HSMs and PKI for classified information
Target architecture with device selection and migration plan
More on thisIndustries / Defense
Protect sensitive information with hardware cryptography and controlled access.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We integrate hardware security modules into PKI, signing, and encryption services, build sovereign platforms in data centers located in Germany, and design security architectures based on zero trust.
Target architecture with device selection and migration plan
More on thisZero trust architecture with domain concept
More on thisDevelopment and supply chain concept with threat model
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Hardware security modules generate and store keys in a certified environment that no key leaves in plain text. For classified information up to VS-NfD, EU RESTRICTED and NATO RESTRICTED we deploy HSMs with the matching BSI approval, such as Utimaco CryptoServer with the VS-NfD package, and plan the move to successor devices before end of support. On this foundation we build PKI, signing and encryption services whose algorithms follow BSI TR-02102. Key ceremonies with roles, quorums and records are part of every commissioning.
A defense supplier replaces the software keys of its PKI with VS-NfD approved HSMs; the root CA is created in a recorded ceremony and the issuing CAs issue certificates for people, devices and code.
Our approach
Sovereign hosting means that data, keys and operations stay under German control and no provider outside the EU gains access. We build private and hybrid platforms in data centers in Germany, separate network zones by protection need and automate provisioning and operations with Kubernetes and Terraform. Data at rest is encrypted with keys from the HSM, and every change to the platform remains traceable through code and logs.
A security authority moves collaboration and specialist applications from a provider outside the EU to a platform in a German data center; the keys sit in its own HSM and the location can be proven.
Our approach
Zero trust verifies every access individually by identity, device and context instead of trusting an internal network by default. We design security architectures on this principle, harden systems under BSI IT-Grundschutz and separate domains of different classification with data diodes and gateways that inspect content and enforce release rules. For exchange with allies we label data under STANAG 4774 and bind the label to the content under STANAG 4778. A SIEM detects attacks across all systems, and a rehearsed incident response process reacts to them.
An authority exchanges situational data with partners through a gateway with content inspection; every file carries a confidentiality label and leaves the domain only after a defined release.
Our approach
Classified information on notebooks, file servers and removable media needs encryption that the BSI has approved for the respective level. We roll out Utimaco LAN Crypt for files and folders and Utimaco DiskEncrypt for hard disks, both approved for VS-NfD and usable for EU RESTRICTED and NATO RESTRICTED. Roles separate administration and security officers, smartcards hold the users' keys and policies encrypt transparently without users changing the way they work.
A supplier under industrial security clearance rules rolls out LAN Crypt and DiskEncrypt to all project devices; the security audit receives approval documents, policies and configuration evidence.
Our approach
Software in operational systems must prove what it consists of, who built it and that it arrives unchanged at the user. We develop and operate specialist applications with build pipelines that record every component in a software bill of materials, check dependencies for known vulnerabilities and sign artifacts with keys from the HSM. Air-gapped environments without network connection are supplied through verified transfer paths, and development, test and operational environments stay separate.
A maker of operational software introduces signed builds with a bill of materials; the client verifies signature and component list before every installation in the air-gapped environment.
Our approach
Classified information stays sensitive for decades, longer than RSA and elliptic curves are expected to remain secure by current assessment. We inventory algorithms, keys and certificates across HSMs, PKI, VPN and applications and rate them by protection period. We plan the migration to ML-KEM and ML-DSA in hybrid modes, as BSI TR-02102 recommends for the transition period. Because allies follow their own timelines, every algorithm stays aligned with partners and replaceable.
A procurement office inventories the cryptography across PKI, VPN and device certificates; the root CA moves to hybrid certificates first, the gateways follow with the next device refresh.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Defense
The PKI issues certificates with software keys, the client demands keys in approved hardware and a crypto concept.
VS-NfD approved HSMs, root CA in a recorded ceremony, issuing CAs on EverTrust PKI, crypto concept under BSI TR-02102.
