DARZ Managed PKI & CLM – All Plans at a Glance
Start for free, scale flexibly!
Get your PKI ready for the quantum computing era. Quantum computers will make classical algorithms such as RSA and EC vulnerable in the long term. With the PQC Upgrade Package, your certificates are prepared for this shift today.
ML-DSASLH-DSAOwn PQC Root CAsPQC HSM Configuration included
Ideal for getting started: up to 50 active certificates, core PKI & CLM features, and no setup fees.
FREE Highlights:
- For up to 50 active certificates Only issued certificates that are neither expired nor revoked are counted. Imported certificates are not counted.
- Import an unlimited number of your own public and private certificates
- Flexible Certificate Lifecycle Management (CLM) Centralized management, monitoring, issuance, renewal, and revocation of certificates, including reporting, role and access management, and policies.
- Certificate Discovery Automatic identification and monitoring of server certificates on the network.
- Flexible Notification System Configure alerts for upcoming expiration dates and compliance issues.
- Automation with ACME, EST, SCEP & CMP Established PKI protocols for automated certificate issuance and management.
- Automation via REST API & CLI Enables automated certificate management via REST API or command line.
- Private CA Integration with MTG CARA MTG CARA is connected to the Certificate Lifecycle Manager as a private Certification Authority.
- Microsoft AD CS Integration Integration of Microsoft AD CS with the CLM.
- One Root CA for RSA or EC
- Own Sub-CA
- RSA and EC Cryptography Support for classical RSA methods and elliptic curve cryptography.
- Hosting on Shared, High-Availability Infrastructure Operation on a shared, high-availability infrastructure with logically separated customer environments.
- OCSP & HTTP CRLs OCSP enables online certificate revocation status checks. HTTP CRLs provide certificate revocation lists over HTTP.
- Self-Service Support Extensive online resources for direct support, including videos, guides, online documentation, and frequently asked questions (FAQs).
For growing certificate environments with greater automation, scalability, high availability, and support needs.
BUSINESS Highlights:
- All FREE Features
- Up to 10,000 active certificates
- Flexible 500-certificate pricing tiers The number of active certificates can be increased flexibly in increments of 500 certificates.
- Microsoft Active Directory & Autoenrollment Automatic certificate issuance via Microsoft Active Directory using the Autoenrollment Connector.
- Additional Sub-CAs at no extra cost
- Highly Available, Geo-Redundant Infrastructure Operated across two geo-redundant data centers in Darmstadt and Frankfurt with 99.98% availability. A dedicated namespace and database are provided for each customer.
- Dedicated HSM Partition for CA Keys CA keys are stored in a PQC-capable shared HSM infrastructure with a dedicated, cryptographically isolated HSM partition for each customer.
- 24/7 Hotline & Ticket Support
Optional features:
- PQC Upgrade Package Support for ML-DSA and SLH-DSA as well as selected future PQC algorithms. A dedicated Root CA is set up for each PQC algorithm used. The PQC license, required Root CAs, and required PQC HSM configuration are included.
- VPN Access – one connection included Secure access via an encrypted VPN connection. Available upon request; one VPN connection is included in the monthly plan price.
- IP-Based Access Control – one IP address included Restricts access to approved IP addresses. One IP address is included when activated.
For large certificate environments with maximum scalability and expanded options for dedicated hardware.
ENTERPRISE Highlights:
- All FREE Features
- All BUSINESS Features
- Unlimited number of active certificates with flexible pricing tiers
- Two Root CAs for RSA and EC
Optionale Features:
- Offline Root CA Optional Root CA operated outside the regular online environment.
- Dedicated HSM Hardware Optional PQC-capable HSM provided exclusively for the customer. Suitable for requirements for a fully dedicated HSM infrastructure and possible migration of key material when changing providers.
