Transparent cloud PKI pricing

Pay per certificate authority, not per certificate. No infrastructure to buy and no hidden fees.

Basic

All the security at an affordable price

$200 / CA / month

  • FIPS 140-3 (Level 2) HSM backed CAs
  • 1 certificate created or OCSP response per CA per second
  • Support within one business day
  • 99.9% availability
  • Issue certificates via ACME, EST, and SCEP protocols
  • Azure IoT integration
  • Azure Key Vault integration
  • Azure application certificate rotation
  • Bring your own AD CS CA
  • Available in Azure Public, Government, and Azure GCC High environments
Get started

Private Infrastructure

Best for your most critical workloads

$6,000 / location / month

  • Everything in Premium, plus:
  • 160 certificates created or OCSP responses per CA per second
  • 24/7 support within 1 hour
  • Fully isolated infrastructure
Book a demo

Self-Hosted Licensing

Host and manage your own infrastructure in your own environment

$3,000 (with unlimited CAs) / location / month

  • Everything in Private Infrastructure, plus:
  • Self-healing infrastructure with Azure PaaS services
Book a demo

Not sure which plan is best for you?

Talk to one of our PKI experts about how EZCA can reduce your IT cost while improving your user productivity and security.

Frequently asked questions

There is no certificate limit. EZCA pricing is based on the number of certificate authorities you manage, not the number of certificates you issue, so you can manage thousands of certificates from a single CA.

Level 3 adds higher standards of physical protection to the HSM. Most organizations only require level 2.

No. With EZCA there are no hidden fees, you pay what you see. If you create a basic CA in a single location you will only be charged $200 a month. All resources are created in the Keytos tenant and paid by Keytos.

The plan limits exist to ensure organizations don't abuse the system. If you issue two certificates in the same second on the basic plan, the CA will issue them without a problem. Throttling starts if you begin issuing at volumes like 10,000 per hour.

Yes. If you already have an existing root CA, you can export the certificate signing request of your EZCA CA, sign it with your existing root CA, and import it back to EZCA.

Yes. Creating your own PKI can be daunting, so our PKI experts are here to help you set up a world class PKI following the latest industry standards.