Keys in certified hardware, complete ceremony records, crypto concept for the industrial security audit.
02 / Defense
Specialist applications and collaboration run with a provider outside the EU, the keys sit with the provider, the data location cannot be proven.
Platform in a German data center with zones by protection need, keys in the authority's own HSM, infrastructure as code, operation under ISO 27001.
Provable location, key sovereignty with the authority, documented operation with exit concept.
03 / Defense
A client's classified information sits on notebooks without approved encryption, and the audit is imminent.
Encryption concept, rollout of LAN Crypt and DiskEncrypt with smartcards, roles for administration and security officers.
Approved encryption on all project devices, audit file with approvals and configuration evidence.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Classification, protection needs, systems and gaps in approval and operation
Security architecture, crypto concept, operating model
HSMs, PKI, platform and encryption in stages
Monitoring, key maintenance, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from HSMs and PKI for classified information to a post-quantum roadmap, planned, integrated and operated by OTOKO®. BSI approvals and interoperability with allies are requirements of the architecture, not checkpoints added later. The entire solution runs in German data centers.
IT solutions for defense and security process classified information only in components approved for the respective level, keep key material and data under German control and remain interoperable with allies and NATO structures. OTOKO® covers six fields of action: HSMs and PKI for classified information, sovereign hosting in German data centers, zero trust with domain separation and attack detection, file and disk encryption approved for VS-NfD, a secure software supply chain, and a post-quantum roadmap with interoperability for partners.
The difference to a pure consulting project lies in approval, operations and evidence. Every component, key ceremony and release gets a record, a version and the documents that security officers, BSI IT-Grundschutz and auditors ask for. Cryptography and hardware security modules are our core competence. Keys for PKI, signatures and encryption therefore live in approved devices instead of software.
Cryptography and hardware security modules are our core competence. BSI approved HSMs, PKI and key ceremonies are planned and operated the way security clearance rules and BSI TR-02102 demand.
The entire solution runs in German data centers. From the HSM to the collaboration platform, with a provable location and key sovereignty on your side.
We work with operators of critical infrastructure and regulated industries. We know what security officers, clearance authorities and auditors expect from a provider.
One team accompanies you from consulting to operations. Cryptography specialists, platform engineers and developers stay on without handover to third parties.
Most organizations do not fail on technology but on standard tools without approval, keys in software and supply chains without evidence.
01
Classified documents sit on ordinary file servers and notebooks, the encryption is not approved for VS-NfD and nobody can prove the protection.
02
PKI, signing services and VPN gateways keep private keys in working memory, where malware and memory dumps can extract them.
03
Software arrives without a bill of materials, builds are unsigned and dependencies from external sources flow unchecked into operational systems.
04
Collaboration and documents run with providers outside the EU, the keys sit with the provider and the location of the data cannot be proven.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your data center, your HSMs, physically separated zones | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, unclassified data only, region Germany |
| Operation | Your team or OTOKO® as managed service | OTOKO®, access under the four-eyes principle and logged | Shared, platform services by the provider |
| Tools | CryptoServer or Luna on site, LAN Crypt, DiskEncrypt, Kubernetes | Hosted HSMs and PKI, sovereign platform, data diodes to your network | Cloud HSM services, collaboration and analytics for unclassified data |
| Suited for | Classified information, PKI root, operational systems | Authorities and contractors with sovereignty needs | Unclassified data, training, scaling at peak load |
| Compliance | Full control, evidence from your ISMS and security clearance rules | Processing agreement under GDPR, location Germany, IT-Grundschutz evidence | Processing agreement, standard contractual clauses, no classified data |
Collaboration
Project
Clearly scoped undertaking such as a PKI setup on HSMs or the rollout of VS-NfD encryption with a defined result, milestones and acceptance.
Team reinforcement
Cryptography specialists, platform engineers or developers work in your teams, tools and release processes, on request on site in your shielded environment.
