A data security specialist by Swiss Post

Main section

MPKI from Switzerland

With shorter certificate lifetimes, manual certificate management is no longer an option - but global PKI-as-a-Service providers do not meet your expectations for security and privacy? Automate your certificate issuance with the MPKI solution from SwissSign, the Swiss CA.

  • For SSL/TLS and S/MIME certificates, DV, OV or EV - declared as trusted in all relevant root stores

  • Seamlessly integrated through REST interface standards (OpenAPI V3) and ACME and broad partner network

  • Unique security and compliance, 100% Swiss Made, certified CA & TSP, ISO/IEC 27001  

  • Scalable pricing model and attractive volume discounts

Order MPKI now Compare products

With our Managed PKI, you can automate your certificate management - 100% Swiss Made, data protection compliant and convenient as PKI as a service. The best starting point for digital trust in your products and services, for your business success.

Our customers

What is Managed PKI?

 

Issue certificates for your employees, customers and partners independently and directly, around the clock - PKI as a Service!

  • SSL/TLS and S/MIME certificates, number and type of certificates scalable as required

  • Recognised by all browser root stores

  • Available with Domain Validation DV, Organisation Validation OV or Extended Validation EV

  • Single-Domain, Wildcard or Multi-Domain available

Automatic issuance - ready for short lifetimes and post-quantum cryptography

 

As of March 2029, SSL/TLS certificates are only valid for 47 days. Domain validations must be made every 10 days. Eliminate manual processes:

100% Swiss Made, ideal for high regulatory requirements

 

Reliability, quality, precision and innovation - rely on Swiss values and SwissSign for PKI and certificates.

Act now: Automate your certificate management - with full security and compliance

As of 2029, SSL/TLS certificates will only be valid for 47 days, and domain validations will need to be renewed every 10 days. Those who automate today will be compliant tomorrow - and will relieve their teams. In just a few steps, we will guide you through our online ordering process to your own PKI with the desired validation level.

Domenico Valentini, Managing Director, Zinitrionic Suisse AG

We decided to work with SwissSign after conducting extensive research. Its solutions are certified, guarantee security and generate added value for both us and our customers.

 

Price overview by validation stages and certificate types

  • Identity check
  • Available products
  • Trust level
  • Display in browser
  • Suitable for...
  • Pricing
  • Processing time
  • Minimum order value per year
  • Over CHF 20,000 / EUR turnover per year?

MPKI DV

  • Order now
  • Domain ownership

  • SSL/TLS and email certificates with domain validation

  • Basis

  • Lock symbol in browser

  • Simple websites, blogs, email servers

  • Benefit from scalable prices: the higher your order quantity, the lower the price per certificate.

  • 1 working day

  • 0 CHF

  • Order online now
  • Volume prices are automatically applied during checkout.

MPKI OV

  • Order now
  • Domain ownership and organisational identity
  • SSL/TLS and email certificates with domain and organisational validation

  • High

  • Ownership is listed in the certificate
  • Smaller e-commerce sites and corporate websites that handle sensitive data or financial transactions

  • Benefit from scalable prices: the higher your order quantity, the lower the price per certificate.

  • 1 working week

  • 300 CHF

  • Order online now
  • Volume prices are automatically applied during checkout.

MPKI EV

  • Order now
  • Verification of legal status and address of the company using official registers

  • SSL/TLS and email certificates with domain, organisation validation, and extended validation.
  • Highest trust

  • Ownership is visible in the browser's context menu

  • Companies or organisations such as banks or large e-commerce sites that want to clearly signal their trustworthiness to their customers and partners

  • Benefit from scalable prices: the higher your order quantity, the lower the price per certificate.

  • 1 working week

  • 500 CHF

  • Order now online
  • Volume prices are automatically applied during checkout.

SwissSign's standard currency is Swiss Franc. Invoicing in Euros is available on the MPKI order portal.

Frequently Asked Technical Questions about SwissSign's PKI as a Service

A standard Managed PKI is a subscription service that allows you to retrieve SSL/TLS certificates and S/MIME (email) certificates at any time. Certificates can be issued manually or automatically (over dedicated interfaces, e.g. a REST API or the ACME protocol). It is best combined with a Certificate Lifecycle Management (CLM) solution.

