Public sector, Axiad Conductor vs Entrust

The PIV card is the strongest credential in the building. The gap is everywhere it does not reach.

Migrate derived PIV credential issuance from Entrust to Axiad Conductor without disrupting existing PKI infrastructure. Reduce licensing costs and give the CIO a consolidated compliance reporting view aligned with OMB zero trust.

Two ways to build this

A certificate platform issues certificates. A credential platform manages identity.

Entrust built its federal business on public key infrastructure: certificate authorities, hardware security modules, and the certificates they issue. That layer works, and Conductor runs on top of it wherever an agency wants to keep it. The work federal identity now requires sits above that layer: getting a phishing-resistant credential to every person and machine, keeping it current, revoking it the hour acontract ends, and producing the evidence without an export. That is the layer Axiad built.

A certificate platform
The requirement

Certificates, from a CA the agency operates or a managed service.

Who assembles the lifecycle

The agency, from middleware on the endpoint, a separately licensed derived-credential product, help-desk procedure for expiry and separation, and exports for the auditor.

What licensing follows

The certificate. Every new device, token, and machine identity is another line item.

What the team runs

The CA, the HSM refresh cycle, the patching, and the specialists who keep it up.

The population map

Who has a phishing-resistant credential today, and who does not

OMB M-22-09 requires phishing-resistant MFA for agency staff, contractors, and partners. Most agencies can answer for the PIV holders at a desk. The comparison is about everyone else, and about the people who run the platform.

How Conductor does it
PIV holders
Covered at the desktop. Not on the phone, the tablet, or the workstation with no reader.
The card’s trust travels to every device the person works from, with nothing new to badge.
Derived PIV under NIST SP 800-157, issued from the card the agency already trusts onto phones, tablets, and USB tokens. Same lifecycle, same audit trail. Self-service enrollment, no middleware on the device.
New hires in the PIV queue
Ninety days, often longer, on a password. The requirement does not carve out the first quarter of employment.
Phishing-resistant access on day one. The password window closes.
Interim and PIV-compatible credentials issued under the same policy and revocation as thecard, converting or expiring automatically when the PIV arrives.
Contractors and affiliates
Often never PIV-eligible. Access ends when someone remembers to end it.
Every contractor on the same credential standard as staff, and off the system the hour the contract ends.
Certificate-based, hardware-bound credentials for non-PIV populations: smart card, FIDO2 security key, or mobile. Revocation on separation is driven from the identity source over SCIM, not from an offboarding checklist.
Machines and workloads
Domain controllers, servers, network gear, service accounts. Expired certificates take production down, and nobody owns the renewal.
Machine identities on the same lifecycle as people, renewed before they expire, in the same view the CIO sees.
Conductor NHI in the FedRAMP Moderate cloud offering: ACME, SCEP, EST, and CMP enrollment; an auto-enrollment proxy that registers as a standard CA in the Active Directory forest; templates, notification policy, and role-based administration.
The team that runs it
HSM refresh cycles, CA patching, hard-to-hire specialists, and a help-desk ticket for every expired credential.
The team stops running infrastructure and starts running policy. The next refresh comes off the budget.
FedRAMP Moderate cloud PKI as a Service in a dedicated VPC per agency, with FIPS 140-2 validated HSM partitions that are ours to operate. For classified or disconnected enclaves, 
on-premises UCMS inside the agency boundary, issuing against the CA you already run.
For the executive

Two outcomes to hold any credential platform to

Evidence produced, not assembled

One audit trail across every population the platform issues to, mapped to the NIST SP 800-53 Rev. 5 controls under the FedRAMP authorization, exported to the SIEM the agency already runs. When the Inspector General asks who had access to what on a given date, the answer is a report, not a two-month project. The consolidated compliance reporting view DOJ’s CIO gained is this outcome, in production.

2030 as a lifecycle motion

Executive Order 14412 sets December 31, 2030 for key establishment and December 31, 2031 for digital signatures to be migrated to post-quantum cryptography. OMB M-26-15 calls a continuously updated inventory the foundation of the migration plan. A platform that already renews every credential it issues from policy, and keeps the algorithm on each one, turns the algorithm change into a renewal cycle. Conductor’s support tracks FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) as your CAs adopt them. Nobody should sell you quantum-safe issuance ahead of that, and we do not.

How one agency did it

The Department of justice

The requirement

A federal PKI the agency had invested in and trusted, with Entrust issuing derived PIV credentials on top of it.

What moved

Derived PIV credential issuance moved to Axiad Conductor. The existing PKI infrastructure stayed where it was, and the transition ran without disrupting it. Conductor connected to what the agency already operated and took over issuance for the populations and devices the card does not reach.

What changed

Licensing costs came down. The CIO gained a consolidated compliance reporting view aligned with OMB zero trust, produced by the platform rather than assembled by hand across systems.

Today

Conductor’s FedRAMP Moderate cloud offering runs in production 
at the Department of Justice.

