Secure Your Network with Keytos Shield
Overview - What is Keytos Shield Network Security?
Keytos Shield provides a zero trust networking solution which allows you to issue passwordless identities via ACME & SCEP, and to use those identities for secure network authentication via the RADIUS protocol. Keytos Shield manages all of the cloud PKI and cloud RADIUS services, without any servers or infrastructure for you to manage.
Do I Need an Existing PKI to Use Keytos Shield?
No. Keytos Shield provides a fully managed cloud PKI, so you do not need to have an existing PKI infrastructure. You can start issuing and managing passwordless identities for your network authentication directly through Keytos Shield. However, if you already have an existing PKI, you can either chain your Shield Issuing CA to your existing PKI or trust your existing PKI directly in your RADIUS policies to enable seamless integration with your existing network security setup.
Do I Need to Run Any Servers, VMs, or Containers for Keytos Shield?
No. Keytos Shield is a fully managed cloud service, so you do not need to run any servers, virtual machines, or containers to use its network security features. All of the necessary infrastructure for cloud PKI and cloud RADIUS is handled by Keytos Shield, allowing you to focus on securing your network without the overhead of managing additional hardware or software.
If you want to run your own local RADIUS server alongside Keytos Shield, you can optionally set this up at no extra cost.
Does Keytos Shield Network Security Help Me Meet CMMC Requirements?
Yes. Keytos Shield helps organizations implement many of the identity, authentication, PKI, and secure network access controls required for CMMC Level 2. By combining cloud PKI, certificate-based authentication, and RADIUS-based network access control, Shield helps ensure that only authorized users and devices can access corporate networks and systems.
While no single product delivers full CMMC compliance, Keytos Shield supports key requirements across Access Control (AC), Identification & Authentication (IA), and System & Communications Protection (SC) by enabling phishing-resistant MFA, device authentication, WPA Enterprise access, and certificate-based security.
| CMMC Requirement | How Keytos Shield Helps |
|---|---|
| Unique user & device authentication | Issues and manages certificate-based identities for users and devices, instead of shared passwords and shared accounts. |
| Multi-factor authentication (MFA) | Issues and manages certificate-based identities that can be used for multi-factor authentication. |
| Secure Wi-Fi & VPN access | Enables RADIUS and EAP-TLS authentication for network access control. |
| PKI requirements | Provides cloud-based certificate issuance and lifecycle management. |
| Encryption & secure communications | Supports certificate-driven authentication and secure connectivity. |
Note: Keytos Shield is one component of a CMMC program and is typically used alongside Microsoft Entra ID, Intune, and broader security controls and processes
Check out our CMMC blog post for more details on how Keytos Shield supports CMMC compliance.