control layer. Medium SE006
CE007 SignServer 7.6 adds support for composite certificates, improved CloudHSM handling, and WildFly 39 support. High SE014, SE020
CE008 SignServer 7.6 release notes say the release resolves three security issues later associated with CVE-2026-25825, CVE-2026-25826, and CVE-2026-25827. Medium SE014
CE009 EJBCA Community 9.0 moved to newer WildFly or JBoss EAP prerequisites and Java 17, with Java 21 planned later. Medium SE017
CE010 The EJBCA community repository explicitly says the community edition is not intended for production use and that enterprise deployments require higher-assurance features, certifications, SLAs, and operational assurances. Medium SE016
CE011 The SignServer community repository explicitly says the community edition is not intended for production use and that production deployments require enterprise-grade key management, auditability, compliance capabilities, and support. Medium SE018
CE012 The SignServer community releases page shows a continuing release history and notes product documentation availability on Keyfactor Docs. Medium SE019
CE013 Keyfactor maintains a public security-advisories section that includes 2025 and 2026 EJBCA and SignServer issues. Medium SE013
CE014 OpenCVE lists disclosed Keyfactor-related issues affecting Command, SignServer, EJBCA, and AWS Orchestrator. Medium SE015
CE015 FedRAMP Moderate authorization gives Keyfactor a documented public-sector trust signal for its government cloud automation offering. High SE007, SE022
CE016 The EJBCA community repository exposes multiple adjacent repositories, SDKs, clients, and deployment artifacts, indicating an active practitioner surface around the PKI engine. Medium SE016
CE017 The SignServer community repository exposes discussions, deployment artifacts, and related repositories, indicating a visible practitioner and integration surface around signing workflows. Medium SE018, SE019
CE018 AWS CloudHSM is a visible external dependency in Keyfactor’s signing roadmap because SignServer 7.6 documents improvements for CloudHSM migrations and existing-key use. Medium SE014, SE020
CE019 Public trust controls include FedRAMP messaging, public documentation, public community repositories, and a public advisory process. Medium SE007, SE013, SE014, SE016, SE018
CE020 Keyfactor’s government offering provides a dedicated public-sector deployment path beyond self-managed enterprise PKI. Medium SE005, SE007
CE021 Cloud PKI as-a-Service gives Keyfactor a managed-delivery option in addition to self-managed software deployment. Medium SE004, SE005
CE022 Keyfactor’s partners page and IBM partnership page show that product delivery depends partly on ecosystem and joint-solution motion, not only direct software sales. Medium SE011, SE012
CE023 Customer stories from ServiceNow, Siemens, and OVHcloud show the stack deployed for enterprise-scale digital trust, PKI automation, and sovereign-cloud use cases. Medium SE008, SE009, SE010
CE024 EJBCA.org presents EJBCA as open-source certificate authority software covering the certificate lifecycle and linking to community resources. Medium SE023
CE025 SignServer.org presents SignServer as open-source signing software and a community access point for signing workflows. Medium SE024
CE026 Keyfactor has a visible developer surface through GitHub repositories, release pages, project sites, and documentation rather than a purely closed product surface. Medium SE014, SE016, SE017, SE018, SE019, SE023, SE024, SE026
CE027 A meaningful part of Keyfactor’s product differentiation comes from combining open-source practitioner adoption with commercial enterprise support and managed delivery. Medium SE002, SE003, SE004, SE016, SE018, SE023, SE024
CE028 Keyfactor’s public product record shows real vulnerability-management and compliance obligations rather than a zero-incident marketing posture. Medium SE013, SE014, SE015
CE029 The product family appears mature in core modules but still actively evolving around post-quantum support, SaaS delivery, and unified trust-governance messaging. Medium SE004, SE006, SE014, SE017
CE030 Trust Control Plane shifts the architecture narrative from separate PKI, CLM, and signing tools toward a unified control model. Medium SE006, SE001, SE002, SE003
CE031 The public advisory surface is itself a trust signal because it documents fixes and issue categories in a form operators can act on. Medium SE013, SE014
CE032 A reasonable customer workflow interpretation is discovery, issuance, automation, signing, and ongoing governance rather than one isolated certificate step. Medium SE001, SE002, SE003, SE006, SE008, SE009, SE010
CE033 Quality and compliance controls visible publicly include FedRAMP messaging, production-versus-community boundaries, release notes, and security advisories. Medium SE007, SE013, SE014, SE016, SE018
CE034 Both EJBCA and SignServer community editions are explicitly framed for learning, testing, or prototyping rather than production. High SE016, SE018
CE035 Critical dependencies visible publicly include Java runtimes, application servers, HSMs, cloud integrations, partner ecosystems, and customer deployment environments. Medium SE014, SE016, SE017, SE018, SE020, SE021
CE036 Public evidence does not provide independent uptime, throughput, or implementation-time benchmarks for the full Keyfactor stack. Medium SE001, SE002, SE003, SE006, SE014
CE037 Recent EJBCA and SignServer stack upgrades imply real migration and upgrade burden for customers operating production trust systems. Medium SE014, SE017
CE038 Keyfactor’s public post-quantum direction is credible but still implementation-sensitive because standards migration, HSM support, and mixed classical-plus-PQC environments remain operationally complex. Medium SE014, SE020
