MyID CMSEnterprise
The identity infrastructure platform trusted by large enterprises, financial institutions and government organisations worldwide. Credential lifecycle management - PKI and FIDO2 passkeys - issuance, renewal, revocation and recovery, at any scale, in any environment.
Complete credential lifecycle - PKI & passkeys - from issuance to revocation
MyID® CMS manages the full lifecycle of digital credentials across smart cards, USB security keys, mobile devices, Windows Hello for Business and virtual smart cards, and FIDO2 passkeys. A single solution issues, personalises, renews, suspends and revokes credentials across your PKI infrastructure, with no vendor lock-in
Self-Service Enrolment
Employees can request, collect and activate credentials without IT intervention, reducing helpdesk load and eliminating delays.
Automated Renewal
MyID automatically triggers renewal workflows for the credentials it manages as they approach expiry - no manual tracking needed.
Instant Revocation
Revoke any credential in seconds across all trust points. Critical for leavers, lost tokens and security incidents.
Multi-CA Support
Native connectors for Entrust, DigiCert, Microsoft ADCS, PrimeKey EJBCA and others. Works with your existing PKI infrastructure, no rip and replace.
100% Offline Operation
MyID CMS operates in fully air-gapped environments, essential for classified networks, defence and critical infrastructure.
Audit & Compliance
Complete audit trail for every credential event, with reporting via the Operator Client, Core API and MyID Report Designer to support your compliance programmes.
Deploy where your infrastructure demands
MyID CMS is proven in production across on-premise, cloud, hybrid and fully air-gapped environments.
On-Premise
Full control, zero cloud dependency. Ideal for classified networks, regulated sectors and organisations with strict data residency requirements.
- Windows Server 2022 / 2025
- SQL Server / Azure SQL / AWS RDS
- Active Directory integration
- HSM support (Thales, Entrust)
Cloud, hybrid or fully managed
Deploy MyID CMS on your own Microsoft Azure or AWS tenancy, or consume it as a managed service through an Intercede partner.
- Azure (VM with Azure SQL Database) and AWS (EC2 with Amazon RDS for SQL Server)
- You retain full control of data residency and key material
- Managed-service and hosted delivery available through Intercede’s certified partner network
- Microsoft Entra ID for directory, sign-in and passkey authentication
Air-Gapped / Classified
Proven in fully offline, air-gapped environments. No internet connectivity required at any point in the credential lifecycle.
- Fully on-premise, no cloud dependency
- Complete credential lifecycle managed on disconnected networks
- Works with your on-network certificate authority
- Proven in defence and classified environments
Built for the most regulated environments
MyID CMS is deployed in environments where compliance failure is not an option. From US Federal PIV to EU NIS2, the platform meets the standards that matter.
US Federal
Federal-ready PIV. The MyID CMS PIV edition personalises and manages PIV and PIV-I credentials in conformance with FIPS 201, issuing to NIST SP 800-73-4 and validated with the SP 800-85B conformance test tool.
- FIPS 201 conformant PIV / PIV-I issuance (PIV edition)
- Supports authentication assurance to NIST SP 800-63B (AAL2/AAL3)
- Supports derived PIV credentials to NIST SP 800-157
- Helps satisfy NIST SP 800-171 (CUI) and EO 14028 programme requirements
- CMMC Level 1
EU and UK
Built for regulated environments. MyID CMS gives you the phishing-resistant credentials and audit evidence that underpin your compliance programmes.
- Supports your NIS2 obligations with phishing-resistant PKI and FIDO2 credentials
- Supports DORA operational-resilience requirements for financial services
- Strong access control and a signed audit trail to support GDPR accountability
- Intercede is certified to ISO 27001, ISO 9001 and Cyber Essentials Plus
Defence and Classified
Proven in air-gapped, classified environments across allied defence programmes. Supports operation without internet connectivity, with documented offline configuration across the credential lifecycle.
- 100% offline / air-gap operation - full credential lifecycle with no external connectivity
- Supports CMMC programme requirements for defence suppliers
- Proven on SC/DV-cleared and allied coalition deployments
- Tamper-evident, signed audit trail supporting non-repudiation
Technical specifications
Supported CAs
- Microsoft Windows CA (AD CS)
- PrimeKey EJBCA (including post-quantum ML-DSA and ML-KEM issuance for software certificates)
- DigiCert ONE
- Entrust
- API for custom PKI integrations
- Additional CAs available on request
Device Support
- Smart cards (contact + contactless)
- USB security keys - FIDO2 + PKI lifecycle
- Virtual smart cards
- Mobile (iOS and Android)
- FIDO2 passkeys, including Entra ID passkey import
- Windows Hello for Business
HSM Support
- Entrust nShield (Connect / Solo)
- Thales Luna, including Luna Cloud HSM (DPoD)
- FIPS 140-2 Level 3 mode supported
Integrations
- Microsoft Entra ID (hybrid & cloud only deployments)
- Physical access control systems (PACS) via REST notifications
- Card printers: HID, Entrust, IDP, Matica
- SIEM collection via Windows event log and REST notifications
- Any LDAP directory
Enterprise scale, integration ready
MyID CMS is engineered for the largest, most complex identity estates, from millions of credentials in a single deployment to coalition programmes spanning multiple agencies and trust boundaries. Native integration with the certificate authorities, HSMs, directory services and identity platforms you already operate.