- Special Billing Model for IoT Device Manufacturers
Our Offering in Detail
Compare All Plans
| Features | FREE | BUSINESS | ENTERPRISE |
|---|---|---|---|
| Setup & Onboarding Setup and configuration of two MPKI instances for high-availability operation, including HSM integration and a kickoff meeting. Additional use cases and services can be agreed separately. | ❌ | ✅ One-time fee | ✅ One-time fee |
| Certificate Lifecycle Manager (CLM) Management, monitoring, issuance, renewal, and revocation of certificates, plus reporting, role and access management, and policies. Certificate templates for common applications can be configured individually. | ✅ | ✅ | ✅ |
| Import Public Certificates Import and manage an unlimited number of your own active public certificates. | ✅ Unlimited | ✅ Unlimited | ✅ Unlimited |
| Import Private Certificates Import and manage an unlimited number of your own active private certificates. | ✅ Unlimited | ✅ Unlimited | ✅ Unlimited |
| Certificate Discovery Automatic identification and monitoring of server certificates on the network. | ✅ | ✅ | ✅ |
| Issue & Manage Certificates Only active, issued certificates are counted. Certificates are considered active if they are neither expired nor revoked. Imported certificates are not counted. | ✅ Up to 50 active certificates | ✅ Up to 10,000 active certificates, available in flexible 500-certificate pricing tiers | ✅ Unlimited number of active certificates, available in flexible pricing tiers |
| Flexible Notification System Configure alerts for upcoming expiration dates and compliance issues. | ✅ | ✅ | ✅ |
| Automation with ACME, EST, SCEP & CMP Support for established PKI protocols for automation: ACME, EST, SCEP, and CMP. | ✅ | ✅ | ✅ |
| Automation via REST API & CLI Client Enables automated certificate management via REST API or command line. | ✅ | ✅ | ✅ |
| OCSP & HTTP CRLs OCSP enables online certificate revocation status checks. HTTP CRLs provide certificate revocation lists over HTTP. | ✅ | ✅ | ✅ |
| Private CA Integration (MTG CARA) Integration of a private CA using MTG CARA. | ✅ | ✅ | ✅ |
| Microsoft AD CS Integration Integration of Microsoft AD CS with the CLM. | ✅ | ✅ | ✅ |
| Certificate Issuance with Microsoft Active Directory Integration Automatic certificate issuance via Active Directory (AD) using the Autoenrollment Connector. | ❌ | ✅ | ✅ |
| Public CA Integration – GlobalSign A contract with GlobalSign is required. | ✅ | ✅ | ✅ |
| Public CA Integration – PSW GROUP A contract with PSW GROUP is required for certain public certificates from Sectigo. | ✅ | ✅ | ✅ |
| Identity Management via Keycloak & Microsoft AD Synchronization of users and roles between Microsoft Active Directory and MTG CLM via Keycloak. | ✅ | ✅ | ✅ |
| Root CA For many use cases, a single Root CA using one algorithm, e.g., RSA, is sufficient. | ✅ 1 Root CA for RSA or EC | ✅ 1 Root CA for RSA or EC | ✅ 2 Root CAs for RSA and EC |
| Offline Root CA | ❌ | ❌ | ✅ Optional |
| Own Sub-CA A dedicated Sub-CA is provided. | ✅ | ✅ | ✅ |
| Additional Sub-CAs Additional Sub-CAs can be set up as needed at no extra cost. | ❌ | ✅ | ✅ |
| RSA Cryptography Support for multiple RSA key lengths: 2048, 3072, 4096, and 8192 bits. | ✅ | ✅ | ✅ |
| Elliptic Curve Cryptography (EC) Support for NIST and Brainpool curves as well as Ed25519 and Ed448. | ✅ | ✅ | ✅ |
| PQC Upgrade Package NEW Support for ML-DSA and SLH-DSA algorithms and selected future post-quantum cryptography algorithms. For each PQC algorithm used, a dedicated Root CA is set up as part of this solution. The PQC license, required Root CAs, and required PQC HSM configuration are included. | ❌ | ✅ Optional | ✅ Optional |
| Dedicated HSM Partition for CA Keys CA keys are stored in a PQC-capable shared HSM infrastructure. Each customer receives a dedicated, cryptographically isolated HSM partition for its CA keys. | ❌ | ✅ Dedicated per customer | ✅ Dedicated per customer |
| Dedicated HSM Hardware Optional PQC-capable HSM provided exclusively for the customer. Suitable for requirements for a fully dedicated HSM infrastructure and possible migration of key material when changing providers. | ❌ | ❌ | ✅ Optional |
| Infrastructure Hosting (shared) Operation on a shared, high-availability infrastructure with logically separated customer environments. | ✅ | ❌ | ❌ |
| High-Availability Hosting
Shared high-availability infrastructure across two geo-redundant data centers in Darmstadt and Frankfurt with 99.98% availability. - Shared: VMware virtualization, routers & firewalls, Kubernetes cluster, PostgreSQL server infrastructure - Dedicated: namespace per customer, database per customer | ❌ | ✅ | ✅ |
| Public Internet Access | ✅ | ✅ | ✅ |
| VPN Access Secure access via an encrypted VPN connection. Available upon request; one VPN connection is included in the monthly plan price. | ❌ | ✅ Optional, one connection included | ✅ Optional, one connection included |
| IP-Based Access Control Optional access to the systems from approved IP addresses. One IP address is included when activated. | ❌ | ✅ Optional, one IP address included | ✅ Optional, one IP address included |
| Self-Service Support | ✅ | ✅ | ✅ |
| 24/7 Hotline & Ticket Support | ❌ | ✅ | ✅ |
| Contract Term | No minimum term (Provider may terminate with prior notice) | Minimum term: 12 months, then cancelable monthly | Minimum term: 12 months, then cancelable monthly |
PKI for Mid-Sized Businesses
Get started now with DARZ Managed PKI & CLM
Full Control. Less Errors. More Automation.