CU001 Keyfactor said in July 2026 that it serves more than 2,500 customers worldwide. Medium SU002
CU002 Keyfactor said in July 2026 that it supports over 40% of Fortune 100 companies, 50% of the largest banks in the U.S. and Europe, and 80% of leading U.S. retailers. Medium SU002
CU003 Keyfactor said in October 2023 that more than 1,500 organizations used its platform. Medium SU003
CU004 Keyfactor’s public customer proof spans financial services, software, manufacturing, cloud infrastructure, digital identity, and government. Medium SU005, SU007, SU009, SU011, SU013, SU015, SU017, SU019, SU021, SU022
CU005 ServiceNow represents a large software and platform customer segment for Keyfactor. Medium SU005, SU006
CU006 Siemens and Schneider Electric represent industrial, device-security, and manufacturing-oriented customer segments for Keyfactor. Medium SU007, SU008, SU017, SU018
CU007 OVHcloud and SK ID Solutions represent infrastructure-heavy and digital-identity customer segments for Keyfactor. Medium SU009, SU010, SU011, SU012
CU008 The Netherlands Ministry of Justice and Security represents public-sector identity and document-trust use for Keyfactor. Medium SU013, SU014
CU009 M&T Bank and GRENKE represent financial-services use cases centered on certificate visibility, compliance, and outage prevention. Medium SU015, SU016, SU019, SU020, SU022
CU010 ServiceNow reported millions of certificates issued across services and workloads with 100% API-driven issuance and renewal after moving to Keyfactor EJBCA. Medium SU005
CU011 Siemens reported an 85% reduction in deployment time after adopting Keyfactor EJBCA Enterprise and automating deployment with Red Hat Ansible. Medium SU007
CU012 OVHcloud reported 100% internal PKI control, support for more than 1.5 million developers, and management of more than 10,000 certificates with Keyfactor EJBCA Enterprise. Medium SU009
CU013 SK ID Solutions reported migrating 20 million certificates across more than 20 countries with zero incidents using Keyfactor EJBCA. Medium SU011
CU014 The Netherlands Ministry reported more than 15 years of PKI operations supported by EJBCA and expansion into multiple identity and document workflows. Medium SU013
CU015 GRENKE reported more than 25,000 active certificates managed centrally, provisioning in under five minutes, zero certificate-related outages, and 50% faster deployments with Keyfactor Command. Medium SU015
CU016 Schneider Electric reported a 10x reduction in software-signing cost, an 80% reduction in key-ceremony cost, and support for more than one million signing events annually with Keyfactor. Medium SU017
CU017 M&T Bank reported a 50% reduction in self-signed certificates identified and eliminated, management of more than 350,000 active certificates, and more than ten years of partnership with Keyfactor. Medium SU019
CU018 ServiceNow said Keyfactor removed human dependencies from certificate issuance and renewal and saved dozens of engineering hours through automation. Medium SU005
CU019 OVHcloud said EJBCA aligned with its sovereignty requirements by supporting private infrastructure control together with enterprise support. Medium SU009
CU020 Schneider Electric said Keyfactor replaced siloed firmware and software signing systems with a centralized, standards-based PKI and signing platform. Medium SU017
CU021 M&T Bank said Keyfactor scaled with certificate volume growth from roughly 2,000 to 350,000 certificates while maintaining visibility and control. Medium SU019
CU022 Keyfactor’s public adoption trajectory links customer-base growth to strong enterprise demand, including nearly doubled ARR in less than two years and expansion to 540+ employees across 12 countries. Medium SU004
CU023 The public case studies suggest a land-and-expand motion in which customers start with visibility, PKI modernization, or signing and then broaden into automation, control, and crypto-agility workflows. Medium SU005, SU007, SU009, SU011, SU015, SU017, SU019, SU025
CU024 M&T Bank’s more-than-ten-year relationship and the Netherlands Ministry’s 15-plus years of PKI operations are the clearest public duration signals for customer durability. Medium SU013, SU019
CU025 Several named customers appear deeply embedded in operational workflows, implying meaningful switching cost once discovery, issuance, policy, and trust anchors are centralized. Medium SU005, SU007, SU009, SU015, SU017, SU019
CU026 Public sources do not disclose NRR, GRR, churn, renewal rates, or average contract length for Keyfactor’s customer base. Medium SU001, SU002, SU003, SU004
CU027 Public sources do not disclose customer satisfaction metrics such as NPS or CSAT. Medium SU001, SU002, SU004
CU028 Durability is therefore more inferential than measured in the public record. Medium SU013, SU019, SU001, SU004
CU029 Keyfactor appears to expand with trust complexity, especially where customer needs widen from visibility or PKI modernization into signing, managed delivery, or broader governance. Medium SU005, SU009, SU017, SU021, SU025
CU030 Government, financial-services, and industrial customers suggest Keyfactor is strongest in regulated, high-assurance environments where outages and compliance matter. Medium SU013, SU015, SU017, SU019, SU021, SU022, SU023
CU031 Because public proof skews toward large, reference-grade organizations, customer concentration risk cannot be ruled out from public materials alone. Medium SU002, SU005, SU007, SU009, SU013, SU015, SU017, SU019
CU032 Government and banking segments likely introduce slower, more compliance-heavy procurement than smaller or self-serve software motions. Medium SU013, SU014, SU019, SU020, SU021, SU023