Millions of credentials
Proven in production from thousands to multiple millions of credentials. Three-tier architecture supports horizontal scale-out with load-balanced web and application tiers and database failover clustering.
Multi-region, multi-trust
Deploy across regions and trust boundaries. Air-gapped, classified, sovereign cloud and hybrid topologies all supported by the same platform.
REST API, anywhere
Full REST API coverage for people & credential lifecycle events, and audit data retrieval. Integrate directly with your existing identity provisioning, ITSM, and SIEM workflows, with little to no custom integration work required
CA, HSM, directory native
Native connectors for ADCS, Entrust, DigiCert, PrimeKey EJBCA. Validated against Thales Luna and Entrust nShield HSMs, including the Thales Data Protection on Demand (DPoD) cloud HSM service. Direct AD and Entra ID integration. No custom code.
Built for the most demanding environments
Issue, renew, replace and revoke credentials at scale, with role-based workflows and a full audit trail behind every event.
Automate certificate issuance, renewal, and revocation across every device type. Automated renewal and lifecycle workflows, with self-service collection and silent client deployment for large estates.
Trusted by federal agencies and allied governments across 20+ countries. For FIPS 201 PIV and PIV-I issuance, see MyID CMS PIV.
Let users manage their own credentials. PIN reset, certificate renewal, and device recovery without helpdesk calls.
Issue certificates with NIST-standardised ML-DSA and ML-KEM algorithms today, via EJBCA, with more PQC integrations to follow. Start your migration before the deadlines arrive.
Runs in disconnected environments with no cloud dependency. Deployed in classified networks worldwide.
Real-time visibility into credential status, expiry, and policy compliance, with full audit data available for reporting.
Issue and lifecycle-manage FIDO2 passkeys at enterprise scale - standalone or alongside PKI credentials - with optional enterprise attestation to prove a passkey lives on an approved, enterprise-issued authenticator.
Keep Microsoft Entra ID as your Passkey identity provider while MyID CMS issues and manages the credential. Synchronise Entra-issued passkeys into MyID for lifecycle control, and issue PKI and Passkeys to the same device.
Archive encryption keys on your CA or in MyID SecureVault and automatically recover them to a new device when a token is lost or replaced, with third-party key-recovery workflows and separation of duties.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
A Credential Management System automates the full lifecycle of digital credentials - issuance, renewal, suspension, revocation and recovery - whether the credential is a PKI certificate, a FIDO2 passkey, Windows Hello for Business, or a certificate on a smart card, USB security key or mobile device. MyID CMS manages every credential type in a single solution, eliminating the manual processes that cause credential expiry outages and helpdesk overhead.
A CA issues certificates; a CMS manages what happens to them. MyID CMS sits above your CA, whether that's Microsoft ADCS, Entrust, DigiCert or EJBCA, and handles enrolment, personalisation, lifecycle workflows, self-service and revocation at scale. You can connect multiple CAs to a single MyID instance.
MyID CMS supports credential hardware across the estate. For end users: smart cards from IDEMIA, Thales, Giesecke & Devrient, Swissbit and others; USB security keys and tokens including Yubico YubiKeys and Thales SafeNet eTokens; Windows computers, via Windows Hello for Business and TPM virtual smart cards; and mobile devices on iOS and Android. Server-side, MyID integrates with Entrust nShield and Thales Luna HSMs, and supports card printers from HID, Entrust, IDP and Matica for physical badge issuance.
Yes. MyID CMS runs fully on-premise with no cloud dependency, and the complete credential lifecycle, enrolment, issuance, renewal and revocation, can be operated within a disconnected network. Certificate services are provided by your on-network certificate authority, which MyID CMS manages through its native CA connectors.
FIPS 201 is the US federal standard for Personal Identity Verification (PIV) credentials. The MyID CMS PIV edition issues, manages and revokes PIV and PIV-I credentials in conformance with FIPS 201 - personalising to NIST SP 800-73-3 and validated with the SP 800-85B conformance test tool. It covers the full PIV data model, biometric enrolment and derived credentials (NIST SP 800-157).
Deployment timescales depend on your infrastructure and accreditation requirements. Our professional services team will map the deployment plan with you during the demo.
MyID CMS licensing scales from small deployments through to enterprise estates managing millions of credentials. Contact our sales team for a tailored quote.
Yes. Roles, groups and scope ensure no single operator both enrols a user and issues their credential. Every credential event is written to a full audit trail - supporting the segregation-of-duties controls that regulators and auditors expect.
Trusted at every scale, in every environment
Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2, smart card systems, and credential lifecycle management across government, defence, and enterprise environments.
MyID is deployed in environments requiring FIPS 201, NIS2, NIST SP 800-63B and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.
From financial institutions and healthcare providers to national identity programmes serving millions of citizens, MyID is proven at every scale and in every sector. A leading European bank manages PKI credentials for more than 12,000 employees with MyID CMS, and a leading US health-services provider secures strong authentication for 160,000 employees across all 50 states.