vSEC:CMS C-Series on AWS

vSEC:CMS will change your views on how to manage the lifecycle of credentials. The vSEC:CMS C-Series on AWS is an innovative, easily integrated and cost effective Credential Management System or Credential Management System (SCMS or CMS) that will help you deploy and manage credentials within your organization. Organizations can run vSEC:CMS C-Series in public clouds, private clouds and hybrid clouds.

The vSEC:CMS C-Series is fully functional with minidriver enabled credentials and it streamlines all aspects of a credential management system by connecting to enterprise directories, certificate authorities, physical access control systems, email servers, log servers, biometric fingerprint readers, PIN mailers etc. With vSEC:CMS organizations can issue credentials to employees, personalize the credential with authentication certificates and manage the lifecycle of the credentials - directly from the cloud.

Vendor Independent

vSEC:CMS is fully functional with minidriver enabled credentials such as smart cards, USB tokens and virtual smart cards including Windows Hello for Business (WHfB) and it streamlines all aspects of managing credentials by connecting to enterprise directories, certificate authorities, physical access control systems, email servers, log servers, biometric fingerprint readers, PIN mailers... the list goes on. With vSEC:CMS organizations can issue credentials to employees, personalize the credentials with authentication credentials and manage the lifecycle of the credentials - directly from the cloud.

Versasec is an IAM provider that helps businesses manage their access-enabling devices.

vSEC:CMS Connectors

  1. 1. Smart card printer for batch operations
  2. 2. User directory for looking up users
  3. 3. File and database servers
  4. 4. Secure transport of PIN codes
  5. 5. Event & log management
  6. 6. User photo capture
  7. 7. Certificate/PKI services
  8. 8. Physical access control systems
  9. 9. Hardware security module
  10. 10. Secondary/out-of-band communication
  11. 11. Key archival & key recovery
  12. 12. Credential provider -login screen interface
  13. 13. Remote security device management
  14. 14. Physical & virtual smart cards/tokens
  15. 15. User self-service application
  16. 16. Administrative operator console

Demonstration and Free Consultation

You can schedule a demo or contact our Versasec team for a free consultation.
To find a local partner, please check our Versasec Partner Network page.


A cornerstone of vSEC:CMS is security, all sensitive data and keys are secured using hardware. Operators of the system are authenticated using two-factor authentication and all usage is securely audited for full traceability.
The main task of a CMS is to securely connect user identities (credentials) into an enterprise systems and maintain this connection throughout the lifecycle of the credential. That implies the need of secure communication with several external systems.

Instant Access

vSEC:CMS C-Series is available on the AWS Marketplace. Once the AWS Instance has been launched, vSEC:CMS is ready to use in Evaluation Mode. During the evaluation, you can configure your environment with up to 5 licenses and your own use cases. Each license manages one credential. Additional licenses can be acquired as a subscription or as a perpetual license. Please contact a Versasec reseller or Versasec directly to proceed.

Instant Setup!

It’s easy to get started and you can have the most common configuration (Windows Credential Logon) set up in minutes instead of days following our step-by-step tutorials. Once you have the initial use case configured you can build from there adding: User Self Service, Remote Operators and support for other secure devices including Virtual Smart Cards and Windows Hello for Business (WHfB). We support many different use cases; configuration options and our feature set are vast.

Use Case Guide: Windows Credential Logon

We will guide you through the initial setup all the way to you issuing and managing the lifecycle of your secure devices. Follow this guide on our Support Portal: Windows Credential Logon
Note: The PKI used in this example use case will be an MS CA. Other PKIs are also supported.


Complete Documentation is found on our Support Portal

Product News

vSEC:CMS Version 6.0 is now available. A press release about this version is available here. In the latest version of vSEC:CMS we have focused on ease of use and speed, and have added a variety of new, automated tasks. Other enhancements and features include the following:

  • Offers full support for 64-bit and an automatic migration to the client installer (user self-service console).
  • Strengthens integration with physical access management systems (PACS) with a new connector to Honeywell Access Control Systems (ACS).
  • Provides MacOS User Self-Service support (gold version).
  • Extends the certificate management functionality of vSEC:CMS with support for the ACME protocol, allowing automation around requesting certificates and managing them through vSEC:CMS. This is especially important for computer/server and Internet of Things (IoT) certificates.
  • Improves management for scheduled tasks that are built or configured in vSEC:CMS. Now, the tasks can be managed and their status viewed from a central location.
  • Improves eToken support, strengthens PIN policies and management of token names, and improves YubiKey support.

vSEC:CMS Suite

More information about the complete vSEC:CMS product suite can be found here. vSEC:CMS Suite

Migrate to vSEC:CMS

vSEC:CMS S-Series includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

Check out the details on how to upgrade from:


The product can be purchased from authorized vSEC:CMS integrators and resellers, via our partners reseller network or contact Versasec directly to let us help you find the best way forward.