CU033 The public-sector opportunity is strategically important but partly dependent on maintaining certifications such as FedRAMP. Medium SU021, SU023
CU034 Keyfactor’s partner surface suggests some expansion may depend on channels, ecosystems, or joint-solution relationships rather than direct sales alone. Medium SU024
CU035 The customer sample supports enterprise credibility because it includes large software, industrial, banking, infrastructure, digital-identity, and government references rather than one narrow cohort. Medium SU005, SU007, SU009, SU011, SU013, SU015, SU017, SU019
CU036 The public record is better at showing operational wins than at proving renewal quality or concentration safety. Medium SU005, SU007, SU009, SU011, SU013, SU015, SU017, SU019, SU001, SU004
CU037 Managed and government delivery options likely improve expansion potential for customers that do not want to operate PKI infrastructure themselves. Medium SU021, SU023, SU025
CU038 Keyfactor’s customer verdict is positive on production proof and segment quality, but incomplete on retention and concentration because core customer economics remain private. Medium SU002, SU004, SU001, SU024, SU025
CR001 Keyfactor has a visible public vulnerability surface across Command, SignServer, EJBCA, and AWS Orchestrator. High SR005, SR006, SR007, SR008, SR009, SR010
CR002 NVD says Keyfactor Command before 12.5.0 had incorrect access control affecting over-permissioned access tokens. Medium SR007
CR003 NVD says Keyfactor Command 10.5.x and 11.5.x before the fixed versions allowed SQL injection that could result in code execution and privilege escalation. Medium SR008
CR004 NVD says SignServer versions prior to 7.2 had a container startup logic error that could reset access control to allowany on restart. Medium SR009
CR005 NVD says EJBCA before 7.10.0 allowed XSS. Medium SR010
CR006 Keyfactor’s public security-advisories section lists a May 2026 EJBCA MPIC compliance issue and multiple SignServer issues in 2025-2026. Medium SR005
CR007 The existence of public advisories and release notes indicates meaningful mitigation maturity because Keyfactor documents issues and fixes rather than hiding them entirely. Medium SR005, SR011
CR008 Public disclosure of fixes does not eliminate risk because customers still need to patch and upgrade deployed environments. Medium SR005, SR011, SR026, SR027
CR009 FedRAMP Moderate authorization is a strategic asset for Keyfactor but also a regulatory dependency that requires ongoing maintenance. High SR002, SR003, SR004
CR010 Keyfactor’s public privacy policy creates baseline privacy, notice, and data-handling obligations across website and service interactions. Medium SR001
CR011 Keyfactor’s concentration in banking, government, infrastructure, and industrial trust use cases links revenue opportunity to regulated and high-assurance customer expectations. Medium SR013, SR018, SR019, SR020, SR021, SR029, SR030
CR012 The move toward post-quantum migration and shorter certificate lifetimes increases implementation and customer-readiness risk even if it expands demand. Medium SR011, SR012, SR013
CR013 EJBCA and SignServer public release materials show that Java and application-server upgrades are real operational dependencies rather than background implementation details. Medium SR011, SR026, SR027
CR014 CloudHSM and broader HSM environments are a meaningful dependency for signing workflows and migrations. Medium SR011, SR023
CR015 Keyfactor’s community-versus-enterprise boundary reduces support ambiguity for production use, but it also means self-managed customers can still under-resource operational discipline. Medium SR026, SR027
CR016 Public customer proof is concentrated in large reference-grade organizations, so concentration risk cannot be bounded from public sources alone. Medium SR013, SR018, SR019, SR020, SR021, SR022
CR017 Government and large-bank opportunities likely bring longer procurement cycles and higher compliance burden than typical enterprise software sales. Medium SR004, SR021, SR029
CR018 Competitive bundle pressure from CyberArk/Venafi and other broad trust vendors can compress budget and renewal quality for a standalone platform. Medium SR025, SR013
CR019 Public sources do not disclose ARR, NRR, churn, gross margin, cash, or top-customer exposure, creating material model risk. Medium SR013, SR014, SR015, SR022
CR020 Sponsor backing from Insight, Sixth Street, and Summit mitigates near-term financing risk but does not resolve operating-opacity risk. Medium SR013, SR014
CR021 Keyfactor’s partner ecosystem introduces execution and dependency risk because some deployment leverage and market access may depend on channel or integration partners. Medium SR016, SR017
CR022 The January 2026 CRO appointment after the company’s strongest year indicates elevated go-to-market execution expectations during a scaling phase. Medium SR015
CR023 Keyfactor’s 540-plus employees across 12 countries create coordination and compliance complexity even while improving scale. Medium SR015
CR024 Public-sector growth depends partly on sustaining government-ready delivery and authorization posture, not only on having product demand. Medium SR003, SR004, SR029
CR025 Because Keyfactor sells trust infrastructure, a major outage or exploit would have outsized reputational impact versus an ordinary enterprise software incident. Medium SR005, SR006, SR028
CR026 Public materials do not provide independent uptime or reliability benchmarks for the full platform. Medium SR011, SR012, SR022
CR027 Hybrid, multi-CA, and legacy-customer environments make implementation and upgrade complexity a standing operational risk. Medium SR019, SR020, SR021, SR024
