vSEC:CMS

vSEC:CMS will change your views on how to manage the lifecycle of user authentication credentials (smart cards, USB security keys, tokens). vSEC:CMS is an innovative, easily integrated and cost effective Smart Card Management System or Credential Management System (SCMS or CMS) that will help you deploy and manage credentials within your organization.

Vendor Independent

vSEC:CMS is fully functional with minidriver enabled credentials such as smart cards, USB tokens and virtual smart cards including Windows Hello for Business (WHfB). It streamlines all aspects of managing credentials by connecting to enterprise directories, certificate authorities, physical access control systems, email servers, log servers, biometric fingerprint readers, PIN mailers… the list goes on. With vSEC:CMS, organizations can issue Credentials to employees, personalize the Credentials with authentication credentials and manage the lifecycle of the Credentials – directly from the off-the-shelf product.

Versasec Card Lifecycle Management

Versasec goes beyond basic identity management by offering unparalleled flexibility, advanced FIDO2 capabilities, and seamless integration with identity providers (ie, Entra ID). Thus, enabling organizations to meet their unique identity needs and exceed the requirements of modern security mandates like Executive Order 14028.
vSEC:CMS manages the lifecycle of identity credentials (smart cards, security keys, tokens, authenticators), integrating with identity providers (like Microsoft Entra ID), certificate authorities, user directories, smart card printers, hardware security modules, and more. This allows businesses to leverage existing IAM infrastructure with cloud-native Azure solutions.

Key Differentiators:

  • Unmatched User Experience: vSEC:CMS simplifies credential management for both IT administrators and end-users. Our innovative self-issuance process with identity providers (ie, Entra ID) allows employees to set up authentication devices without IT intervention. For scenarios where self-service is unsuitable, vSEC:CMS offers help-desk on-behalf of users management. This streamlines onboarding, especially for remote or hybrid workforces, and eliminates the complexities of traditional self-enrollment methods.
  • Advanced FIDO2 Enterprise Features: Versasec is at the forefront of FIDO2 innovation. We provide centralized management of FIDO2 devices with features like PIN unblock, Relying Party allow lists, and granular control over fingerprint enrollment. This level of control is crucial for enterprise deployment security.
  • Seamless Entra ID Integration: vSEC:CMS leverages the latest technology in Entra ID, enabling organizations to reach the full potential of Microsoft’s identity platform.
  • Comprehensive IAM: vSEC:CMS offers a single pane of glass for managing all logical and physical authentication needs. It supports many authenticators, integrates with existing infrastructure (cloud and on-premises), and provides complete lifecycle management for identity credentials.

Impact:

  • Increased Efficiency: vSEC:CMS drastically reduces IT overhead. For example, pre-registering a FIDO key with vSEC:CMS takes a tenth of the time compared to traditional enrollment. This efficiency gain is further amplified with batch issuance, integrations, and APIs.
  • Enhanced Security: Our solution strengthens security by protecting enrollment, revocation, and recovery processes. Features like FIDO2 PIN unblock (5 mins vs. hours for manual complete reset and recovery) minimize downtime and mitigate risks associated with temporary replacements with weaker authentication methods.
  • Compliance and Oversight: vSEC:CMS provides comprehensive audit trails and reporting, ensuring compliance with industry regulations and security policies, including Executive Order 14028.

Addressing Trends:

Versasec is committed to supporting the global shift towards phishing-resistant authentication. Our robust FIDO2 implementation, coupled with identity providers, directly addresses the requirements of Executive Order 14028 and NIST Digital Identity Guidelines. By enabling organizations to adopt FIDO2 security keys and establish Zero Trust, Versasec creates a more secure digital landscape.

“Finally, we can start deploying FIDO2 – this is what we have been waiting for!” – CISO in aeronautics.

KuppingerCole Analysts chose Versasec as one of the first 8 companies to spotlight as KC Rising Star in 2024. A research spotlighting innovation and market alignment in the IAM, digital identity, and cybersecurity.

