Context

The National Public Key Infrastructure (PKI), providing trust services (digital signatures, authentication and timestamping) for government and regulated industries, required comprehensive modernisation. The system lacked documented processes and asset inventory, had no formal Business Impact Analysis (BIA) or Business Continuity Plan (BCP), and suffered from critical architectural flaws that threatened service availability and disaster recovery capability.

Outcome

Full asset and process inventory established; BIA performed; BCP developed and operationalised.

Phased, component-by-component migration to new hardware executed with zero service disruption.

Service-Oriented (SOA) and multi-data-centre (Multi-DC) architecture implemented — ensuring high availability and fault tolerance across all components.

Service as Code (SaC), Configuration as Code (CaC) and Disaster Recovery as Code (DRaC) principles embedded — enabling rapid deployment and reliable recovery of core services.

Strict segregation of duties established across CA, VA, RA, KA, TSA, MSSP and RSSP — meeting eIDAS and national trust-service regulatory requirements.

Modernised national trust infrastructure with documented resilience, automated recovery and regulatory-aligned role separation — ensuring continued trust services for government and industry.

Frameworks referenced in this engagement:
  • eIDAS
  • ISO/IEC 27001
  • ISO 22301

01 Management System Assurance

Independent audit of QMS, ITSM, BCMS and ISMS against agreed criteria. Implementation and remediation support is available as a separate advisory engagement, with independence safeguards.

All services →