CR028 No major public litigation surfaced in the reviewed source set, but the absence of surfaced litigation is not a substitute for legal diligence. Low SR001, SR025
CR029 Customer and operator error remains relevant because the platform frequently enters environments that were already fragmented or manually managed before deployment. Medium SR018, SR019, SR020, SR021
CR030 Recent acquisitions of InfoSec Global and CipherInsights add integration and platform-cohesion risk alongside strategic breadth. Medium SR015
CR031 The core investment risk is a trust contradiction, where product-security, reliability, or compliance problems undermine the company’s own positioning. Medium SR005, SR006, SR007, SR008, SR009, SR010
CR032 Regulated-sector strength improves customer quality but also raises procurement and renewal friction risk. Medium SR004, SR021, SR029, SR030
CR033 Keyfactor’s dependence on banks, government, and industrial trust buyers links part of the growth thesis to policy-sensitive and audit-sensitive sectors. Medium SR013, SR020, SR021, SR029, SR030
CR034 A critical exploited vulnerability, major authorization setback, or flagship-customer loss would be a primary thesis-break trigger. Medium SR005, SR007, SR008, SR009, SR003, SR021
CR035 Investors should treat missing data-room basics on ARR, NRR, margin, and concentration as a kill trigger for premium pricing rather than as a minor diligence inconvenience. Medium SR013, SR014, SR015, SR022
CR036 Deterioration in win rates versus bundled competitors in regulated segments would be an important monitorable signal of competitive risk transmission. Medium SR025, SR013, SR021
CR037 If implementation and support intensity rise faster than product leverage, margin and capital-intensity risk would increase materially. Medium SR015, SR018, SR019, SR021
CR038 If public-sector authorization or partner-backed delivery falters, Keyfactor’s expansion path into regulated segments would weaken. Medium SR003, SR004, SR016, SR017
CR039 The most important unresolved diligence topic is mitigation maturity: incident response, patch adoption, support SLAs, and release-quality governance. Medium SR005, SR011, SR015, SR026, SR027
CR040 Residual investment risk remains moderate-to-high until security execution, customer concentration, and model opacity are verified in diligence. Low SR013, SR015, SR019, SR021, SR031, SR032
CV001 The best public recommendation on Keyfactor is a constructive but conditional invest stance rather than an unconditional buy. Medium SV001, SV005, SV013, SV029, SV030
CV002 The strongest part of the thesis is that Keyfactor sits in a structurally urgent trust-infrastructure category shaped by machine identity growth, certificate-lifetime compression, and post-quantum preparation. Medium SV001, SV002, SV011, SV016
CV003 The second-strongest part of the thesis is the combination of broad product coverage and reference-grade customer proof. Medium SV012, SV015, SV024, SV025, SV026, SV027, SV028
CV004 The strongest anti-thesis is evidence opacity around ARR, retention, margin, concentration, and round structure. Medium SV001, SV005, SV013, SV030
CV005 Bundle pressure and strategic M&A in machine identity create an anti-thesis that a standalone platform could face pricing or exit compression. Medium SV009, SV010, SV017
CV006 A disciplined investor should not pay as if Keyfactor's growth durability and software economics are already proven from public evidence alone. Medium SV001, SV005, SV013, SV029, SV030
CV007 Public evidence supports a premium step-up from the 2023 anchor only if diligence validates current ARR quality, retention, and margin structure. Medium SV005, SV006, SV013, SV014
CV008 If data-room evidence on retention, concentration, or structure disappoints, the right answer could quickly shift from invest to track or pass. Medium SV005, SV009, SV013, SV030
CV009 Round structure matters as much as headline price because preference overhang, dilution, and secondary mix can materially change investor outcomes. Medium SV001, SV005, SV006
CV010 The correct public stance is price-sensitive rather than purely company-quality-sensitive. Medium SV001, SV005, SV013, SV017, SV030
CV011 The best disclosed company-specific valuation anchor is the October 2023 Sixth Street transaction at approximately $1.3 billion enterprise value. High SV005, SV006
CV012 The July 2026 Summit-led transaction indicates a position of strength, not distress financing. Medium SV001, SV002, SV003, SV004
CV013 The 2026 public transaction disclosures do not reveal post-money valuation, primary versus secondary mix, or preference terms. Medium SV001, SV002, SV003, SV004
CV014 The 2026 public narrative includes accelerating year-over-year growth, record profitability, and more than 2,500 customers, which supports a higher-quality story than the 2023 anchor alone. Medium SV001, SV013
CV015 CyberArk’s roughly $1.54 billion acquisition of Venafi is the most directly relevant strategic M&A comparable in this source set. High SV009, SV010
CV016 CompaniesMarketCap says CyberArk’s market capitalization was about $20.63 billion in July 2026. Medium SV017
CV017 CompaniesMarketCap says Okta’s market capitalization was about $24.34 billion in July 2026. Medium SV018
CV018 CompaniesMarketCap says CrowdStrike’s market capitalization was about $190.43 billion in July 2026. Medium SV019
CV019 CompaniesMarketCap says Rubrik’s market capitalization was about $17.31 billion in July 2026. Medium SV020
CV020 CompaniesMarketCap provides larger-platform sentiment references for Palo Alto Networks, Zscaler, and SentinelOne, but those are context comps rather than direct Keyfactor peers. Medium SV021, SV022, SV023
