How EZCA provides a secure cloud PKI

EZCA eliminates the complexity of creating and managing PKI infrastructure by automating provisioning, management, and monitoring. It was created by world-class experts and is the first PKI solution built from the ground up to work in the cloud and scale to cloud workloads.

Seamless in your environment

EZCA can be added in minutes to your existing Azure, Intune, and Entra ID environments, issuing through Intune SCEP, ACME, Azure Key Vault, and Azure IoT while publishing CRLs and OCSP responses over a global CDN.

EZCA architecture: HSM backed certificate authorities in Azure issuing certificates to Intune, ACME clients, Azure Key Vault, and Azure IoT

How EZCA works

Create your first HSM-backed certificate authority in minutes without any servers

01

Create your EZCA subscription

Get started for free in minutes and only pay for the certificate authorities you actually create and use.

02

Chain it, or start fresh

You can either chain to your existing root CA or start a new root directly in EZCA, giving you flexibility in managing your certificate hierarchy.

03

Connect your services that need certificates

Point Intune SCEP, ACME clients, Azure Key Vault, and Azure IoT at your CA so the platforms you already run can request certificates directly.

04

Let the lifecycle run itself

EZCA rotates and renews certificates, publishes CRLs and OCSP responses over a global CDN, and surfaces every issued certificate in dashboards and your SIEM.

Protocols & technical details

Issuance protocols

Device certificates Intune SCEP, Static SCEP, Dynamic SCEP, ACME via device attestation
Server certificates ACME via DNS & HTTP
IoT certificates EST
Other certificates EZCA portal, REST API

Key protection

Basic FIPS 140-3 (Level 2) validated HSM
Premium FIPS 140-3 (Level 3) validated HSM

Certificate Revocation

Revocation protocols CRL and OCSP, distributed over a global CDN, Intune SCEP revocation
Read the documentation

Secure your organization with cloud based PKI in minutes

No cost per certificate, no servers, no HSMs, no geo-redundant data centres to pay for. Start with a monthly subscription and scale your certificate authorities as you need them.

Transparent pricing

View pricing details

Basic

FIPS 140-3 HSM backed CAs with Azure IoT and Key Vault integration

$200 / CA / month

Private Infrastructure

Fully isolated infrastructure for your most critical workloads

$6,000 / location / month

Frequently asked questions

EZCA backs every certificate authority with an HSM so you can create geo-redundant, hardware backed certificate authorities without manually provisioning and managing the HSMs.

EZCA natively communicates over industry standard protocols like SCEP, ACME, and EST to issue certificates directly to devices, or to your cloud infrastructure via Azure Key Vault and Entra ID integration.

Yes. EZCA monitors and automatically rotates and renews your Azure Key Vault certificates, which minimizes the risk of a mismanaged certificate causing an outage or a breach. It also communicates directly with your devices via SCEP, ACME, and EST so your devices can automatically renew expiring certificates.

EZCA automates the issuance and distribution of Certificate Revocation Lists (CRLs) over a global CDN, removing one of the most common causes of PKI outages. It also provides an Online Certificate Status Protocol (OCSP) service for real-time certificate status checking.

EZCA provides dashboards that give IT admins visibility into every issued certificate, so you can detect issues before bad actors do. SIEM integration lets security teams monitor and secure the infrastructure with the tools they already use.

No. EZCA pricing is based on the number of certificate authorities you manage, not the number of certificates you issue, so you can manage thousands of certificates without added costs or hidden fees.