Skip to main content
Home > MyID Product Family > MyID CMS Enterprise

MyID CMSEnterprise

The identity infrastructure platform trusted by large enterprises, financial institutions and government organisations worldwide. Credential lifecycle management - PKI and FIDO2 passkeys - issuance, renewal, revocation and recovery, at any scale, in any environment.

What MyID CMS does

Complete credential lifecycle - PKI & passkeys - from issuance to revocation

MyID® CMS manages the full lifecycle of digital credentials across smart cards, USB security keys, mobile devices, Windows Hello for Business and virtual smart cards, and FIDO2 passkeys. A single solution issues, personalises, renews, suspends and revokes credentials across your PKI infrastructure, with no vendor lock-in

Why teams choose MyID CMS
Technology-independent platform
Native connectors for Microsoft, Entrust, DigiCert and EJBCA - deploy without rip-and-replace of your existing PKI, HSM, directory or identity management system, including deep Microsoft Entra ID integration.
Every credential form factor
Smart cards, USB security keys, mobile, Windows Hello for Business, FIDO2 passkeys - one platform issues to all of them.
Air-gap and classified ready
Deploy anywhere: private cloud, on-premise, or 100% offline air-gapped networks
Credential Management
MyID CMS
100%
offline capable
Deploy anywhere - Private cloud · on-premise · 100% offline air-gap
Credential types
All form factors
Smart cards · USB security keys · mobile · Windows Hello for Business · Passkeys
Proven scale
Thousands to millions
Single deployment, horizontal scale-out
CA connectors
Native multi-CA
Entrust, DigiCert, ADCS , EJBCA

Self-Service Enrolment

Employees can request, collect and activate credentials without IT intervention, reducing helpdesk load and eliminating delays.

Automated Renewal

MyID automatically triggers renewal workflows for the credentials it manages as they approach expiry - no manual tracking needed.

Instant Revocation

Revoke any credential in seconds across all trust points. Critical for leavers, lost tokens and security incidents.

Multi-CA Support

Native connectors for Entrust, DigiCert, Microsoft ADCS, PrimeKey EJBCA and others. Works with your existing PKI infrastructure, no rip and replace.

100% Offline Operation

MyID CMS operates in fully air-gapped environments, essential for classified networks, defence and critical infrastructure.

Audit & Compliance

Complete audit trail for every credential event, with reporting via the Operator Client, Core API and MyID Report Designer to support your compliance programmes.

Flexible Deployment

Deploy where your infrastructure demands

MyID CMS is proven in production across on-premise, cloud, hybrid and fully air-gapped environments.

On-Premise

Full control, zero cloud dependency. Ideal for classified networks, regulated sectors and organisations with strict data residency requirements.

  • Windows Server 2022 / 2025
  • SQL Server / Azure SQL / AWS RDS
  • Active Directory integration
  • HSM support (Thales, Entrust)

Cloud, hybrid or fully managed

Deploy MyID CMS on your own Microsoft Azure or AWS tenancy, or consume it as a managed service through an Intercede partner.

  • Azure (VM with Azure SQL Database) and AWS (EC2 with Amazon RDS for SQL Server)
  • You retain full control of data residency and key material
  • Managed-service and hosted delivery available through Intercede’s certified partner network
  • Microsoft Entra ID for directory, sign-in and passkey authentication

Air-Gapped / Classified

Proven in fully offline, air-gapped environments. No internet connectivity required at any point in the credential lifecycle.

  • Fully on-premise, no cloud dependency
  • Complete credential lifecycle managed on disconnected networks
  • Works with your on-network certificate authority
  • Proven in defence and classified environments
Compliance

Built for the most regulated environments

MyID CMS is deployed in environments where compliance failure is not an option. From US Federal PIV to EU NIS2, the platform meets the standards that matter.

US Federal

Federal-ready PIV. The MyID CMS PIV edition personalises and manages PIV and PIV-I credentials in conformance with FIPS 201, issuing to NIST SP 800-73-4 and validated with the SP 800-85B conformance test tool.