CV021 Public security-market sentiment in July 2026 is strong enough that investors can plausibly support premium software valuations when growth quality is visible. Medium SV017, SV018, SV019, SV020, SV021, SV022, SV023
CV022 Those public comps are still imperfect for Keyfactor because they differ in scale, category mix, disclosure quality, and liquidity. Medium SV017, SV018, SV019, SV020, SV021, SV022, SV023
CV023 The bull case assumes Keyfactor converts trust-control-plane breadth, regulated demand, and existing customer proof into durable high-quality growth. Medium SV001, SV011, SV024, SV025, SV026, SV027, SV028
CV024 The base case assumes Keyfactor remains strategically strong but that public evidence gaps still justify a measured step-up rather than a narrative-driven re-rating. Medium SV005, SV013, SV014, SV029, SV030
CV025 The bear case assumes that hidden metrics reveal weaker retention, heavier services intensity, or higher concentration than sponsor enthusiasm suggests. Medium SV001, SV005, SV009, SV030
CV026 The highest-probability thesis-break events are security trust failure, concentration disappointment, authorization slippage, or materially weak unit economics in diligence. Medium SV009, SV010, SV025, SV029, SV030
CV027 Public evidence supports a wide valuation band rather than a point estimate. Medium SV001, SV005, SV015, SV017, SV018
CV028 Multiple compression risk remains meaningful if Keyfactor proves less scalable or less defensible than public-market enthusiasm for security platforms implies. Medium SV017, SV018, SV019, SV021, SV022, SV023, SV030
CV029 Exit logic is credible because Keyfactor could fit both strategic platform buyers and future sponsor-to-sponsor transactions. Medium SV009, SV010, SV001, SV002, SV005, SV006
CV030 The strategic-exit path is strongest if larger security or identity vendors continue to consolidate machine-identity and trust infrastructure. Medium SV009, SV010, SV011
CV031 The sponsor-to-sponsor path is strongest if the company’s hidden metrics prove cleaner than public evidence can currently show. Medium SV001, SV002, SV005, SV006, SV013
CV032 The right reason to pass would not be that Keyfactor is a weak company, but that price or structure assume a certainty that public evidence does not support. Medium SV001, SV005, SV013, SV030
CV033 Recommendation confidence would improve materially if management disclosed strong ARR growth quality, healthy retention, software-heavy gross margins, and diversified customer exposure. Medium SV013, SV014, SV015, SV026, SV027, SV028, SV030
CV034 Recommendation confidence would fall materially if diligence revealed services-heavy economics, top-customer dependence, or weak win rates versus bundled rivals. Medium SV009, SV010, SV027, SV030
CV035 ABI Research’s leadership ranking supports a moat narrative, but it is not sufficient by itself to justify a premium entry price. Medium SV011
CV036 Security and compliance diligence matter directly to valuation because a trust-infrastructure vendor can lose premium status quickly after a major credibility event. Medium SV009, SV010, SV029, SV030
CV037 If Keyfactor’s 2026 growth investment included heavy preferences or a large secondary component, common-equity upside could be materially less attractive than the headline suggests. Low SV001, SV002, SV005, SV006
CV038 The most important unanswered valuation questions are current ARR, retention quality, gross-margin mix, concentration, and round terms. Medium SV001, SV005, SV013, SV030
CV039 The public case supports investor attention and access, but not blind valuation generosity. Medium SV001, SV005, SV013, SV029, SV030
CV040 On public evidence alone, Keyfactor is better framed as a high-quality but wide-band underwriting opportunity than as a precision-priced deal. Medium SV001, SV005, SV009, SV011, SV013, SV030
Sources
IDPublisherTitleQuote
SO001 Keyfactor Certified Security Solutions Re-Brands As Keyfactor The company, established in 2001 ... has rebranded as Keyfactor.
SO002 Keyfactor Keyfactor Raises $77 Million from Insight Venture Partners Founded in 2001 as Certified Security Solutions (CSS), Keyfactor recently rebranded in November 2018.
SO003 Insight Partners Keyfactor Raises $77 Million from Insight Venture Partners Keyfactor had doubled revenue year-over-year and now secures more than 500 million certificates for Global 2000 clients worldwide.
SO004 FinTech Global Keyfactor raises $77m from Insight Venture, supporting market expansion plans
SO005 Keyfactor Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B Keyfactor ... has secured a significant minority investment from Sixth Street Growth ... at an enterprise value of approximately $1.3 billion.
SO006 Sixth Street Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SO007 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led By Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise The company issues and manages billions of machine identities globally each year, helping more than 2,500 customers worldwide secure and automate trust at scale.
SO008 Summit Partners Building Trust Infrastructure in the AI and Quantum Era: Our Investment in Keyfactor The company manages billions of machine identities each year for more than 2,500 customers, including more than 40% of the Fortune 100.
SO009 The Quantum Insider Keyfactor Announces $1B+ Strategic Growth Investment to Expand Leadership in Securing Post-Quantum Enterprise
SO010 The SaaS News Keyfactor Raises $1B+ Growth Capital
SO011 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era Nearly doubled ARR in less than two years ... accelerated global expansion to 540+ employees across 12 countries.
