Migrate derived PIV credential issuance from Entrust to Axiad Conductor without disrupting existing PKI infrastructure. Reduce licensing costs and give the CIO a consolidated compliance reporting view aligned with OMB zero trust.
Entrust built its federal business on public key infrastructure: certificate authorities, hardware security modules, and the certificates they issue. That layer works, and Conductor runs on top of it wherever an agency wants to keep it. The work federal identity now requires sits above that layer: getting a phishing-resistant credential to every person and machine, keeping it current, revoking it the hour acontract ends, and producing the evidence without an export. That is the layer Axiad built.
Certificates, from a CA the agency operates or a managed service.
The agency, from middleware on the endpoint, a separately licensed derived-credential product, help-desk procedure for expiry and separation, and exports for the auditor.
The certificate. Every new device, token, and machine identity is another line item.
The CA, the HSM refresh cycle, the patching, and the specialists who keep it up.
Phishing-resistant, hardware-bound credentials for people and machines, from its own FedRAMP Moderate PKI as a Service or against the CA you already run.
Enrollment, renewal, device swap, and revocation from policy, with derived PIV from the card the agency already trusts.
The identity. One active person or machine is one license, however many credentials it carries.
One audit trail across every population, exportable to the SIEM.
OMB M-22-09 requires phishing-resistant MFA for agency staff, contractors, and partners. Most agencies can answer for the PIV holders at a desk. The comparison is about everyone else, and about the people who run the platform.
One audit trail across every population the platform issues to, mapped to the NIST SP 800-53 Rev. 5 controls under the FedRAMP authorization, exported to the SIEM the agency already runs. When the Inspector General asks who had access to what on a given date, the answer is a report, not a two-month project. The consolidated compliance reporting view DOJ’s CIO gained is this outcome, in production.
Executive Order 14412 sets December 31, 2030 for key establishment and December 31, 2031 for digital signatures to be migrated to post-quantum cryptography. OMB M-26-15 calls a continuously updated inventory the foundation of the migration plan. A platform that already renews every credential it issues from policy, and keeps the algorithm on each one, turns the algorithm change into a renewal cycle. Conductor’s support tracks FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) as your CAs adopt them. Nobody should sell you quantum-safe issuance ahead of that, and we do not.
A federal PKI the agency had invested in and trusted, with Entrust issuing derived PIV credentials on top of it.
Derived PIV credential issuance moved to Axiad Conductor. The existing PKI infrastructure stayed where it was, and the transition ran without disrupting it. Conductor connected to what the agency already operated and took over issuance for the populations and devices the card does not reach.
Licensing costs came down. The CIO gained a consolidated compliance reporting view aligned with OMB zero trust, produced by the platform rather than assembled by hand across systems.
Conductor’s FedRAMP Moderate cloud offering runs in production at the Department of Justice.
Axiad has run PKI and credential lifecycle for the federal government and defense community for more than sixteen years. The populations on this page are the ones we have watched fall outside every PIV program.
For the practitioner and the contracting office. Axiad’s column is stated as fact. The other column is the written question to put to the incumbent, so the file carries their answer, not ours.
Conductor runs alongside the CA your agency operates today, Entrust included, and can issue against it. Agencies move in three steps. Each one is reversible, and each one produces its own evidence.
Conductor connects to the existing CA and your identity provider over SAML and SCIM. Interim hires, contractors, affiliates, and derived-PIV users enroll first: the populations PIV was never built for, and the ones on passwords today.
When the agency is ready, issuance moves to Conductor’s FedRAMP Moderate cloud PKI as a Service. Where the chain has to validate against existing PKI, the issuing CA is cross-signed to your trust anchor. The HSM refresh leaves the budget.
When the last certificate the legacy CA issued expires, it is decommissioned. Machine identities join the same lifecycle in the cloud offering through ACME, SCEP, EST, and CMP.
Note: Publicly trusted certificates stay with your existing public CA. Conductor issues private trust.
On-premises and air-gapped UCMS runs inside the agency boundary and issues against the CA you operate. It does not carry the authorization, and we will not describe it as if it did.
The validation level (Level 2 or Level 3 partitions) is confirmed per engagement and written into the quote, not asserted on a web page.
Discovery of certificates issued elsewhere in your estate is a separate conversation and a separate product.
We state that up front rather than making you dig for it.
Public-trust certificates stay with your existing public CA; the two coexist.
Quantum-safe issuance follows your CAs’ adoption of FIPS 203, 204, and 205. We do not sell it as shipping ahead of that.