DARZ Managed PKI & CLM – All Plans at a Glance

Start for free, scale flexibly!

PQC Upgrade PackageNEW

Get your PKI ready for the quantum computing era. Quantum computers will make classical algorithms such as RSA and EC vulnerable in the long term. With the PQC Upgrade Package, your certificates are prepared for this shift today.

FREE

Ideal for getting started: up to 50 active certificates, core PKI & CLM features, and no setup fees.

0 €
/ month
FREE Highlights:
Best for Mid-Sized Businesses
BUSINESS

For growing certificate environments with greater automation, scalability, high availability, and support needs.

800 €
/ month
Cost for
BUSINESS Highlights:
Optional features:
PQC Upgrade PackageNEW ML-DSA & SLH-DSA, own PQC Root CAs, license and HSM configuration included.
ENTERPRISE

For large certificate environments with maximum scalability and expanded options for dedicated hardware.

Custom quote upon request
ENTERPRISE Highlights:
Optionale Features:
PQC Upgrade PackageNEW ML-DSA & SLH-DSA, own PQC Root CAs, license and HSM configuration included. Can be combined with PQC-capable Dedicated HSM Hardware.

Our Offering in Detail

Compare All Plans

FeaturesFREEBUSINESSENTERPRISE
Setup & Onboarding Setup and configuration of two MPKI instances for high-availability operation, including HSM integration and a kickoff meeting. Additional use cases and services can be agreed separately. ❌✅ One-time fee✅ One-time fee
Certificate Lifecycle Manager (CLM) Management, monitoring, issuance, renewal, and revocation of certificates, plus reporting, role and access management, and policies. Certificate templates for common applications can be configured individually. ✅✅✅
Import Public Certificates Import and manage an unlimited number of your own active public certificates. ✅ Unlimited✅ Unlimited✅ Unlimited
Import Private Certificates Import and manage an unlimited number of your own active private certificates. ✅ Unlimited✅ Unlimited✅ Unlimited
Certificate Discovery Automatic identification and monitoring of server certificates on the network. ✅✅✅
Issue & Manage Certificates Only active, issued certificates are counted. Certificates are considered active if they are neither expired nor revoked. Imported certificates are not counted. ✅ Up to 50 active certificates ✅ Up to 10,000 active certificates, available in flexible 500-certificate pricing tiers✅ Unlimited number of active certificates, available in flexible pricing tiers
Flexible Notification System Configure alerts for upcoming expiration dates and compliance issues. ✅✅✅
Automation with ACME, EST, SCEP & CMP Support for established PKI protocols for automation: ACME, EST, SCEP, and CMP. ✅✅✅
Automation via REST API & CLI Client Enables automated certificate management via REST API or command line. ✅✅✅
OCSP & HTTP CRLs OCSP enables online certificate revocation status checks. HTTP CRLs provide certificate revocation lists over HTTP. ✅✅✅
Private CA Integration (MTG CARA) Integration of a private CA using MTG CARA. ✅✅✅
Microsoft AD CS Integration Integration of Microsoft AD CS with the CLM. ✅✅✅
Certificate Issuance with Microsoft Active Directory Integration Automatic certificate issuance via Active Directory (AD) using the Autoenrollment Connector. ❌✅✅
Public CA Integration – GlobalSign A contract with GlobalSign is required. ✅✅✅
Public CA Integration – PSW GROUP A contract with PSW GROUP is required for certain public certificates from Sectigo. ✅✅✅
Identity Management via Keycloak & Microsoft AD Synchronization of users and roles between Microsoft Active Directory and MTG CLM via Keycloak. ✅✅✅
Root CA For many use cases, a single Root CA using one algorithm, e.g., RSA, is sufficient. ✅ 1 Root CA for RSA or EC✅ 1 Root CA for RSA or EC✅ 2 Root CAs for RSA and EC
Offline Root CA❌❌✅ Optional
Own Sub-CA A dedicated Sub-CA is provided. ✅✅✅
Additional Sub-CAs Additional Sub-CAs can be set up as needed at no extra cost. ❌✅✅
RSA Cryptography Support for multiple RSA key lengths: 2048, 3072, 4096, and 8192 bits. ✅✅✅
Elliptic Curve Cryptography (EC) Support for NIST and Brainpool curves as well as Ed25519 and Ed448. ✅✅✅
PQC Upgrade Package NEW Support for ML-DSA and SLH-DSA algorithms and selected future post-quantum cryptography algorithms. For each PQC algorithm used, a dedicated Root CA is set up as part of this solution. The PQC license, required Root CAs, and required PQC HSM configuration are included. ❌✅ Optional✅ Optional
Dedicated HSM Partition for CA Keys CA keys are stored in a PQC-capable shared HSM infrastructure. Each customer receives a dedicated, cryptographically isolated HSM partition for its CA keys. ❌✅ Dedicated per customer✅ Dedicated per customer
Dedicated HSM Hardware Optional PQC-capable HSM provided exclusively for the customer. Suitable for requirements for a fully dedicated HSM infrastructure and possible migration of key material when changing providers. ❌❌✅ Optional
Infrastructure Hosting (shared) Operation on a shared, high-availability infrastructure with logically separated customer environments. ✅❌❌
High-Availability Hosting Shared high-availability infrastructure across two geo-redundant data centers in Darmstadt and Frankfurt with 99.98% availability.
- Shared: VMware virtualization, routers & firewalls, Kubernetes cluster, PostgreSQL server infrastructure
- Dedicated: namespace per customer, database per customer
❌✅✅
Public Internet Access✅✅✅
VPN Access Secure access via an encrypted VPN connection. Available upon request; one VPN connection is included in the monthly plan price. ❌✅ Optional, one connection included✅ Optional, one connection included
IP-Based Access Control Optional access to the systems from approved IP addresses. One IP address is included when activated. ❌✅ Optional, one IP address included✅ Optional, one IP address included
Self-Service Support✅✅✅
24/7 Hotline & Ticket Support❌✅✅
Contract TermNo minimum term
(Provider may terminate with prior notice)
Minimum term: 12 months, then cancelable monthlyMinimum term: 12 months, then cancelable monthly
FREE
0 € / month
BUSINESS
from 800 € / month
ENTERPRISE
Custom quote