Managed service
OTOKO® operates HSMs, PKI or platform with agreed service levels, reports, logged access and an exit concept that describes the return to your data center.
What each regulation in defense and security requires and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| VS-NfD and security clearance rules | Processing of classified information only in products and environments the BSI has approved for the level, with access control, encryption and documentation | Architecture with approved HSMs, LAN Crypt and DiskEncrypt, role concept, configuration evidence and documents for the industrial security audit |
| BSI IT-Grundschutz | Protection needs assessment, modeling with building blocks, implementation of the requirements and evidence in the security concept | Protection needs analysis, security concept with building blocks, hardened systems and operating procedures under IT-Grundschutz |
| BSI TR-02102 | Cryptographic algorithms, key lengths and protocols according to the BSI recommendations, including hybrid modes for the transition to PQC | Crypto concept with algorithms per protection need, HSM configuration, PKI profiles and post-quantum roadmap under the guideline |
| ISO 27001 | Information security management system with risk assessment, controls, internal audits and continual improvement | Operation under ISO 27001, risk register for platform and HSMs, evidence for your own certification |
| NIS2 | Risk management, reporting of significant incidents, supply chain security and accountability of management | Risk analysis, reporting process with SIEM connection, supply chain evidence with software bill of materials, documents for management |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers HSMs and PKI with BSI approval for classified information, sovereign hosting in German data centers, zero trust with domain separation and attack detection, file and disk encryption approved for VS-NfD, secure software supply chains and a post-quantum roadmap. Each field of action can be commissioned on its own or as a package, on request with operation by OTOKO®.
BSI approvals apply to products and to the operating environment, not to a service provider as such. We design architectures so that approved components are integrated correctly and the evidence for an evaluation is produced. Whether a program requires industrial security clearance or clearances for individual people is clarified with your security officer before the project starts.
With pure software encryption, keys sit in working memory where malware and memory dumps can extract them. An HSM keeps keys in a tamper-protected environment, performs operations inside it and logs every use. For classified information the BSI requires approved products depending on the level, and that approval presupposes certified hardware.
The exchange runs through gateways with content inspection and release rules that define which information may leave a domain. Every file carries a confidentiality label under STANAG 4774 that is bound to the content under STANAG 4778. Identities from the PKI prove who is sending and who is receiving, and the SIEM logs every transition.
Yes. HSMs, PKI, platform and encryption services run in your data center or in German data centers that are operated under ISO 27001. Hyperscalers are an option for unclassified data only, for example training or analytics. We work with operators of critical infrastructure and regulated industries. There a provable location is standard.
Now, with the inventory. Classified information has protection periods that exceed the expected arrival of capable quantum computers, and attackers already store encrypted data today for later decryption. The inventory shows which HSMs, certificates and gateways must migrate first, and the roadmap ties the migration to device refreshes and partner timelines.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: Target architecture, zero trust, domain concept. Cryptography specialist: HSMs, PKI, key ceremonies, post-quantum roadmap. Platform engineer: Sovereign platform, infrastructure as code, operations. Developer: Specialist applications, build pipeline, signing. Compliance consultant: IT-Grundschutz, BSI TR-02102, audit documents. Project lead: Milestones, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Classification, protection needs, systems and gaps in approval and operation Prioritized list of measures, crypto inventory, requirements for approval and operation
Project: Clearly scoped undertaking such as a PKI setup on HSMs or the rollout of VS-NfD encryption with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, platform engineers or developers work in your teams, tools and release processes, on request on site in your shielded environment. Managed service: OTOKO® operates HSMs, PKI or platform with agreed service levels, reports, logged access and an exit concept that describes the return to your data center.
Monitoring, key maintenance, audits, knowledge transfer Monitoring, key and certificate maintenance, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Defense
Let us discuss confidentially how cryptography and sovereign hosting protect your classified data.
Book a first consultation