Public Key Infrastructure
Public Key Infrastructure (PKI) is the combination of policies, processes, hardware, and software used to create and manage the digital certificates and cryptographic key pairs that secure data on networks. It underpins common forms of internet encryption, helping to protect and authenticate traffic between systems such as web browsers and web servers. In practical terms, PKI is what allows two parties who may not know each other to establish trust when exchanging information online.
PKI is a set of roles, policies, processes, hardware, software, server platforms, and workstations used to create, manage, distribute, use, store, and revoke digital certificates and to administer the associated public-private key pairs. It provides a trust framework in which certificates bind public keys to identities, supporting encryption, authentication, and secure data transfer across digital networks. PKI is a framework of components and procedures rather than a single product or protocol, and specific implementations, certificate policies, and supporting standards vary by deployment and should be verified against the relevant authoritative specifications.
Why it matters
PKI is foundational to trust on digital networks because it allows parties who have no prior relationship to authenticate one another and exchange information securely. By binding public keys to verified identities through digital certificates, PKI enables the encryption and authentication that protect traffic between systems such as web browsers and web servers. For compliance and security professionals, this makes PKI a load-bearing element of many technical safeguards: without a functioning trust framework, common forms of internet encryption and secure data transfer would not be possible.
Because PKI underpins so much of everyday secure communication, weaknesses in its policies, processes, or key management can have broad consequences. A framework is only as trustworthy as the procedures governing certificate issuance, storage, use, and revocation; gaps in any of these can undermine the assurances that relying parties depend on. This matters for organizations that must demonstrate the confidentiality, integrity, and authenticity of data in transit as part of their broader security and data protection obligations.
It is worth emphasizing that PKI is a framework of components and procedures rather than a single product, protocol, or compliance requirement in itself. It is frequently a means of implementing security controls rather than an obligation imposed by any specific regulation. Whether and how a particular PKI deployment satisfies a given legal or contractual requirement is fact-specific and depends on the applicable standards, certificate policies, and risk context, which should be verified against the relevant authoritative specifications.
Who it's relevant to
Inside PKI
Common questions
Answers to the questions practitioners most commonly ask about PKI.