All types of Internet SSL/TLS certificates can be issued:

  • Validation levels: Domain Validated (DV), Organization Validated (OV – with organization entry) and Extended Validated (EV – with organization entry plus additional features)

  • Variants: single-domain, multi-domain (SAN) and wildcard

Email certificates of the types:

  • Mailbox Validated (MV – email address only)

  • (coming soon) Organization Validated (OV – email address plus organization entry)

  • Sponsor Validated (SV – email address plus organization entry plus person as holder)

For Private Managed PKI see next FAQ.

A Private Managed PKI (also called PKI as a Service) means outsourcing the operation of your certificate infrastructure to a specialised provider while maintaining control over your certificate policies and issuance rules. Instead of running your own CA servers, HSMs, and certificate management software on premise, you access PKI capabilities through APIs and management interfaces.

The key difference: with an internal PKI, your team handles server maintenance, security updates, compliance audits, HSM management, and disaster recovery. With a Private Managed PKI, the provider handles infrastructure operations while you focus on certificate policies and integration. You get enterprise PKI capabilities without the operational overhead.

Like the standard Managed PKI the Private Managed PKI is best combined with a Certificate Lifecycle Management (CLM) solution.

The platform handles both publicly trusted certificates (from SwissSign's public CA) and private certificates for internal-only use cases:

  • The standard SwissSign Managed PKI supports certificates for the Internet (see "What is a SwissSign Managed PKI?")

  • The Private Managed PKI can issue any type of (X.509) certificate, e.g. SSL/TLS certificates for internal use, client certificates for user authentication or device certificates for IoT and industrial equipment

PKI automation uses protocols like ACME (Automatic Certificate Management Environment) to issue, renew, and revoke certificates without manual intervention. With ACME, your servers or devices communicate directly with the Certificate Authority (CA) to request certificates, prove domain ownership automatically, and receive certificates within seconds.

SwissSign's REST API provides additional flexibility for custom integrations, allowing you to manage certificates programmatically across your entire infrastructure. This eliminates manual CSR generation, reduces human error, and ensures smooth certificate renewal.

SwissSign MPKI integrates with leading certificate lifecycle management (CLM) platforms and enterprise tools through standard protocols. SwissSign also offers a proper full CLM, powered by innovative French company Evertrust.

Further integration options include:

  • ACME protocol support for automated certificate workflows

  • REST API for custom integrations and programmatic management

  • Direct integration capabilities with major CLM vendors

Therefore, the platform supports certificate deployment across web servers, load balancers, API gateways, IoT devices, and container environment.

Certificate deployment varies by infrastructure type but follows automated workflows. For web servers and load balancers, ACME clients or Certificate Lifecycle Management tools - like our proper CLM - handle deployment directly. In Kubernetes and container environments, cert-manager or similar operators automate certificate injection - they can be integrated into a CLM. IoT devices use SCEP or custom API integration for bulk provisioning.

The key is establishing the initial connection between your infrastructure, the MPKI platform and the CLM - after that, certificate issuance, deployment, and renewal happen automatically based on your defined policies. Learn more about how Certificate Lifecycle Management works here.

Frequently Asked Commercial Questions about SwissSign's MPKI Solution

The managed PKI service period is generally one year and automatically renews for another year if the contract is not cancelled. If the contract is cancelled, any active certificates will be withdrawn ("revoked") as of the cancellation date.

You can obtain as many certificates as you need. If you have issued more certificates than were included in the pre-invoice, you will receive a post-invoice based on the number of active certificates as of the yearly renewal date of your contract.

Your first contract year: You will receive a pre-invoice that takes into account all available discounts. The higher your annual turnover, the lower the price per certificate. This order amount forms the basis for the price to be paid.

You can also issue more certificates than you have ordered. You will then receive a post-invoice based on the number of active certificates as of the yearly renewal date of your contract. This new order amount will then form the new basis for the following annual pre-invoice.

Basically, the higher your annual turnover, the lower the price per certificate. Up to an annual turnover of 20,000 CHF / EUR, you can calculate and order your certificate prices including discounts directly on our ordering platform. If you need more certificates, please contact us and we will make you an attractive individual offer.

Three months before the end of your annual contract and its automatic renewal.

How digital certificates and public key infrastructure work

Background knowledge from our blog

What is PKI - Public Key Infrastructure?

What is a Certificate Authority?

DV, OV, EV: what validation levels do you need?

What is TLS 1.3 - and what are the advantages over TLS 1.2?

Start your SwissSign MPKI now

Highest security standards, easy integration, flexible scaling. SwissSign's MPKI is your answer to modern PKI requirements.

Order SwissSign MPKI now