vSEC:CMS | Smart Card Lifecycle Management

vSEC:CMS will change your views on how to manage the lifecycle of user authentication credentials (smart cards, USB security keys, tokens). vSEC:CMS is an innovative, easily integrated and cost effective Smart Card Management Software or Credential Management Software (SCMS or CMS) that will help you deploy and manage credentials within your organization.

What is a Smart Card Management System?

A Smart Card Management System (SCMS) serves as the central command center for your organization’s authentication infrastructure. It is a specialized software solution designed to streamline and secure the entire lifecycle of physical and virtual credentials—from smart cards and USB tokens to FIDO2 authenticators. By bridging the gap between users, directories, and Certificate Authorities (PKI), an SCMS automates complex workflows like batch issuance, PIN management, and certificate renewal. It replaces manual, error-prone processes with a policy-driven approach, ensuring that every credential in your fleet is accounted for, compliant, and easily managed from issuance through to retirement.

 

vSEC:CMS Credential Lifecycle Stages

Orchestrate the entire lifecycle of your organization’s smart cards and secure tokens from a single, centralized console. vSEC:CMS ensures every stage of the credential journey is secure, compliant, and efficient.

 

Diagram of vSEC:CMS Smart Card Management System Lifecycle
Diagram of vSEC:CMS Smart Card Management System Lifecycle

1. Registration

Secure Onboarding & Root of Trust. The lifecycle begins by securely attaching new credentials to the system. During registration, vSEC:CMS replaces default manufacturer keys with unique, secure administration keys. This establishes a hardware-backed root of trust, ensuring only authorized administrators can manage the token moving forward.

2. Issuance

Policy-Driven Provisioning. Credentials are effectively “born” when a Credential Template is applied. This stage binds the physical token to a specific user and technical policy, loading necessary certificates or enrolling the device with a FIDO2 Identity Provider (IdP). Support for both individual and batch execution streamlines high-volume rollouts.

3. Activation

Flexible User Enablement. Transitioning to the Active state turns a personalized token into a functional authenticator. vSEC:CMS supports diverse activation workflows to suit your infrastructure:

  • Centralized: Immediate activation by an administrator.
  • Decentralized: Remote activation via User Self-Service, allowing users to securely set their PINs and unblock devices without IT intervention.

4. Inactive Status

Temporary Suspension. When a credential is misplaced or temporarily out of compliance, it can be moved to the Inactive state. This action instantly blocks access to the credential’s administration key without permanently revoking certificates. It provides a secure “pause” button, allowing for easy reactivation if the token is recovered.

5. Locked Status

Automated Security Response. If a user exceeds PIN attempts or an administrator triggers a lock, the credential enters the Locked state to prevent unauthorized access. vSEC:CMS maintains the administrative connection, enabling authorized Helpdesk staff to perform secure remote unblocking workflows and restore user access quickly.

6. Revocation

Immediate Access Termination. When a credential is lost, stolen, or an employee leaves, the Revocation stage ensures immediate security. vSEC:CMS communicates directly with the Certificate Authority (CA) to invalidate certificates, providing a definitive kill-switch that updates revocation lists (CRLs) instantly to protect the network.

7. Retirement

Sustainable Credential Recycling. Maximize your hardware investment with the Retire workflow. This process securely wipes personal data, keys, and certificates from the smart card or token while retaining the device in the system inventory. The sanitized token is then ready to be re-issued to a new user, reducing electronic waste and hardware costs.

8. Deletion

Audit-Ready End of Life. The final stage permanently removes the credential from the active database and releases the associated software license. While the operational data is removed, vSEC:CMS retains comprehensive transaction logs, ensuring your organization maintains full audit compliance even after a credential has left the system.

Vendor Independent

vSEC:CMS is fully functional with minidriver enabled credentials such as smart cards, USB tokens and virtual smart cards including Windows Hello for Business (WHfB). It streamlines all aspects of managing credentials by connecting to enterprise directories, certificate authorities, physical access control systems, email servers, log servers, biometric fingerprint readers, PIN mailers… the list goes on. With vSEC:CMS, organizations can issue Credentials to employees, personalize the Credentials with authentication credentials and manage the lifecycle of the Credentials – directly from the off-the-shelf product.