  • FIPS 201 conformant PIV / PIV-I issuance (PIV edition)
  • Supports authentication assurance to NIST SP 800-63B (AAL2/AAL3)
  • Supports derived PIV credentials to NIST SP 800-157
  • Helps satisfy NIST SP 800-171 (CUI) and EO 14028 programme requirements
  • CMMC Level 1

EU and UK

Built for regulated environments. MyID CMS gives you the phishing-resistant credentials and audit evidence that underpin your compliance programmes.

  • Supports your NIS2 obligations with phishing-resistant PKI and FIDO2 credentials
  • Supports DORA operational-resilience requirements for financial services
  • Strong access control and a signed audit trail to support GDPR accountability
  • Intercede is certified to ISO 27001, ISO 9001 and Cyber Essentials Plus

Defence and Classified

Proven in air-gapped, classified environments across allied defence programmes. Supports operation without internet connectivity, with documented offline configuration across the credential lifecycle.

  • 100% offline / air-gap operation - full credential lifecycle with no external connectivity
  • Supports CMMC programme requirements for defence suppliers
  • Proven on SC/DV-cleared and allied coalition deployments
  • Tamper-evident, signed audit trail supporting non-repudiation
Specifications

Technical specifications

Supported CAs

  • Microsoft Windows CA (AD CS)
  • PrimeKey EJBCA (including post-quantum ML-DSA and ML-KEM issuance for software certificates)
  • DigiCert ONE
  • Entrust
  • API for custom PKI integrations
  • Additional CAs available on request

Device Support

  • Smart cards (contact + contactless)
  • USB security keys - FIDO2 + PKI lifecycle
  • Virtual smart cards
  • Mobile (iOS and Android)
  • FIDO2 passkeys, including Entra ID passkey import
  • Windows Hello for Business

HSM Support

  • Entrust nShield (Connect / Solo)
  • Thales Luna, including Luna Cloud HSM (DPoD)
  • FIPS 140-2 Level 3 mode supported

Integrations

  • Microsoft Entra ID (hybrid & cloud only deployments)
  • Physical access control systems (PACS) via REST notifications
  • Card printers: HID, Entrust, IDP, Matica
  • SIEM collection via Windows event log and REST notifications
  • Any LDAP directory
Scale & Integration

Enterprise scale, integration ready

MyID CMS is engineered for the largest, most complex identity estates, from millions of credentials in a single deployment to coalition programmes spanning multiple agencies and trust boundaries. Native integration with the certificate authorities, HSMs, directory services and identity platforms you already operate.

Millions of credentials

Proven in production from thousands to multiple millions of credentials. Three-tier architecture supports horizontal scale-out with load-balanced web and application tiers and database failover clustering.

Multi-region, multi-trust

Deploy across regions and trust boundaries. Air-gapped, classified, sovereign cloud and hybrid topologies all supported by the same platform.

REST API, anywhere

Full REST API coverage for people & credential lifecycle events, and audit data retrieval. Integrate directly with your existing identity provisioning, ITSM, and SIEM workflows, with little to no custom integration work required

CA, HSM, directory native

Native connectors for ADCS, Entrust, DigiCert, PrimeKey EJBCA. Validated against Thales Luna and Entrust nShield HSMs, including the Thales Data Protection on Demand (DPoD) cloud HSM service. Direct AD and Entra ID integration. No custom code.

Key Capabilities

Built for the most demanding environments

Issue, renew, replace and revoke credentials at scale, with role-based workflows and a full audit trail behind every event.

PKI Lifecycle

Automate certificate issuance, renewal, and revocation across every device type. Automated renewal and lifecycle workflows, with self-service collection and silent client deployment for large estates.

Government Grade

Trusted by federal agencies and allied governments across 20+ countries. For FIPS 201 PIV and PIV-I issuance, see MyID CMS PIV.

Self-Service Portal

Let users manage their own credentials. PIN reset, certificate renewal, and device recovery without helpdesk calls.

Post-Quantum ready

Issue certificates with NIST-standardised ML-DSA and ML-KEM algorithms today, via EJBCA, with more PQC integrations to follow. Start your migration before the deadlines arrive.