Why Axiad knows where the gaps are

Axiad has run PKI and credential lifecycle for the federal government and defense community for more than sixteen years. The populations on this page are the ones we have watched fall outside every PIV program.

Federal production references:
Department of Justice
CDC
USPTO
Department of Energy
For the evaluation file

The comparison as checkable lines

For the practitioner and the contracting office. Axiad’s column is stated as fact. The other column is the written question to put to the incumbent, so the file carries their answer, not ours.

Authorization
FedRAMP Moderate Authorized, FedRAMP Marketplace ID FR2333756970. The cloud offering runs in a dedicated VPC per agency.
Which product is on the FedRAMP Marketplace, at what impact level, under what ID? Check it at marketplace.fedramp.gov.
One platform or several
One console issues and runs the lifecycle for human and non-human credentials: PIV-derived, interim, contractor and affiliate populations, and machine certificates.
How many separately licensed products cover derived credentials, credential management, and machine certificates, and how many consoles does the team log into?
Derived PIV
Derived credentials under NIST SP 800-157 from the PIV card the agency already issued, onto phones, tablets, and USB tokens. Self-service enrollment, no middleware on the device.
Is derived PIV inside the base license or priced as a separate product, and does enrollment require middleware or an agent on each device?
Licensing
Entity-based: priced per active identity, not per certificate issued. Temporary and interim credentials consume the same license.
Is pricing per certificate, per credential, or per identity, and what is the 
year-over-year escalator written into the term?
Infrastructure
Cloud offering: no HSMs to buy, no CA servers to patch; FIPS 140-2 validated HSM partitions inside the VPC. Separately, on-premises and air-gapped UCMS inside the agency boundary, issuing against the CA you operate.
Which HSM and CA hardware refreshes fall inside the contract term, and who funds them?
Lifecycle automation
Issuance, renewal, revocation, and device swap run from policy. Revocation on separation is automatic, not an off boarding checklist item.
When a contractor’s access has to be cut on a Friday afternoon, who does it, and how long does it actually take?
Evidence
One audit trail across every population Conductor issues to, exportable to your SIEM, with controls mapped to NIST SP 800-53 Rev. 5 under the FedRAMP authorization.
How many exports, from how many systems, does the identity-control evidence take today?
Algorithm rollover
Architecture built for rollover; support tracks FIPS 203, 204, and 205 as your CAs adopt them, so rollover runs as a lifecycle motion instead of a re-enrollment program.
What is the written post-quantum roadmap for the exact product being evaluated, with dates against December 31, 2030 and December 31, 2031?
Federal production
In production at DOJ, CDC, USPTO, and DOE.
Which agencies run this exact configuration in production today?
How to buy
Via Carahsoft on GSA MAS, NASA SEWP, and NASPO ValuePoint. Current list at carahsoft.com/axiad/contracts.
Which contract vehicle carries the product, and through which reseller?
The transition path

You do not have to leave Entrust on day one

Conductor runs alongside the CA your agency operates today, Entrust included, and can issue against it. Agencies move in three steps. Each one is reversible, and each one produces its own evidence.

Run alongside

Conductor connects to the existing CA and your identity provider over SAML and SCIM. Interim hires, contractors, affiliates, and derived-PIV users enroll first: the populations PIV was never built for, and the ones on passwords today.

Move issuance

When the agency is ready, issuance moves to Conductor’s FedRAMP Moderate cloud PKI as a Service. Where the chain has to validate against existing PKI, the issuing CA is cross-signed to your trust anchor. The HSM refresh leaves the budget.

Retire the legacy CA

When the last certificate the legacy CA issued expires, it is decommissioned. Machine identities join the same lifecycle in the cloud offering through ACME, SCEP, EST, and CMP.

Note: Publicly trusted certificates stay with your existing public CA. Conductor issues private trust.

Stated precisely

The lines an evaluator checks, written the way we would want to read them

FedRAMP attaches to the cloud offering

On-premises and air-gapped UCMS runs inside the agency boundary and issues against the CA you operate. It does not carry the authorization, and we will not describe it as if it did.

FIPS 140-2 validated

The validation level (Level 2 or Level 3 partitions) is confirmed per engagement and written into the quote, not asserted on a web page.

Conductor tracks what it issues

Discovery of certificates issued elsewhere in your estate is a separate conversation and a separate product.

Axiad Mesh is not on the FedRAMP Marketplace today

We state that up front rather than making you dig for it.

Private trust only

Public-trust certificates stay with your existing public CA; the two coexist.

Post-quantum support tracks the NIST standards

Quantum-safe issuance follows your CAs’ adoption of FIPS 203, 204, and 205. We do not sell it as shipping ahead of that.

Bring your populations

A 30-minute working session with our public sector team. We fill in the population map for your agency: who has a phishing-resistant credential today, who does not, and what closes each gap. The map is yours to keep.

FedRAMP Moderate Authorized (Conductor). Frost and Sullivan Customer Value Leader. Gartner Market Guide Recognized. ISO/IEC 27001. SOC 2 Type II.

Copyright Axiad 2026. All rights reserved.