Versasec Card Lifecycle Management

Versasec goes beyond basic identity management by offering unparalleled flexibility, advanced PKI/PIV, FIDO2, RFID capabilities, and seamless integration with identity providers (ie, Microsoft Entra ID). Thus, enabling organizations to meet their unique identity needs and exceed the requirements of modern security mandates, such as Executive Order 14028.

vSEC:CMS manages the lifecycle of identity credentials (smart cards, security keys, tokens, authenticators), integrating with identity providers (Microsoft Entra ID, Ping Identity, Thales STA), certificate authorities (Microsoft, Keyfactor, DigiCert, Entrust), user directories, smart card printers (Matica, Magicard, HID), hardware security modules (Futurex, Utimaco), and more. This allows businesses to leverage existing IAM infrastructure with leading providers.

Key Differentiators:

  • One platform: for PKI and FIDO2 orchestration: integrates with identity leaders bringing you the highest number of supported credentials for the orchestration, & configuration of your IAM security. Versasec serves your budget, compliance, and IT preferences, performing at the security core of your organization.
  • Unmatched User Experience: vSEC:CMS simplifies credential management for both IT administrators and end-users. Our innovative self-issuance process with identity providers and PKI certificates allows employees to set up authentication devices without IT intervention. For scenarios where self-service is unsuitable, vSEC:CMS offers help-desk on-behalf of users management. This streamlines onboarding, especially for remote/hybrid workforces, and eliminates the complexities of traditional self-enrollment methods.
  • Advanced FIDO2 Enterprise Features: Versasec is at the forefront of FIDO2 innovation. We provide centralized management of FIDO2 devices with features like PIN unblock, Relying Party allow lists, and granular control over fingerprint enrollment. This level of control is crucial for enterprise deployment security.
  • Seamless Microsoft Entra ID Integration: vSEC:CMS leverages the latest technology in Microsoft Entra ID, enabling organizations to reach the full potential of Microsoft’s identity platform.
  • Comprehensive IAM: vSEC:CMS offers a single pane of glass for managing all logical and physical (access) authentication needs. It supports multiple authenticators, integrates with existing infrastructure (cloud and on-premises), and provides complete lifecycle management for identity credentials.

Impact:

  • Increased Efficiency: vSEC:CMS drastically reduces IT overhead. For example, pre-registering a PKI or FIDO, or hybrid key with vSEC:CMS takes a tenth of the time compared to traditional enrollment. This efficiency gain is further amplified with batch issuance, integrations, and APIs.
  • Enhanced Security: Our solution strengthens security by protecting enrollment, revocation, and recovery processes. Features like FIDO2 PIN unblock (5 mins vs. hours for manual complete reset and recovery) minimize downtime and mitigate risks associated with temporary replacements with weaker authentication methods.
  • Compliance and Oversight: vSEC:CMS provides comprehensive audit trails and reporting, ensuring compliance with industry regulations and security policies, including NIS2 Directive, GDPR, ENISA, U.S. Executive Order 14028.

Addressing Trends:

Versasec is committed to supporting the global shift towards passwordless phishing-resistant authentication. Our robust PKI and FIDO2 implementation, coupled with identity providers, directly addresses the requirements of Executive Order 14028 and NIST Digital Identity Guidelines. By enabling organizations to adopt PKI, FIDO2 security keys and establish Zero Trust, Versasec creates a more secure digital landscape.

Versasec has more than 15 years of expertise in PKI and its with this expertise, we are committed to supporting the global shift toward passwordless phishing-resistant authentication.

“Finally, we can start deploying FIDO2 – this is what we have been waiting for!” – CISO in aeronautics.

KuppingerCole Analysts chose Versasec as one of the first 8 companies to spotlight as KC Rising Star in 2024. A research spotlighting innovation and market alignment in the IAM, digital identity, and cybersecurity.

In conclusion, Versasec products are ideal to:

  • Comply with security regulations through high-level security and reduced effort.
    Improve user experience and oversight through IT on-behalf-of-user management, simplified self-service, and streamlined workflows.
  • Utilize identity investments to their fullest potential for secure and efficient identity management.
  • Satisfy customers’ unique identity needs with a flexible and adaptable solution.

