What is cloud PKI?
Cloud PKI (also called PKI as a service, or PKIaaS) is a public key infrastructure (PKI) that is hosted and managed in the cloud. It issues, renews, and revokes digital certificates without on-premise servers.
PKI is a system that creates and manages digital certificates. A digital certificate is a file that proves the identity of a user or device. When a device connects to a network, the certificate confirms who or what is connecting.
How cloud PKI works
Cloud PKI has three core parts. A certificate authority (CA) issues digital certificates. A registration authority verifies identity before users or devices receive a certificate.
The certificate lifecycle covers issuing, distributing, renewing, and revoking certificates.
In the cloud model, the provider hosts the CA and automates the entire lifecycle. Users and devices receive certificates automatically without manual steps.
These certificates authenticate to networks using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) with 802.1X. Learn more about cloud-ready 802.1X authentication. You can also explore certificate-based authentication methods.
Cloud PKI vs. on-premise PKI
On-premise PKI means running and maintaining your own CA, hardware, and staff. Cloud PKI shifts that responsibility to a managed provider.
| Factor | On-premise PKI | Cloud PKI |
|---|---|---|
| Hosting | Self-managed servers | Provider-managed cloud |
| Maintenance | Internal IT handles updates | Provider handles updates |
| Scaling | Requires hardware investment | Scales on demand |
| Staffing | Dedicated PKI expertise needed | Minimal internal resources |
Managing certificates in-house is demanding, and mistakes are costly. A DigiCert survey found that certificate-related downtime hit many organizations: "Nearly half of all enterprises surveyed experienced downtime due to certificate-related incidents in the past year—resulting in significant financial losses, service disruptions, and reputational harm."
Certificate volumes are also rising. The Keyfactor 2024 PKI report found that "More organizations than ever feel they are deploying more certificates than ever – 91% compared to 74% in 2023 and 61% in 2021." This data comes from the Keyfactor 2024 PKI & Digital Trust Report.
Benefits and use cases
Cloud PKI offers practical advantages for network access teams:
- No hardware to maintain: The provider runs the CA and hardware security module (HSM) infrastructure.
- Automatic certificate lifecycle: Certificates issue, renew, and revoke without manual intervention.
- Scales across sites and devices: Add locations or devices without new infrastructure.
- Passwordless, phishing-resistant authentication: Certificates replace passwords that can be stolen or phished.
- Supports Zero Trust: Certificate-based identity fits Zero Trust architecture by verifying every connection.
Common use cases include securing Wi-Fi and network access for employees, bring your own device (BYOD) users, and Internet of Things (IoT) devices via EAP-TLS. Cloud PKI also replaces legacy on-premise PKI systems.
Cloudi-Fi's Cloud NAC includes an integrated cloud PKI. Teams can issue and manage certificates for EAP-TLS without running a separate on-premise PKI.
Automation is becoming more important industry-wide. According to shrinking TLS certificate lifespans, the CA/Browser Forum voted that "As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days."
This rule applies to publicly trusted TLS certificates, not internal EAP-TLS or Wi-Fi certificates. Still, it reflects broader industry pressure toward automated certificate management.
FAQ
Is cloud PKI the same as PKI as a service?
Yes. Cloud PKI and PKI as a service (PKIaaS) refer to the same model: a provider hosts and manages the PKI infrastructure in the cloud.
Is cloud PKI secure?
Cloud PKI providers use hardware security modules (HSMs) to protect private keys and follow industry security standards. The cloud model removes the risk of misconfigured on-premise servers.
Does cloud PKI replace on-premise PKI?
Cloud PKI can replace on-premise PKI for many use cases, especially certificate-based network authentication. Some organizations run both during migration.
Final thoughts
Cloud PKI makes certificate-based trust scalable without on-premise burden. For network access, it powers EAP-TLS authentication across users and devices.