SO012 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization Keyfactor for Government Certificate Lifecycle Automation as a Service (CLAaaS) has achieved Federal Risk and Authorization Management Program (FedRAMP) Moderate authorization.
SO013 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise AI agents, cloud workloads, and connected devices have multiplied machine identities far beyond what any team can track by hand.
SO014 Keyfactor Keyfactor Command Discover, manage, and automate the lifecycle of every machine identity ... all from a single control plane.
SO015 Keyfactor Keyfactor EJBCA Enterprise Powered by the most trusted and widely used open-source PKI, EJBCA Enterprise empowers teams to establish trust with identity-first security for every human and machine.
SO016 Keyfactor Keyfactor SignServer Enterprise SignServer is the signing engine that gives security teams enforced governance over every signing operation across every environment with hardware security module integration.
SO017 Keyfactor Cloud PKI as-a-Service With Keyfactor PKI as a Service, you get a reliable, secure, and highly scalable cloud-hosted PKI solution.
SO018 Keyfactor Keyfactor for Government
SO019 Keyfactor Spring 2026 Platform Update New and evolved features across EJBCA, Command, AgileSec and our Signing products help customers stay ahead of shorter cert lifecycles.
SO020 EJBCA EJBCA - The Open-Source Certificate Authority (CA) 23 years of history ... 3,000 downloads per month.
SO021 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor By automating PKI deployment, Siemens reduced setup time from more than a week to just one day.
SO022 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor Automated workflows eliminate dozens of hours of manual effort.
SO023 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure OVHcloud has gained full visibility and control over tens of thousands of certificates across its global infrastructure.
SO024 Keyfactor SK ID Scales Digital Identity with Zero Incidents Using Keyfactor EJBCA Working with Keyfactor, SK ID successfully migrated 20 million certificates and four core digital identity solutions without disruption.
SO025 Keyfactor Netherlands Ministry of Justice Establishes Scalable PKI with Keyfactor EJBCA Over nearly 15 years, the Ministry of Justice has built a highly reliable and scalable PKI platform using EJBCA.
SO026 ABI Research Keyfactor, Entrust and DigiCert Lead ABI Research's Enterprise PKI Vendor Competitive Ranking In the face of fierce competition, Keyfactor secured the top spot in the competitive assessment.
SO027 OpenCVE Keyfactor CVEs and Security Vulnerabilities Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection.
SO028 Keyfactor Support Security Advisories – Keyfactor Support EJBCA compliance issue: Potential CA/B Forum compliance issue for customers using EJBCA ACME and MPIC functionality.
SM001 The Business Research Company Global Certificate Lifecycle Management Software Market Report 2026 The certificate lifecycle management software market size has grown ... to $6.19 billion in 2026.
SM002 MarketsandMarkets Post-quantum Cryptography (PQC) Market worth $2.84 billion by 2030 The global post-quantum cryptography market size is projected to grow from USD 0.42 billion in 2025 to USD 2.84 billion by 2030.
SM003 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1 There are 82 machine identities for every human in organizations worldwide.
SM004 VentureBeat Machine identities outnumber humans 82 to 1 and legacy IAM can't keep up
SM005 DigiCert TLS Certificate Lifetimes Will Officially Reduce to 47 Days
SM006 Sectigo CA/Browser Forum Cuts SSL/TLS Certificate Lifespan to 47 Days
SM007 GlobalSign A Complete 47-day SSL/TLS Certificate Validity Q&A
SM008 Federal News Network White House PQC order ‘lights a fire’ under post-quantum transition The order requires agencies to transition high value assets and high impact systems to post-quantum cryptographic keys by Dec. 31, 2030.
SM009 Palo Alto Networks New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset
SM010 AppViewX Machine Identity Management | How Machine Identity Works Machine identity management is the process of governing and orchestrating the identities – digital certificates and keys – of machines.
SM011 CyberArk Machine Identity Security
SM012 Sectigo Certificate Lifecycle Management Platform Sectigo Certificate Manager delivers complete Certificate Lifecycle Management in one CA agnostic platform.
SM013 DigiCert Trust Lifecycle Manager Control every certificate, intelligently.
SM014 ABI Research Keyfactor, Entrust and DigiCert Lead ABI Research's Enterprise PKI Vendor Competitive Ranking
SM015 Keyfactor 2024 PKI & Digital Trust Report 80% say they are concerned about their ability to adapt to cryptography changes.
SM016 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SM017 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SM018 Keyfactor Keyfactor for Government
SM019 Keyfactor Spring 2026 Platform Update
SM020 Keyfactor Keyfactor Command
SM021 Keyfactor Keyfactor EJBCA Enterprise
SM022 CyberArk CyberArk Completes Acquisition of Machine Identity Management Leader Venafi
SM023 U.S. Securities and Exchange Commission CyberArk Software Ltd. Form 6-K regarding Venafi acquisition
SM024 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led By Summit Partners
SM025 Keyfactor Keyfactor for Government Certificate Lifecycle Automation as a Service
SP001 ABI Research Keyfactor, Entrust and DigiCert Lead ABI Research's Enterprise PKI Vendor Competitive Ranking
SP002 CyberArk CyberArk Completes Acquisition of Machine Identity Management Leader Venafi
SP003 U.S. Securities and Exchange Commission CyberArk Software Ltd. Form 6-K regarding Venafi acquisition
SP004 CyberArk Machine Identity Security
SP005 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1
SP006 DigiCert Trust Lifecycle Manager
SP007 DigiCert TLS Certificate Lifetimes Will Officially Reduce to 47 Days
SP008 Sectigo Certificate Lifecycle Management Platform
SP009 Sectigo CA/Browser Forum Cuts SSL/TLS Certificate Lifespan to 47 Days
SP010 HashiCorp PKI secrets engine | Vault
SP011 Smallstep The World's First Device Identity Platform
SP012 Amazon Web Services Cloud CA Service - AWS Private CA
SP013 Microsoft What is Active Directory Certificate Services in Windows Server?
