NIAP-Listed Certificate Authority for High-Assurance Enterprise PKI

common criteria banner

Enterprise trust and zero trust architectures depend on digital certificates. 

They secure users, devices, applications, cloud workloads, APIs, services and machine identities. When certificates fail, expire, are misconfigured or are issued without sufficient control, the impact can be immediate: outages, failed authentication, compliance gaps, weakened encryption and loss of confidence in digital services. 

Cogito Jellyfish Certificate Authority helps organisations strengthen the Certificate Authority layer at the centre of enterprise PKI. 

In addition to our existing Common Criteria certification, Jellyfish is now a NIAP certified and Compliant Product. Jellyfish CA was evaluated against the Protection Profile for Certification Authorities Version 2.1. Jellyfish provides independently tested CA capability for environments where trust, governance and assurance matter. 

Why enterprise PKI risk is increasing

Enterprise PKI environments are becoming harder to govern.

Certificates are now used across cloud platforms, DevOps pipelines, remote access systems, APIs, infrastructure, enterprise applications, mobile devices, workloads and machine-to-machine communications.

This creates recurring challenges:

  • Limited visibility of issued certificates
  • Certificate expiry causing service outages
  • Fragmented CA operations across teams and environments
  • Inconsistent issuance, renewal and revocation processes
  • Weak governance over machine identities
  • Difficulty proving assurance to risk, security and compliance stakeholders
  • Legacy PKI platforms that are hard to operate, audit or scale
  • Certificate-based trust models that are not aligned to Zero Trust architecture

As the certificate estate grows and trust is required inside a network, not just outside of it, the Certificate Authority becomes more than a technical component. It becomes critical trust infrastructure. 

More than certificate management

Certificate lifecycle management helps organisations improve visibility, automation and operational control. 

But certificate management alone does not answer every assurance question. High-assurance PKI also requires confidence in the Certificate Authority capability behind certificate issuance, validation, cryptographic operations and secure communications. 

Cogito Jellyfish Certificate Authority helps address this by providing Common Criteria and NIAP-listed CA capability evaluated against a recognised Certificate Authority Protection Profile. 

Certificate Lifecycle Management

Why evaluated CA assurance matters

Enterprise PKI supports authentication, secure communications, certificate-based access, machine-to-machine trust, encryption, signing and digital identity assurance. 

As certificate estates expand across cloud platforms, DevOps pipelines, remote access, APIs, connected systems and machine identities, organisations need stronger control over the Certificate Authority and certificate lifecycle processes at the centre of the trust environment. 

A NIAP-listed Certificate Authority helps security, risk, compliance and architecture teams assess CA capability against a recognised Protection Profile, supporting more defensible trust decisions in high-assurance environments. 

Official NIAP certification summary

  • Compliant Product: Cogito Jellyfish Certificate Authority Version 7.0
  • Certification Date: 29 April 2026
  • Assurance Maintenance Date: 29 April 2028
  • Conformance Claim: Protection Profile Compliant
  • PP Identifier: Protection Profile for Certification Authorities Version 2.1
  • Common Criteria Testing Lab: Viden Labs

Evaluated Certificate Authority capability areas

The NIAP evaluation identifies tested capabilities across Certificate Authority functions, cryptographic functions and secure communications.

Certificate Authority capabilities

Certificate Authority capabilities

  • Certificate Generation
  • Certificate Validation
  • Certification Authority
Cryptographic capabilities

Cryptographic capabilities

  • Asymmetric Key Generation
  • Symmetric Key Generation
  • Cryptographic Hashing
  • Cryptographic Key Establishment
  • Cryptographic Signature Generation
  • Keyed-hash Message Authentication
Secure communications capabilities

Secure communications capabilities

  • HTTPS Server
  • IPsec
  • TLS Server with Mutual Authentication

Enterprise use cases

Built for high-assurance PKI use cases

Built for High-Assurance Environments

Jellyfish is designed for organisations that need confidence in how digital identity and trust services are delivered, operated and governed.

This includes:

  • government agencies
  • Defence and national security environments
  • critical infrastructure operators
  • financial services organisations
  • healthcare and education providers
  • telecommunications providers
  • regulated enterprises
  • managed service providers delivering secure identity and PKI services

For these organisations, independent assurance is more than a compliance milestone. It supports procurement confidence, security governance, risk reduction and long-term operational trust.

Sovereign Capability for Trusted Digital Infrastructure

Cogito Group designs and delivers cyber security, PKI and digital identity capabilities for organisations that require strong assurance and control.

Jellyfish supports sovereign digital trust outcomes by helping customers manage critical PKI, certificates and credentials with security, resilience and governance at the centre of the platform.

For Australian and New Zealand customers, this is particularly important where data sovereignty, security-cleared operations, government assurance and local expertise are key requirements.

Content Image

FAQs

Background
Cogito Logo

Ready to strengthen your enterprise PKI trust layer?

Talk to Cogito about NIAP-listed Certificate Authority capability, certificate lifecycle control and high-assurance PKI requirements for your organisation.