PKI Credential Management
Seamlessly deploy PKI smart cards, (security keys, authenticators, credentials) at scale.

Manage the deployment of PKI-based digital identities to enable robust passwordless authentication and empower users to safely sign transactions, encrypt emails, and authenticate into systems, applications, and networks, requiring the highest authenticator assurance levels.
PKI/PIV Card (Security Key) Management
The Versasec PKI/PIV card (credential, security key, smart card, token) management offer includes the following functions:
- Issue cryptographically secure digital identities using PKI keys and certificates to smart cards, USB tokens, WHfB, and virtual smart cards.
- Configure certificate and device lifecycle management workflows to ensure the right people receive the appropriate digital credentials.
- Issue credentials centrally automatically and in batch, by helpdesk on-behalf of users, or through self-service. Print on converged badges with a smart card printer – useful for batch issuance and visual identification customization.
- Provide key archiving and recovery, allowing keys and certificates to be deployed to multiple devices for email encryption and recovery in case of loss of PKI credential.
- Offer high levels of user service with straightforward process-driven features for help desks and self-service users to issue replacement devices upon loss or reactivate locked devices.
- Maintain complete auditability and reporting, providing visibility into who issued which digital credentials to which users and on what device, aiding external audits and compliance with identity management guidelines.
- Equip users with phishing-resistant multi-factor authentication (MFA).
- Combine PKI certificate use cases with FIDO2 and physical access.
Download
Free Evaluation
Isn’t it time to start managing your organization’s security effectively? Download a free evaluation version of our powerful vSEC:CMS and see how quickly and easily you can keep your company safe. Register to download Versasec software.
Book now
Schedule a Demo
Talk to our experts about your business requirements, current ecosystem, and plans for the future. Let us walk alongside your IT business priorities, and make the most out of your IAM investments.
Versasec Supported Credentials & Passwordless Authenticators
Versasec strives to support as many credential types as possible in all of Versasec’s products. Below are phishing-resistant credentials we support. We hope one fits your enterprise, users, and devices. Not all multi-factors are created equal. Customize based on your organizational needs and goals. We support PIV, PKI, Virtual, Physical Access, Logical Access, and combined FIDO+PIV, and FIDO-only credentials. Versasec does not lock you in to one provider, we are credential-agnostic. The number of supported credential types is continuously increasing with every new product version. If you want to manage a different credential, currently not on our list, please contact us at info@versasec.com.
* Tokens and smart cards with FIDO2

ACS
Atos
Ensurity
Feitian
Open FIPS
Safe Trust
Swissbit
Taglio
TCOS
Thales IDPrime .NET 5500
Thales IDPrime MD 830
Thales IDPrime MD 840
Thales IDPrime MD 930
Thales IDPrime MD 940/940C/940 CC
Thales IDPrime MD 3810
Thales IDPrime MD 3840
Thales IDPrime MD 3930
Thales IDPrime MD 3940
Thales IDPrime MD 3940 FIDO *
Thales IDPrime PIV 2.1
Thales IDPrime PIV 3.0
Thales IDPrime Virtual
Thales MultiApp ID
Thales SafeNet eToken 5100, 5110 FIPS, 5110+ FIPS, 5110+ CC
Thales Safenet eToken 5300
Thales SafeNet eToken FIDO*
Thales SafeNet eToken Fusion/CC *
Thales SafeNet eToken Fusion FIPS*
Thales SafeNet eToken Fusion NFC PIV*
Thales SafeNet IDCore 3121 FIDO*
*Tokens and smart cards with FIDO2
Versasec Demos and Webinars
Versasec’s YouTube channel contains multiple curated demos and webinars to showcase products and solutions, from PKI use cases to FIDO orchestration.

Deploying with Versasec Credential Management
Versasec’s state-of-the-art system is helping enterprises worldwide adopt secure authentication technology for web and app authentication devices in today’s cyber world. Enterprises are saying goodbye to confusion and manual siloed systems and welcoming efficient, simple, and cost-effective core solutions.