In conclusion, Versasec products are ideal to:

  • Comply with security regulations through high-level security and reduced effort.
    Improve user experience and oversight through IT on-behalf-of-user management, simplified self-service, and streamlined workflows.
  • Utilize identity investements to their fullest potential for secure and efficient identity management.
  • Satisfy customers’ unique identity needs with a flexible and adaptable solution.

Product News:

Meet vSEC:CMS 7.0 – A Mature FIDO Credential Management System

  • Multiple Passkeys Enrollment allows, during Issuance, the enrollment of one authenticator in more than two different IdPs and generates multiple passkeys simultaneously. This feature saves time and effort. Enroll a new employee to your selected IdPs from our list of available integrations (Entrust, Gluu, Microsoft Entra ID, Okta, Ping Identity, or Thales).
  • Credential Template Description found on the Issuance Screen (Agent and Admin apps) assists you in choosing the right template for management.
  • One Step Unregistration allows you to return a token or smartcard from every lifecycle stage to the factory default state. Automatically takes the identity device through revocation and clean up in one click.
  • System Health Information Panel lets you quickly see system health notifications on the Admin Home Screen and resolve them promptly. For urgent alerts, you can also choose to be notified by email.
  • Alerts to Webhook allow you to push system health events with HTTPS to add alerts to SIEM infrastructure, or similar.
  • PKI and FIDO Device PIN Selection allows you to request employees to set the PINs only for the technology to be used in combined devices (PKI + FIDO). Set up a PIN for PKI, FIDO, or both.
  • Four Plus PIV Certificate Support allows you to manage more than four PIV certificates, which is the PIV standard, on a PIV smart card or token. Functionality is limited to the PIV devices that offer a supporting MiniDriver.
  • Configuration Audit Trail collects system configuration changes, including username and time of changes. It provides accountability and tracks changes, increasing security and visibility.
  • Token2 PIN+ FIDO2 Security Keys Series can now be managed using our new HID interface integration. Allowing administration over USB as an alternative to the already available NFC interface integration.
  • Add New HSM By Migrating Admin Keys of the Credential allows you to switch to a new HSM with a new master key. Eliminates the need to migrate Master Keys between HSMs.
  • Entra ID User Information Extended allows you to utilize user information in Microsoft Entra ID for other integrations. Suitable for hybrid and cloud environments.
  • Passkey Dynamic Display Name allows you to edit the passkey display name for the user in the IdP. Lets you add a dynamic value instead of a fixed name for all users. It can be generated based on user-specific values.

vSEC:CMS

Starter Pack 1

€1.68

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • 100 Credentials
  • Customer On-Prem or Private Cloud
  • Professional Level Support
  • Full vSEC:CMS Feature Set

vSEC:CMS

Starter Pack 2

€1.42

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • 500 Credentials
  • Customer On-Prem or Private Cloud
  • Professional Level Support
  • Full vSEC:CMS Feature Set

vSEC:CMS

Starter Pack 3

€1.24

Per Credential Per Month
Yearly Subscription
Price Excl. Taxes

  • 1000 Credentials
  • Customer On-Prem or Private Cloud
  • Professional Level Support
  • Full vSEC:CMS Feature Set

vSEC:CMS

>1000 Credentials

Contact Sales
for Pricing

Contact us
  • Custom
  • Customer On-Prem or Private Cloud
  • Professional Level Support
  • Full vSEC:CMS Feature Set

Evaluation – Download Today!

Once downloaded and installed vSEC:CMS is ready for use in Evaluation Mode. During the evaluation, you can configure your environment with up to 10 licenses and your own use cases. Each license manages one credential. Additional licenses can be acquired as a subscription or by perpetual license. Please contact a Versasec reseller or Versasec directly to proceed.

Schedule a Demo

To enjoy the vSEC:CMS full feature set (including Self-Service, Virtual Smart Card, HSM support etc), schedule a demo with Versasec or contact your local Versasec reseller.

Scalability

The vSEC:CMS scales with your project. With the new load balancing capability, there is no upper limit!

