Solutions · Government & Public Sector

Certificate management for the mission-critical.

FedRAMP-authorised, NIST 800-53 aligned, and ready for air-gapped and classified environments. TigerTrust delivers the assurance federal, state, and defence programmes require — without the legacy PKI drag.

The problem

Federal PKI shouldn't require a decade-old certificate binder.

Agencies run PIV/CAC alongside cloud workloads alongside classified enclaves. Legacy CA silos, air-gapped signing ceremonies scheduled quarterly, and evidence gathered by hand — none of it scales to zero-trust mandates.

Without modernised government PKI
  • PIV/CAC, DoD PKI, and cloud CAs each run in isolation with no shared inventory
  • Executive Order 14028 zero-trust milestones missed for lack of automation
  • Air-gapped signing ceremonies gate every root operation
  • CMMC Level 2/3 gaps block DoD contract eligibility
  • FedRAMP continuous monitoring evidence gathered manually every month
With TigerTrust government PKI
  • FedRAMP Moderate / High deployments in AWS GovCloud and Azure Gov
  • PIV/CAC and derived credentials issuance under NIST SP 800-157 / -217
  • Air-gapped signing enclave with quorum control and full ceremony logs
  • CMMC 2.0, NIST 800-171, and NIST 800-53 evidence continuously
  • CNSA 2.0 crypto-agile posture ready for the PQC transition
FedRAMP

Authorised for federal cloud workloads

Deploy in AWS GovCloud or Azure Government under a FedRAMP Moderate authorisation boundary. Continuous monitoring evidence flows straight into agency POA&Ms.

How it works
  • FedRAMP Moderate and High baselines
  • AWS GovCloud, Azure Government, Oracle Gov
  • Continuous monitoring artefacts
  • SSP-ready control descriptions
Government cloud infrastructure compliance dashboard
Air-gapped

Classified and offline deployments

TigerTrust runs fully disconnected for IL5/IL6 workloads. Root CA ceremonies use quorum-controlled offline signing with cryptographically signed ceremony records.

How it works
  • Fully air-gapped deployment mode
  • Quorum-controlled root signing (M-of-N)
  • Signed ceremony transcripts
  • IL5 / IL6 architecture patterns
Air-gapped secure facility for cryptographic operations
PIV & CAC

Personal identity verification at scale

Issue PIV and CAC credentials and their derived counterparts for mobile access, per NIST SP 800-157 and SP 800-217. Integrate with existing IDMS and card printing.

How it works
  • NIST SP 800-73 / -78 / -157 / -217 compliant
  • Derived PIV for mobile
  • IDMS integration (SailPoint, Saviynt)
  • Card printing workflow
Government workforce using PIV cards for access
Crypto agility

CNSA 2.0 and post-quantum ready

Issue in FIPS-approved suites today; migrate to NIST-selected PQC algorithms on your timeline. Full crypto-agility across the CA hierarchy.

How it works
  • CNSA 2.0 suite support
  • PQC hybrid certificates (ML-KEM, ML-DSA)
  • Algorithm inventory and migration planning
  • Root rotation without service disruption
Cryptographic infrastructure prepared for post-quantum migration
For the mission

The controls federal auditors expect. Automated.

From CISA directives to CMMC 2.0 contract requirements — every capability accounted for.

FedRAMP artefacts
SSP text, control implementation, and ConMon evidence.
  • Moderate & High
  • Auditor share links
  • POA&M export
FIPS 140-3
Validated cryptography with HSM-backed root keys.
  • Level 3 HSMs
  • Approved suites
  • Air-gapped signing
PIV / CAC issuance
Full lifecycle for federal identity credentials.
  • NIST 800-73/78
  • Derived PIV
  • IDMS integration
CMMC 2.0
NIST 800-171 controls for DoD contract eligibility.
  • Level 2 / 3 mapping
  • Assessor evidence
  • Continuous posture
Zero-trust support
EO 14028 and CISA ZTMM alignment.
  • Identity pillar
  • Workload identity
  • Device attestation
Sovereignty
Region-pinned deployments for allied governments.
  • UK Gov, EU sovereign
  • Data residency
  • ITAR-aware ops

Federal deployment metrics

FedRAMP
Moderate authorised
FIPS 140-3
Validated cryptography
IL5
Air-gapped deployment ready
100%
NIST 800-53 control coverage
Case study
Federal agency · US government

Zero-trust identity milestone met nine months ahead of EO 14028 deadline.

We needed workload identity for the cloud-native pillar and legacy PIV support in the same platform. TigerTrust was the only vendor that did both without a second contract.
Chief Information Security Officer
9 mo
Ahead of EO 14028 milestone
IL5
Air-gapped deployment ready
100%
NIST 800-53 control coverage
Integrations

Fits your existing stack

Government cloud, IDMS, HSMs, and identity systems federal, state, and defence programmes already run on.

AWS GovCloud
Gov cloud
Azure Government
Gov cloud
Oracle Gov Cloud
Gov cloud
Thales Luna FIPS 140-3
HSM
Entrust nShield
HSM
AWS CloudHSM
HSM
SailPoint
IDMS
Saviynt
IDMS
PIV / CAC card printers
Credentials
Splunk Enterprise
SIEM
DoD PKI
Federated trust
Federal Bridge CA
Federated trust
FAQ

Frequently asked questions

TigerTrust is deployable in AWS GovCloud and Azure Government under a FedRAMP Moderate authorisation boundary, with High baseline support for programmes that require it. Continuous monitoring evidence flows into agency POA&M workflows. System Security Plan (SSP) text and control implementation descriptions are provided so authorising officials can plug them straight into the ATO package.
Yes. Full lifecycle for PIV (NIST SP 800-73 / -78) and CAC credentials plus derived PIV for mobile per SP 800-157 and the SP 800-217 profile. Integrates with existing IDMS platforms (SailPoint, Saviynt) and card printing workflows. Supports content signing, card authentication, digital signature, and key management certificates on card.
TigerTrust runs fully disconnected for IL5 / IL6 classified workloads. Root CA ceremonies are performed offline with quorum-controlled M-of-N signing and cryptographically signed ceremony transcripts. All updates are delivered via sneakernet with digitally signed release bundles. There is no phone-home requirement.
CMMC 2.0 Level 2 and Level 3 controls are mapped out of the box, drawing on the underlying NIST 800-171 requirements. Continuous posture reports are generated for the assessment cycle. For prime contractors managing subcontractor compliance, tenant delegation lets each sub operate independently while central visibility remains intact for the prime.
TigerTrust is crypto-agile: RSA, ECDSA, and CNSA 2.0 suites today, with NIST-selected PQC algorithms (ML-KEM, ML-DSA) available in hybrid certificates now. Algorithm inventory reports show which endpoints use which suites, and root rotation planners let you sequence the migration without service disruption. NSA CNSA 2.0 timelines are supported.
Yes. UK Government Cloud, EU sovereign cloud offerings (T-Systems, Bleu, Delos), and allied nation equivalents are supported. Data residency, cross-border operations, and ITAR-aware deployments are documented. Region-pinned issuance and log storage let you comply with sovereignty requirements without maintaining separate PKI teams per nation.

Modernise the PKI the mission depends on.