SP014 ManageEngine Certificate Life Cycle Management Solution | Key Manager Plus
SP015 Keyfactor Keyfactor Command
SP016 Keyfactor Keyfactor EJBCA Enterprise
SP017 Keyfactor Keyfactor SignServer Enterprise
SP018 Keyfactor Cloud PKI as-a-Service
SP019 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SP020 Keyfactor Keyfactor for Government
SP021 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SP022 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SP023 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SP024 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure
SP025 Microsoft What is Network Device Enrollment Service for Active Directory Certificate Services?
SP026 Amazon Web Services What is AWS Private CA?
SP027 Amazon Web Services AWS Private CA Pricing
SI001 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise
SI002 Summit Partners Building Trust Infrastructure in the AI and Quantum Era: Our Investment in Keyfactor
SI003 The Quantum Insider Keyfactor Raises $1B+ Growth Capital
SI004 The SaaS News Keyfactor Raises $1B+ Growth Capital
SI005 Keyfactor Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SI006 Sixth Street Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SI007 Keyfactor Keyfactor Raises $77 Million from Insight Venture Partners
SI008 Insight Partners Keyfactor Raises $77 Million from Insight Venture Partners
SI009 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era
SI010 Keyfactor Total Economic Impact Study Finds Keyfactor Delivered 356% ROI and $12.7 Million in Benefits Over Three Years for Enterprises, with Payback in Under Six Months
SI011 Keyfactor Keyfactor Command
SI012 Keyfactor Keyfactor EJBCA Enterprise
SI013 Keyfactor Keyfactor SignServer Enterprise
SI014 Keyfactor Cloud PKI as-a-Service
SI015 Keyfactor Keyfactor for Government
SI016 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SI017 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SI018 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SI019 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SI020 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure
SI021 U.S. Securities and Exchange Commission CyberArk Software Ltd. Form 6-K regarding Venafi acquisition
SI022 Amazon Web Services AWS Private CA Pricing
SI023 Amazon Web Services What is AWS Private CA?
SI024 ABI Research Keyfactor, Entrust and DigiCert Lead ABI Research's Enterprise PKI Vendor Competitive Ranking
SI025 Keyfactor Calculate Your PKI Costs & ROI Potential
SI026 Keyfactor 5 Numbers from the Forrester TEI That Should Change How You Think About PKI
SI027 Keyfactor What Forrester Found When They Interviewed 5 Keyfactor Customers
SI028 Keyfactor Partners
SI029 Keyfactor IBM + Keyfactor
SI030 Keyfactor Financial Services
SI031 Keyfactor How PKI Solutions Help Support Business Continuity
SE001 Keyfactor Keyfactor Command
SE002 Keyfactor Keyfactor EJBCA Enterprise
SE003 Keyfactor Keyfactor SignServer Enterprise
SE004 Keyfactor Cloud PKI as-a-Service
SE005 Keyfactor Keyfactor for Government
SE006 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SE007 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SE008 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SE009 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SE010 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure
SE011 Keyfactor Partners
SE012 Keyfactor IBM + Keyfactor
SE013 Keyfactor Support Security Advisories
SE014 Keyfactor Docs SignServer 7.6 Release Notes
SE015 OpenCVE Keyfactor vendor CVE index
SE016 GitHub Keyfactor/ejbca-ce
SE017 GitHub Releases · Keyfactor/ejbca-ce
SE018 GitHub Keyfactor/signserver-ce
SE019 GitHub Releases · Keyfactor/signserver-ce
SE020 Amazon Web Services What is AWS CloudHSM?
SE021 Microsoft What is Active Directory Certificate Services in Windows Server?