Load Balancer

vSEC:CMS Connectors

Versasec Core Connections

Integrability – APIs

The vSEC:CMS can be integrated and connected in many different ways, the drawing below is trying to visualize the most commonly used options.

vSEC:CMS APIs

Migrate to vSEC:CMS

vSEC:CMS includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

vSEC:CMS system migration paths - never locked in!

vSEC:CMS system migration paths - never locked in!

vSEC:CMS  includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

Check out the details on how to upgrade from:

Resellers

The product can be purchased from authorized vSEC:CMS integrators and resellers, or directly from Versaseccontact Versasec to let us help you find the best way forward.

Versasec Supported Credentials

Versasec strives to support as many credential types as possible in all of Versasec’s products. We support PIV, PKI, Virtual, Physical Access, Logical Access, and FIDO/PIV, and FIDO only credentials. Versasec does not lock you in to one provider, we are credential-agnostic. The number of supported credential types is continuously increasing with every new product version. If you are using a credential that is not on the list, please contact Versasec to check if and when your credential will be supported. Supported Credentials: https://versasec.com/products/supported-credentials/

Product Features

The table below highlights the key features in the Versasec credential management product suites.

 

vSEC:CLOUD

vSEC:CMS

User-Side Credential Operations

Agent-Side Credential Operations

  • Admin Key Change
  • Online Unblock User PIN
  • Offline Unblock User PIN (Operator Side)
  • User PIN Policy Update
  • Certificate Management (pfx or p12 Import, Delete)

Advanced Credential Operations

  • Admin Key Diversification
    from Hardware Protected Masterkey
  • User Fingerprint Policy Update
  • Batch Mode Support
  • Interface Management
  • Custom Data on Credential Management
  • Contact and Contactless (NFC)

Database

  • Credential Repository
  • SQL-based Databases
  • Backup / Restore
  • Multi-forest & Multi-domain

Credential Management System Features

 

vSEC:CLOUD

vSEC:CMS

Product Features

Advanced Management Features

  • User Self-service and MS Credential Provider
  • Key Archive and Key Restore
  • Smart Card Stock Management
  • Granular Operator Permissions and Access Control
  • Card Printing and Batch Processing
  • Photo Capturing
  • Remote Security Device Management (RSDM)
  • Certificate Management using ACME
  • FIDO2 Enterprise Management

Systems Integrations

  • Certification Authorities
  • User Directories
  • Physical Access System (RFID)
  • Identity Providers (IdP)
  • Windows Event Log
  • Mail Server
  • Hardware Security Module (HSM)

Integrations/APIs

Server-Side
  • SQL Database Interface
  • SOAP Helpdesk API
  • SOAP Lifecycle API
  • REST Lifecycle API
Client-Side
  • COM API
  • Web Start API
  • Plugin API
  • Physical Access System (PACS) API
 

vSEC:CLOUD

vSEC:CMS

Licensing/Packaging

Managed by Versasec

 

Subscription

Perpetual Licenses

 

Installation Package

 

NOTE
✔ – The credential is supported by the product.
L – Known limitations – check release notes.
For details about validated middleware/minidrivers check the Versasec support portal or contact us.

vSEC:CMS

Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.

Start here

Free Product Trial

Versasec provides enabling IT security products centered on the usage of security devices such as smart cards. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Get a free product trial.

Job Openings

We are always looking for new exceptional persons to join our team! Find out more about our job openings.

New to credential management?

SCMS = Smart Card Management Systems
CMS = Credential Management System
Have a look at the Wikipedia definition of a ‘Smart Card Management System’.

Versasec Support

Versasec customers with an existing support and maintenance contract can access the Versasec Support Portal, offering extensive professional support and maintenance services. The Versasec Support Portal offers a variety of services, allowing for customers and any site visitor to communicate directly with support engineers.

Visit Support

Company Blog

Our blog addresses the latest security trends and stories. The posts discuss how identity and access management are playing a larger role in keeping corporate data safe as well as brand reputations intact.

Visit our Blog