The vSEC:CMS video content can be found here.

Supported Credentials




Supported Credentials





Athena IDProtect Key USB Token

Athena IDProtect Smart Card

Aventra MyEID 4.5

Avtor CryptoCard 337

Atos CardOS v4.4

Atos CardOS v5.3

Cryptovision SCinterface


Feitian ePass FIDO-NFC

Feitian BioPass FIDO2

Feitian eJava Token

Feitian SmartCard

Feitian ePass2003

Thales IDPrime .NET 510

Thales IDPrime .NET 5500

Thales IDPrime MD 830

Thales IDPrime MD 840

Thales IDPrime MD 930

Thales IDPrime MD 940

Thales IDPrime MD 3810

Thales IDPrime MD 3840

Thales IDPrime MD 3930

Thales IDPrime MD 3940

Thales IDPrime MD 3940 FIDO

Thales IDPrime PIV 2.1

Thales IDPrime PIV 3.0

Thales IDPrime Virtual

Thales MultiApp ID

Thales Safenet eToken 5110

Thales Safenet eToken 5110 FIPS

Thales Safenet eToken 5300

HID Global Crescendo C200

HID Global Crescendo C1150

Identiv uTrust MD

Longmai mToken CryptoID

Microsoft minidriver enabled devices

Microsoft Windows Hello for Business

Idemia ypsID S2

Idemia ypsID S3

Idemia ID-One Cosmo 8.1 IAS ECC

Idemia ID-One PIV 8.1

Open FIPS 201 Applet

SafeTrust-PIV on Placard

Taglio C2

Taglio PIVKey

TCOS TeleSec IDKey

Virtual Smart Cards

Yubico YubiKey 5 NFC/5C/5 Nano/5C Nano

Yubico YubiKey 4/4 Nano/4C/4C Nano

Yubico YubiKey NEO/NEO-n

- The credential is supported by the product.
L - Known limitations - check release notes.
For details about validated middleware/minidrivers check the Versasec support portal or contact us.

The table below highlights the key features included in the vSEC:CMS product suite. Further detailed information about each product is provided from this table.




Product Features




User-Side Credential Operations

  • Change User PIN
  • Offline Unblock User PIN (User Side)
  • Certificate Listing
  • Card Information
  • Support for a large set of credentials

Operator-Side Credential Operations

  • Admin Key Change
  • Online Unblock User PIN
  • Offline Unblock User PIN (Operator Side)
  • User PIN Policy Update
  • Certificate Management (pfx or p12 Import, Delete)

Advanced Operator Side Smart Card Operations

  • Admin Key Diversification
    from Hardware Protected Masterkey
  • User Fingerprint Policy Update
  • Batch mode support


  • Card Repository
  • SQL Support
  • Backup / Restore
  • Multi-forest & Multi-domain

Smart Card Management System Features




Product Features




Advanced Management Features

  • User Self-service and MS Credential Provider
  • Key archive and key restore
  • Smart Card Stock Management
  • Granular Operator Permissions and Access Control
  • Card Printing and Batch Processing
  • Photo Capturing
  • Remote Security Device Management (RSDM)
  • Certificate Management using ACME

Systems Integrations

  • Certification Authorities (MS CA, Entrust, DigiCert, EJBCA, GlobalSign...)
  • User Directories (LDAP, MS AD)
  • Physical Access System (RFID)
  • Identity Providers (IdP) using OpenID Connect (OIDC)
  • Windows Event Log
  • Mail Server (for PIN mailing)
  • Hardware Security Module (HSM)


  • SQL Database Interface
  • SQL High Availability - Microsoft Always On
  • SOAP Helpdesk API
  • SOAP Lifecycle API
  • Web Start API
  • Plugin API
  • Physical Access System (PACS) API







Perpetual Licenses
Stand Alone Application
Installation Package
Ready To Deploy Image

The feature is included in the product.