Whether you want to automate your first certificates or redesign your PKI from the ground up, “DARZ Managed PKI & CLM powered by MTG” makes it easy, secure, and reliable to get started. Our customers value not only our technology and expertise, but above all our dependable collaboration: with direct access to experienced PKI experts – no detours, no obstacles. Personally available, solution-oriented, and there exactly when it matters most.
The ideal way to get started with the FREE plan: Start with no setup fees and manage up to 50 active certificates using core PKI & CLM features. You can import and manage an unlimited number of your own public and private certificates.
The development of quantum computers will make classical algorithms such as RSA and EC insecure in the long term. With DARZ Managed PKI & CLM, based on the MTG PKI, organizations are already prepared for this shift today. With the optional PQC Upgrade Package for BUSINESS and ENTERPRISE, the platform supports ML-DSA, SLH-DSA and selected future PQC algorithms, enabling crypto-agility.
The Securosys HSMs in use can also use the PQC algorithms of the MPKI.
The DARZ Managed PKI & CLM offering combines German technological expertise with highly secure operations in Germany. The PKI & CLM software is provided by MTG, a leading specialist in encryption technologies and PKI. Operations are conducted exclusively in DARZ’s fail-safe, scalable, and multiply certified data centers in Darmstadt and Frankfurt — with full data sovereignty over all keys and data.
MTG CLM makes certificate management simple, transparent, and secure. The interface is deliberately designed to be intuitive and user-friendly, enabling IT teams without specialized PKI expertise to efficiently manage all certificate processes. Whether requesting, renewing, revoking, or reporting, all functions are centrally available and can be automated. This helps prevent errors, reliably meet compliance requirements, and significantly reduce day-to-day dependence on specialized experts.
With automation in MTG CLM, time-consuming and error-prone routine tasks are reliably eliminated. Certificates can be fully automated, from enrollment and renewal to distribution and revocation, whether for servers, network devices, mobile endpoints, or applications. Thanks to support for established PKI protocols (ACME, EST, SCEP, CMP), as well as REST API and CLI, virtually any infrastructure can be integrated.
The result: less effort, reduced risk, greater security, and IT teams can focus on their core responsibilities instead of tracking certificate expirations.
Not every company has in-house PKI expertise, and it doesn’t have to. We work with a partner network of experienced consultants, giving you access to in-depth expertise as needed. From initial preparation and support during implementation and migration to ongoing operational guidance, our experts ensure that projects are delivered faster, more securely, and in full compliance, without the need to build up internal specialist resources.
With “DARZ Managed PKI & CLM powered by MTG”, companies maintain full control over their costs at all times. Getting started is free with the FREE plan. In the BUSINESS plan, you can scale flexibly in increments of 500 certificates, with small price steps up to 10,000 certificates. The ENTERPRISE plan offers flexible pricing tiers for larger certificate volumes.
Full Control. More Automation. Fewer Errors.
PKI Made Easy – Start for Free Today!
We support you every step of the way to your own corporate PKI.