Air-Gap Ready

Runs in disconnected environments with no cloud dependency. Deployed in classified networks worldwide.

Compliance Reporting

Real-time visibility into credential status, expiry, and policy compliance, with full audit data available for reporting.

Enterprise Passkey Management

Issue and lifecycle-manage FIDO2 passkeys at enterprise scale - standalone or alongside PKI credentials - with optional enterprise attestation to prove a passkey lives on an approved, enterprise-issued authenticator.

Works with Entra ID

Keep Microsoft Entra ID as your Passkey identity provider while MyID CMS issues and manages the credential. Synchronise Entra-issued passkeys into MyID for lifecycle control, and issue PKI and Passkeys to the same device.

Secure Key Archival and Recovery

Archive encryption keys on your CA or in MyID SecureVault and automatically recover them to a new device when a token is lost or replaced, with third-party key-recovery workflows and separation of duties.

Frequently Asked Questions

Common questions

Everything you need to know. Can't find the answer? Contact our team →

A Credential Management System automates the full lifecycle of digital credentials - issuance, renewal, suspension, revocation and recovery - whether the credential is a PKI certificate, a FIDO2 passkey, Windows Hello for Business, or a certificate on a smart card, USB security key or mobile device. MyID CMS manages every credential type in a single solution, eliminating the manual processes that cause credential expiry outages and helpdesk overhead.

A CA issues certificates; a CMS manages what happens to them. MyID CMS sits above your CA, whether that's Microsoft ADCS, Entrust, DigiCert or EJBCA, and handles enrolment, personalisation, lifecycle workflows, self-service and revocation at scale. You can connect multiple CAs to a single MyID instance.

MyID CMS supports credential hardware across the estate. For end users: smart cards from IDEMIA, Thales, Giesecke & Devrient, Swissbit and others; USB security keys and tokens including Yubico YubiKeys and Thales SafeNet eTokens; Windows computers, via Windows Hello for Business and TPM virtual smart cards; and mobile devices on iOS and Android. Server-side, MyID integrates with Entrust nShield and Thales Luna HSMs, and supports card printers from HID, Entrust, IDP and Matica for physical badge issuance.

Yes. MyID CMS runs fully on-premise with no cloud dependency, and the complete credential lifecycle, enrolment, issuance, renewal and revocation, can be operated within a disconnected network. Certificate services are provided by your on-network certificate authority, which MyID CMS manages through its native CA connectors.

FIPS 201 is the US federal standard for Personal Identity Verification (PIV) credentials. The MyID CMS PIV edition issues, manages and revokes PIV and PIV-I credentials in conformance with FIPS 201 - personalising to NIST SP 800-73-3 and validated with the SP 800-85B conformance test tool. It covers the full PIV data model, biometric enrolment and derived credentials (NIST SP 800-157).

Deployment timescales depend on your infrastructure and accreditation requirements. Our professional services team will map the deployment plan with you during the demo.

MyID CMS licensing scales from small deployments through to enterprise estates managing millions of credentials. Contact our sales team for a tailored quote.

Yes. Roles, groups and scope ensure no single operator both enrols a user and issues their credential. Every credential event is written to a full audit trail - supporting the segregation-of-duties controls that regulators and auditors expect.

Why Intercede

Trusted at every scale, in every environment

Our Expertise
25+ Years in Identity Security

Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2, smart card systems, and credential lifecycle management across government, defence, and enterprise environments.

Standards & Compliance
Built for Regulated Environments

MyID is deployed in environments requiring FIPS 201, NIS2, NIST SP 800-63B and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.

Proven Scale
Millions of Credentials Managed

From financial institutions and healthcare providers to national identity programmes serving millions of citizens, MyID is proven at every scale and in every sector. A leading European bank manages PKI credentials for more than 12,000 employees with MyID CMS, and a leading US health-services provider secures strong authentication for 160,000 employees across all 50 states.

MyID CMS

See MyID CMS in action

Book a 45-minute technical walkthrough with one of our identity architects. We'll map the right deployment for your infrastructure.