PKI for Mid-Sized Businesses

Get started now with DARZ Managed PKI & CLM

Full Control. Less Errors. More Automation.

Whether you want to automate your first certificates or redesign your PKI from the ground up, “DARZ Managed PKI & CLM powered by MTG” makes it easy, secure, and reliable to get started. Our customers value not only our technology and expertise, but above all our dependable collaboration: with direct access to experienced PKI experts – no detours, no obstacles. Personally available, solution-oriented, and there exactly when it matters most.

The ideal way to get started with the FREE plan: Start with no setup fees and manage up to 50 active certificates using core PKI & CLM features. You can import and manage an unlimited number of your own public and private certificates.

The development of quantum computers will make classical algorithms such as RSA and EC insecure in the long term. With DARZ Managed PKI & CLM, based on the MTG PKI, organizations are already prepared for this shift today. With the optional PQC Upgrade Package for BUSINESS and ENTERPRISE, the platform supports ML-DSA, SLH-DSA and selected future PQC algorithms, enabling crypto-agility.

The Securosys HSMs in use can also use the PQC algorithms of the MPKI.

Request a PQC consultation

The DARZ Managed PKI & CLM offering combines German technological expertise with highly secure operations in Germany. The PKI & CLM software is provided by MTG, a leading specialist in encryption technologies and PKI. Operations are conducted exclusively in DARZ’s fail-safe, scalable, and multiply certified data centers in Darmstadt and Frankfurt — with full data sovereignty over all keys and data.

MTG CLM makes certificate management simple, transparent, and secure. The interface is deliberately designed to be intuitive and user-friendly, enabling IT teams without specialized PKI expertise to efficiently manage all certificate processes. Whether requesting, renewing, revoking, or reporting,  all functions are centrally available and can be automated. This helps prevent errors, reliably meet compliance requirements, and significantly reduce day-to-day dependence on specialized experts.

With automation in MTG CLM, time-consuming and error-prone routine tasks are reliably eliminated. Certificates can be fully automated, from enrollment and renewal to distribution and revocation, whether for servers, network devices, mobile endpoints, or applications. Thanks to support for established PKI protocols (ACME, EST, SCEP, CMP), as well as REST API and CLI, virtually any infrastructure can be integrated.

The result: less effort, reduced risk, greater security, and IT teams can focus on their core responsibilities instead of tracking certificate expirations.

Not every company has in-house PKI expertise, and it doesn’t have to. We work with a partner network of experienced consultants, giving you access to in-depth expertise as needed. From initial preparation and support during implementation and migration to ongoing operational guidance, our experts ensure that projects are delivered faster, more securely, and in full compliance, without the need to build up internal specialist resources.

With “DARZ Managed PKI & CLM powered by MTG”, companies maintain full control over their costs at all times. Getting started is free with the FREE plan. In the BUSINESS plan, you can scale flexibly in increments of 500 certificates, with small price steps up to 10,000 certificates. The ENTERPRISE plan offers flexible pricing tiers for larger certificate volumes.

Full Control. More Automation. Fewer Errors.

PKI Made Easy – Start for Free Today!

We support you every step of the way to your own corporate PKI.

“We support you in the successful implementation of your PKI projects.”