Product News:

We’re happy to announce the arrival of vSEC:CMS 7.2.2 – Enterprise YubiKey Pre-Registration and Lifecycle Management

  • Zero-Touch Deployment: Eliminates the complex manual logistics of shipping and re-shipping keys.
  • Full Lifecycle Management: Centralized control over FIDO and PIV credentials, ensuring compliance with standards like FIPS 201.
  • Effortless User Experience: Users receive pre-registered YubiKeys directly from Yubico, already enrolled in the organization’s Identity Provider (IdP), allowing them to authenticate within minutes with no complex self-enrollment required.
  • Hybrid & IdP Agnostic: Supports managing both PKI and FIDO2 credentials side-by-side and is compatible with multiple Identity Providers (e.g., Entra ID, Okta, Ping Identity) from one central interface.

Meet vSEC:CMS 7.2 – Centralized FIDO2 Management and Transition of Active YubiKeys

  • Centralized FIDO2 Control in Agent App – We’re adding the favorite FIDO2 device management features to the light version app, the vSEC:CMS Agent:
    – Remove passkeys from managed devices,
    – initiate fingerprint enrollment, and
    – perform application resets.
  • Transition of Active YubiKeys – Automate the wipe of all prior (PIV application) access credentials and replace them with new, uniquely diversified PKI keys and certificates. This feature effectively transitions active YubiKeys to vSEC:CMS management.
  • This release expands our supported credentials list to include the Thales SafeNet eToken FIDO NFC, Swissbit iShield Key 2, and support for a new credential provider, AuthenTrend, and the ATKey.Card.NFC. We’re providing you with more options for modern, multi-purpose authentication.
  • Significant under-the-hood enhancements to improve the platform’s overall performance, stability, and security, making the system faster and more resilient against threats.

vSEC:CMS

Starter Pack 50

€2.69

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • Professional Level Support
  • Customer On-Prem or Private Cloud
  • Full vSEC:CMS Feature Set
  • 50 Credentials

vSEC:CMS

Starter Pack 100

€1.85

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • Professional Level Support
  • Customer On-Prem or Private Cloud
  • Full vSEC:CMS Feature Set
  • 100 Credentials

vSEC:CMS

Starter Pack 500

€1.56

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • Professional Level Support
  • Customer On-Prem or Private Cloud
  • Full vSEC:CMS Feature Set
  • 500 Credentials

vSEC:CMS

>500 Credentials

Contact Sales
for Pricing

Contact us
  • Professional Level Support
  • Customer On-Prem or Private Cloud
  • Full vSEC:CMS Feature Set
  • Custom

Evaluation – Download Today!

Once downloaded and installed vSEC:CMS is ready for use in Evaluation Mode. During the evaluation, you can configure your environment with up to 10 licenses and your own use cases. Each license manages one credential. Additional licenses can be acquired as a subscription or by perpetual license. Please contact a Versasec reseller or Versasec directly to proceed.

Schedule a Demo

To enjoy the vSEC:CMS full feature set (including Self-Service, Virtual Smart Card, HSM support etc), schedule a demo with Versasec or contact your local Versasec reseller.

Scalability

The vSEC:CMS scales with your project. With the new load balancing capability, there is no upper limit!

Load Balancer

Integrability – APIs

The vSEC:CMS can be integrated and connected in many different ways, the drawing below is trying to visualize the most commonly used options.

vSEC:CMS APIs

Migrate to vSEC:CMS

vSEC:CMS includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

vSEC:CMS system migration paths - never locked in!

vSEC:CMS system migration paths - never locked in!

vSEC:CMS  includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

Check out the details on how to upgrade from:

Resellers

The product can be purchased from authorized vSEC:CMS integrators and resellers, or directly from Versaseccontact Versasec to let us help you find the best way forward.

Organizations Using Versasec

Organizations worldwide have upgraded their identity management, left behind passwords, and are focusing on other IT priorities.