Versasec Ecosystem
Versasec performs at the security core of organizations.
The Core of Identity & Access Management blog post explores the most popular connections facilitated by our innovative systems. Discover how it can revolutionize your enterprise orchestration journey and enhance security within your organization.
FAQs
We’re glad you asked! PKI hardware tokens and smartcards are being added to our supported credentials page monthly. Please contact your Versasec representative for the latest updates and what is coming in the future. If you have any preferences, we’d love to know!
The paradox between FIDO and PKI comes down to the organization’s goals, users, budget, and systems in place. If you’re asking this question, you’re on the right track. Consider using one of our consulting partners in your region if you need further guidance, or our professional services team, specialized in FIDO enterprise orchestration.
You do not have to choose you can have both as vSEC:CMS can manage PKI and FIDO combined credentials to solve all authentication and PKI use cases. For more information, watch our FIDO webinar, PIV and FIDO: Defense Against Cyber Threats.
According to the “Recommended Best Practices for Administrators on Identity and Access Management” by the US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), “Authentication systems are the front doors to enterprise networks, applications and data. As such, attackers are highly focused on finding and exploiting authentication vulnerabilities.”
They present a chart ranking the weakest to strongest types of multi-factor authentication. In the weakest, they place SMS or voice MFA. In the middle, app-based MFA, including OTP and mobile-push notifications. At the strongest, phishing-resistant MFA, including public-key infrastructure (PKI) and FIDO. To read more in detail about their conclusions and their advice, read the full article here.
Versasec offers many migration paths (wizard) from other credential management systems (CMS or SCMS). We also provide pre-built paths for:
- Microsoft MIM/FIM migrations
- Thales SafeNet Authentication Manager (SAM) identity and access card management system
- Gemalto DAS / IDAdmin 100 smart card management tool
To migrate to vSEC:CLOUD, customers do not need to be on vSEC:CMS, but can migrate directly from any other CMS/SCMS.
vSEC:CLOUD is a service of our credential management software vSEC:CMS. Fully subscription based and deployed in a virtual private cloud, Versasec will manage server hosting and upgrades for customers of all sizes.
Implement Highly Secure Identity Management with Versasec and Microsoft Entra ID
Passwords and traditional multifactor authentication (MFA) are no longer sufficient for keeping identities secure. Many businesses want to upgrade to stronger credential strategies but are not sure where to start.
Luckily, adopting phishing-resistant MFA doesn’t have to be complicated.

Effortlessly deploy and manage passwordless identity security across your organization with Versasec’s Credential Management System, vSEC:CMS, and Microsoft Entra ID. In our eBook, The Next Evolution in Credential Security, we explore how organizations can:
- Implement highly secure identity management with ease.
- Streamline the deployment of FIDO2 passkeys.
- Integrate your access security ecosystem.
Comprehensive identity management has never been easier to achieve.
Get Your Copy
Recent Articles on PKI Credential Management
2025-10-22
Beyond PIV: Credential Management for High-Assurance Environments
High-assurance environments can move "Beyond PIV" by adopting a centralized Credential Management System (CMS) to…
2025-10-09
Why Security is the Non-Negotiable Infrastructure Foundation
In an exclusive interview, Versasec board member Fredrik Runnquist shares his 28 years of experience as a Head of IT…
2025-06-23
AHP’s Smart Card Management Journey
We're excited to feature Air Hydro Power's journey in our latest case study, where you'll discover how they optimized…
2025-05-28
MFA Solutions for Saudi Arabia
Explore how Versasec is strengthening cybersecurity in Saudi Arabia with solutions that meet NCA mandates for…
2025-04-02
7.0 – A Mature FIDO Credential Management
Dive into what vSEC:CMS Version 7.0 is capable of! Versasec introduces its new version of its credential management…
2025-02-26
Welcoming Version 7.0
Twelve versions later, we are closing the vSEC:CMS version 6 feature set and welcoming 7.0! With this new version,…