SE022 FedRAMP Marketplace FR2335051964 product listing
SE023 EJBCA.org EJBCA - The Open-Source Certificate Authority (CA)
SE024 SignServer.org SignServer: Open-Source Signing Software
SE025 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era
SE026 SourceForge EJBCA, JEE PKI Certificate Authority
SU001 Keyfactor Customers | Keyfactor
SU002 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise
SU003 Keyfactor Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SU004 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era
SU005 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SU006 ServiceNow ServiceNow - Put AI to Work
SU007 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SU008 Siemens Company
SU009 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure
SU010 OVHcloud OVHcloud customer
SU011 Keyfactor SK ID Scales Digital Identity with Zero Incidents Using Keyfactor EJBCA
SU012 SK ID Solutions SK ID Solutions | International e-identity solutions since 2001
SU013 Keyfactor Netherlands Ministry of Justice Establishes Scalable PKI with Keyfactor EJBCA
SU014 Government of the Netherlands Ministry of Justice and Security | Government.nl
SU015 Keyfactor GRENKE Streamlines Certificate Management and Eliminates Outages with Keyfactor Command
SU016 GRENKE The grenke Group
SU017 Keyfactor Schneider Electric Secures Device and Software Trust at Global Scale
SU018 Schneider Electric Schneider Electric Global | Your Energy Technology Partner
SU019 Keyfactor M&T Bank Achieves Full Certificate Visibility with Cloud-Based PKI
SU020 M&T Bank Personal Banking | M&T Bank
SU021 Keyfactor Keyfactor for Government
SU022 Keyfactor Financial Services
SU023 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SU024 Keyfactor Partners
SU025 Keyfactor Cloud PKI as-a-Service
SR001 Keyfactor Privacy Policy
SR002 FedRAMP Marketplace FR2335051964 product listing
SR003 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SR004 Keyfactor Keyfactor for Government
SR005 Keyfactor Support Security Advisories
SR006 OpenCVE Keyfactor vendor CVE index
SR007 NIST National Vulnerability Database NVD - CVE-2024-49202
SR008 NIST National Vulnerability Database NVD - CVE-2024-33872
SR009 NIST National Vulnerability Database NVD - CVE-2025-26787
SR010 NIST National Vulnerability Database NVD - CVE-2022-42954
SR011 Keyfactor Docs SignServer 7.6 Release Notes
SR012 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SR013 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise
SR014 Keyfactor Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SR015 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era
SR016 Keyfactor Partners
SR017 Keyfactor IBM + Keyfactor
SR018 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SR019 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SR020 Keyfactor OVHcloud Centralizes PKI to Secure Sovereign Cloud Infrastructure
SR021 Keyfactor M&T Bank Achieves Full Certificate Visibility with Cloud-Based PKI
SR022 Keyfactor Customers | Keyfactor
SR023 Amazon Web Services What is AWS CloudHSM?
SR024 Keyfactor Panel Discussion: Understanding the Implications of Active Directory Certificate Services on PKI
SR025 U.S. Securities and Exchange Commission CyberArk Software Ltd. Form 6-K regarding Venafi acquisition
SR026 GitHub Releases · Keyfactor/ejbca-ce
SR027 GitHub Releases · Keyfactor/signserver-ce
SR028 Keyfactor How PKI Solutions Help Support Business Continuity
SR029 Government of the Netherlands Ministry of Justice and Security | Government.nl
SR030 Schneider Electric Schneider Electric Global | Your Energy Technology Partner
SR031 Keyfactor Security and Compliance at Keyfactor
SR032 Keyfactor 2023 State of IoT Security Report
SV001 Keyfactor Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise
SV002 Summit Partners Building Trust Infrastructure in the AI and Quantum Era: Our Investment in Keyfactor
SV003 The Quantum Insider Keyfactor Raises $1B+ Growth Capital
SV004 The SaaS News Keyfactor Raises $1B+ Growth Capital
SV005 Keyfactor Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SV006 Sixth Street Keyfactor Announces Significant Minority Investment from Sixth Street Growth, Valuing the Company at Approximately $1.3B
SV007 Keyfactor Keyfactor Raises $77 Million from Insight Venture Partners
SV008 Insight Partners Keyfactor Raises $77 Million from Insight Venture Partners
SV009 U.S. Securities and Exchange Commission CyberArk Software Ltd. Form 6-K regarding Venafi acquisition
SV010 CyberArk CyberArk Completes Acquisition of Machine Identity Management Leader Venafi
SV011 ABI Research Keyfactor, Entrust and DigiCert Lead ABI Research's Enterprise PKI Vendor Competitive Ranking
SV012 Keyfactor Customers | Keyfactor
SV013 PR Newswire Keyfactor Appoints Michael Volanoski as President & Chief Revenue Officer to Extend Market Leadership in the AI and Quantum Era
SV014 Keyfactor Total Economic Impact Study Finds Keyfactor Delivered 356% ROI and $12.7 Million in Benefits Over Three Years for Enterprises, with Payback in Under Six Months
SV015 Keyfactor ServiceNow Establishes Digital Trust at Scale with Keyfactor
SV016 Keyfactor Navigating AI Acceleration, Quantum Risk, and Regulatory Volatility
SV017 CompaniesMarketCap CyberArk Software (CYBR) - Market capitalization
SV018 CompaniesMarketCap Okta (OKTA) - Market capitalization
SV019 CompaniesMarketCap CrowdStrike (CRWD) - Market capitalization
SV020 CompaniesMarketCap Rubrik (RBRK) - Market capitalization
SV021 CompaniesMarketCap Palo Alto Networks (PANW) - Market capitalization
SV022 CompaniesMarketCap Zscaler (ZS) - Market capitalization
SV023 CompaniesMarketCap SentinelOne (S) - Market capitalization
SV024 Keyfactor Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise
SV025 Keyfactor Keyfactor Attains FedRAMP Moderate Authorization
SV026 Keyfactor Siemens Automates PKI Deployment to Enable Zero Trust with Keyfactor
SV027 Keyfactor M&T Bank Achieves Full Certificate Visibility with Cloud-Based PKI
SV028 Keyfactor Schneider Electric Secures Device and Software Trust at Global Scale
SV029 Keyfactor Security and Compliance at Keyfactor
SV030 Keyfactor Privacy Policy