pie graph-vsec customers

  • 37% Tech & Services
  • 29% Government
  • 11% Financial
  • 23% Others

What Our Customers Are Saying

vsec-customers-logos

  • “I looked at Versasec and at the end of the day, it wasn’t a product. The way that Paul worked with us and continues to work with us today, it’s a true partnership and I know I can lean on them and make that call, shoot that email, and get a response. It’s a true partnership and it’s really nice to be able to have that, as opposed to a traditional ‘this is my piece of software, call support and have a good day.’” – Head of IT, Air Hydro Power. | Product: vSEC:CMS for PKI + FIDO. | Read Case Study.
  • “Two of the primary reasons that Versasec got our business: one, the on-premises feature. We’re not resisting the cloud, but if we can keep it on-premise, we manage our hardware and virtual environment. Two – perpetual licenses. We pay for support, but the licenses are there and will always be. We know that Versasec would be responsive if we need more licenses. Overall – the experience has been exactly what we were looking for.”
    – Aron Gann, System Administrator, Brookshire Brothers. | Product: vSEC:CMS on-prem for YubiKeys. | Read Case Study.
  • “Our team wants to focus on delivering business value. Updating software and servers, while important, is low value. By using a managed solution, we can focus on business objectives.”
    – Head of Engineering and Cybersecurity | Product: vSEC:CLOUD.

Get Started

Getting started is easy. Schedule a 30 min demo with an identity expert to see if Versasec is a good fit for your organization.

Schedule a Demo

Foundational Security: Credential Issuance and Management for PKI and FIDO

At our core, we establish a secure and controlled environment for enterprise credential issuance and management through primary connections.

This provides both simplicity and the highest level of security for effective credential management.

Schedule a Demo

Versasec Supported Credentials & Passwordless Authenticators

Versasec strives to support as many credential types as possible in all of Versasec’s products. Below are phishing-resistant credentials we support. We hope one fits your enterprise, users, and devices. Not all multi-factors are created equal. Customize based on your organizational needs and goals. We support PIV, PKI, Virtual, Physical Access, Logical Access, and combined FIDO+PIV, and FIDO-only credentials. Versasec does not lock you in to one provider, we are credential-agnostic. The number of supported credential types is continuously increasing with every new product version. If you want to manage a different credential, currently not on our list, please contact us at info@versasec.com.

* Tokens and smart cards with FIDO2

supported credentials logo banner

*Tokens and smart cards with FIDO2

Read about our award-winning credential management software

Product Features

The table below highlights the key features in the Versasec credential management product suites.

 

vSEC:CLOUD

vSEC:CMS

User-Side Credential Operations

Agent-Side Credential Operations

  • Admin Key Change
  • Online Unblock User PIN
  • Offline Unblock User PIN (Operator Side)
  • User PIN Policy Update
  • Certificate Management (pfx or p12 Import, Delete)

Advanced Credential Operations

  • Admin Key Diversification
    from Hardware Protected Masterkey
  • User Fingerprint Policy Update
  • Batch Mode Support
  • Interface Management
  • Custom Data on Credential Management
  • Contact and Contactless (NFC)
  • Credential Ordering and Shipping

Database

  • Credential Repository
  • SQL-based Databases
  • Backup / Restore
  • Multi-forest & Multi-domain

Credential Management System Features

 

vSEC:CLOUD

vSEC:CMS

Product Features

Advanced Management Features

  • User Self-service and MS Credential Provider
  • Key Archive and Key Restore
  • Smart Card Stock Management
  • Granular Operator Permissions and Access Control
  • Card Printing and Batch Processing
  • Photo Capturing
  • Remote Security Device Management (RSDM)
  • Certificate Management using ACME
  • FIDO2 Enterprise Management

Systems Integrations

  • Certification Authorities
  • User Directories
  • Physical Access System (RFID)
  • Identity Providers (IdP)
  • Windows Event Log
  • Mail Server
  • Hardware Security Module (HSM)

Integrations/APIs

Server-Side
  • SQL Database Interface
  • SOAP Helpdesk API
  • SOAP Lifecycle API
  • REST Lifecycle API
Client-Side
  • COM API
  • Web Start API
  • Plugin API
  • Physical Access System (PACS) API
 

vSEC:CLOUD

vSEC:CMS

Licensing/Packaging

Managed by Versasec

 

Subscription

Perpetual Licenses

 

Installation Package

 

NOTE
✔ – The credential is supported by the product.
L – Known limitations – check release notes.
For details about validated middleware/minidrivers check the Versasec support portal or contact us.

Versasec Support

Versasec customers with an existing support and maintenance contract can access the Versasec Support Portal, offering extensive professional support and maintenance services. The Versasec Support Portal offers a variety of services, allowing for customers and any site visitor to communicate directly with support engineers.

Visit Support

Company Blog

Our blog addresses the latest security trends and stories. The posts discuss how identity and access management are playing a larger role in keeping corporate data safe as well as brand reputations intact.

Visit our Blog