Benefit from the full power of EJBCA Enterprise PKI without the headache of managing the underlying infrastructure. We'll handle everything from HSMs to databases to Kubernetes clusters while you run your enterprise.

To get started, follow the link to sign up. Or if you are already a customer, go directly to the login.

Get started in Azure Get started in AWS 

Complete PKI as a cloud service

Full access to your PKI 

You get full access to EJBCA Enterprise, the most used PKI in the world. 

Up and running in no time

Choose your preferred subscription, leverage the elasticity and global presence of the service as you scale. Scale up at any time to run what you need, when you need it.

Hosted, managed and secure

Reduce the need to manage another critical in-house infrastructure component and get a guaranteed SLA.


The dashboard in the PrimeKey SaaS portal displays PKI health, quantity of certificates generated by profile, and number of issued and expiring certificates. 

Features of EJBCA SaaS

EJBCA SaaS will provide you with the full power of EJBCA Enterprise, but without the need for managing the underlying infrastructure. Sign up and get your instance on AWS and we will make sure that your PKI infrastructure will be managed according to best practices and with the highest assurance. 


No hassle with deployment or maintenance

Take advantage of the latest PKI features without having to handle maintenance or upgrades. The hosted, managed and secure EJBCA Software as a Service provides an unlimited number of CAs, scales with your needs and is available for different sizes and geographies. High availability and redundancy setups are supported. 


Pick your subscription

No need to invest in new hardware or infrastructure. Select the subscription that best suits your needs - and only pay for what you use. Your subscription level can be upgraded on the fly. 


Your choice of HSM

Select the HSM that suits you best. You can choose from AWS Key Management Service (KMS) or AWS Cloud HSM


No vendor lock-in 

All customers have their own dedicated offline root – with full user activation and deactivation control. The AWS accounts holding the keys can be given back to the customer.


Self-service control

With EJBCA SaaS, users manage and control their PKI without the need for support involvement, although the PrimeKey Support team is always available to help. Users have self-service options for features like starting and stopping a dedicated Root CA, adding networks that can access their PKI, and configuring external logging; all from within the PrimeKey SaaS portal.

Related resources

enabling security through PKI
On-demand webinar
Corporate PKI
EJBCA Enterprise
EJBCA Hardware Appliance
EJBCA Software Appliance
PKI migration

Webinar: Own your own risks – Modern manufacturers on-prem security journey to the Cloud

Let us demonstrate together with Thales how manufacturing organizations can benefit from robust and securely built PKI implementations. Date: 12 May Time: 11 AM CET Duration: 1 hour Presented by: Paul Hampton, Cyber Security Specialist, Thales Tom...
PKI in the cloud
Blog post

It is up in the Cloud – the how and why for EJBCA SaaS

The PrimeKey PKI approach continues to evolve as we bring EJBCA as a Service in the Cloud to the market. The longevity and stability earned by PKI is not without its own challenges. PKI has been around a long time, and that's because it is the best te...
person smiling
About PrimeKey
EJBCA Enterprise

PrimeKey Enhances Product Portfolio, Raises Digital Security Standard with EJBCA SaaS

Integrates Public Key Infrastructure (PKI) as-a-service for zero touch, high speed issuing and validation of certificates for business critical applications   San Mateo, California -- -- PrimeKey, a leading open-source identity and digital signing s...

Five models adapted to your needs

EJBCA SaaS is available in different size models ranging from XS, which is designed for non-production environments, to M, with more to come. 


Usecase: Non-Production, PoC/Lab/Dev/Test

SLA: 99%

Certificate capacity: 10 K

Certificate performance capacity with KMS: 10 certificates per second

OCSP performance capacity with KMS: 25 OCSP responses per second

Geographic availability: 1 Region – US or EU or AP, 1 Availability zone

Sign up


Usecase: Small production workloads, Corporate IT workloads

SLA: 99.95%

Certificate capacity: 250 K

Certificate performance capacity with KMS: 25 certificates per second

OCSP performance capacity with KMS: 50 OCSP responses per second

Geographic availability: 1 Region – US or EU or AP, 2 Availability zones

Sign up


Usecase: Typical production workloads, Manufacturing / IIoT, Large corporate IT workloads

SLA: 99.95%

Certificate capacity: 2.5 M

Certificate performance capacity with KMS: 80 certificates per second

OCSP performance capacity with KMS: 100 OCSP responses per second

Geographic availability: 1 Region – US or EU or AP, 2 Availability zones

Sign up


Coming soon.

Reach out for more information. 

Contact us



Coming soon.

Reach out for more information. 

Contact us

It's easy to get started!

You're up and running within 30 minutes. No need to discuss your solution with a sales representative.

1. Sign up

Sign up for your EJBCA SaaS subscription on AWS marketplace.


2. Configure service

Register your account and select EJBCA SaaS configuration details in the PrimeKey SaaS portal.


3. Set up PKI

Set up one or multiple CAs for your certificate services in PrimeKey EJBCA UI.

Need any help?

See our online documentation for quick start guides, how-tos and more. 24/7 support services are included in your subscription. Our skilled PKI professionals in Professional services can support you - on request - with the PKI configuration and integration. 

Read the documentation Contact us 

Customer stories from PKI implementations around the globe

communication tower. cell, radio and television antennas on top

EJBCA Enterprise, Telecom

Powering 5G innovation through security, open standards and flexible integration

Attorneys talking

EJBCA Enterprise, Enterprise, Trust Service Provider

Bundesnotarkammer – Innovation and security in German notaries

DGN Customer Story, PrimeKey

EJBCA Enterprise, Enterprise, Trust Service Provider

Securing and enabling German healthcare


Document signing, EJBCA Enterprise, SignServer Enterprise, Timestamping, Trust Service Provider

The Faroe Islands – Creating a Future-Proof National e-ID

vault and businessman

Bank & Finance, EJBCA Enterprise, Trust Service Provider

Bank-Verlag – Launching an eIDAS-compliant trust center for the German banking industry

EJBCA Telecom

EJBCA Enterprise, PKI migration, Trust Service Provider

Swisscom – Becoming eIDAS compliant and migrating from RSA to EJBCA Enterprise

Contact us

Fill in your contact information below and we will get in touch with you.