up:: The Mandates MOC
PKI Consortium
The PKI Consortium is a nonprofit industry association of several hundred organizations spanning certificate authorities, software and hardware vendors, enterprises, financial institutions, and regulators, organized around improving policies, best practices, and tooling for public key infrastructure. For the quantum transition it matters through two artifacts: its Post-Quantum Cryptography Conference series, which has become one of the main practitioner venues where the PKI industry works through the migration in public, and its PQC Capabilities Matrix, a community-maintained inventory of which products and libraries claim post-quantum support.
The short version:
- The consortium is a 501(c)(6) nonprofit established in 2013 as the Certificate Authority Security Council and restructured under its current name in 2021, with free membership spanning CAs, vendors, enterprises, and regulators rather than CAs alone.
- Its Post-Quantum Cryptography Conference has run since 2023 (Ottawa, Amsterdam, Austin, Kuala Lumpur, with Amsterdam next in December 2026), and the sessions are a running record of how the web PKI and enterprise PKI communities are actually approaching migration.
- The PQC Capabilities Matrix (PQCCM) tracks post-quantum support across software, libraries, and hardware for the standardized algorithms, with per-entry status and update dates.
- The matrix is self-reported by vendors and carries the consortium’s own disclaimer that it lists capabilities “without endorsing their implementation or quality,” so it’s a discovery tool for your vendor conversations rather than evidence a product works.
Think of the consortium as the trade association for the internet’s locksmiths. The standards define the new locks, and this is the room where the people who install and operate locks for a living compare notes on retooling, plus the bulletin board where toolmakers post which of their products claim to fit the new hardware.
What is the PKI Consortium?
The PKI Consortium is a 501(c)(6) nonprofit business league registered in Utah, whose stated mission is to advance trust in assets and communication using public key infrastructure. It began in 2013 as the Certificate Authority Security Council, a CA-industry group, and rebranded to the PKI Consortium in 2021 as membership widened. Its members today span certificate authorities, regulators, supervisory bodies, industry experts, and enterprise stakeholders, with names like DigiCert, Sectigo, Entrust, Keyfactor, Thales, Microsoft, IBM, and Citi on the roster, and membership is free.
The consortium collaborates on policies, procedures, best practices, standards and tools, and its decisions are taken by substantial consensus of the members rather than carrying regulatory force. In the PKI ecosystem it sits beside the CA/Browser Forum, which publishes the Baseline Requirements for TLS server certificates that the root programs enforce across the web PKI, as a broader and less formal collaboration surface.
Sources: PKI Consortium, “About us,” which describes the consortium as collaborating on “generic, industry or use-case specific policies, procedures, best practices, standards and tools” and states that “decisions within the PKI Consortium are taken by substantial consensus of the members,” pkic.org/about; CA/Browser Forum, “Baseline Requirements,” for the Baseline Requirements for TLS Server Certificates and the Forum’s self-description as “a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates,” cabforum.org. The About page does not mention the CA/Browser Forum.
Why does the PQC Conference series matter?
The conference series matters because it’s where the PKI-operating industry works through the migration’s practical problems in public, and the talks are freely available. A CA moving its roots and issuance to ML-DSA, an HSM vendor sequencing firmware support, and an enterprise wrestling with certificate lifecycle at PQC sizes all present in the same room, which makes the archive a running primary record of where real deployments actually stand.
| # | Dates | Location |
|---|---|---|
| 1 | March 3, 2023 | Ottawa, Canada |
| 2 | November 7–8, 2023 | Amsterdam, Netherlands |
| 3 | January 15–16, 2025 | Austin, Texas |
| 4 | October 28–30, 2025 | Kuala Lumpur, Malaysia |
| 5 | December 1–3, 2026 | Amsterdam, Netherlands |
Source: PKI Consortium, events index, pkic.org/events.
What is the PQC Capabilities Matrix, and how much should you trust it?
The PQC Capabilities Matrix (PQCCM) is a community-maintained inventory of software applications, libraries, and hardware that claim post-quantum support, tracking which standardized algorithms (FIPS, IETF, ITU-T) each product supports and at what status (available, planned, or out of scope). It’s maintained by the consortium’s PQC working group as a living, GitHub-contributed document, with per-entry last-updated dates, and entries for draft-era algorithms have been archived so it now covers the standardized set.
The trust question has a precise answer, because the consortium states it itself: the matrix lists products “without endorsing their implementation or quality.” Entries are self-reported by vendors. That makes the matrix genuinely useful for one job and unsuited to another:
- Use it for discovery. When you need to know whether a vendor has even claimed ML-KEM support, the matrix is a fast, maintained starting point, and a vendor’s absence from it is a good prompt for a roadmap question.
- Verify before you rely. A matrix row is a claim rather than a test result. Whether an implementation is validated (see ACVP and PQC Validation), performant, and correctly integrated in your configuration only your own evaluation establishes, which is the same evidence bar this guide applies to every vendor claim.
Source: PKI Consortium, “PQC Capabilities Matrix,” pkic.org/wg/pqc/pqccm.
Common misconceptions
- “The PKI Consortium sets the rules for certificates.” The binding baseline requirements for publicly-trusted certificates come from the CA/Browser Forum and the root programs. The consortium is a collaboration and best-practices body.
- “It’s just a CA club.” That was closer to true of its 2013 predecessor. Today’s membership spans vendors, enterprises, financial institutions, and regulators, which is what makes its PQC work a cross-industry read rather than a CA-only one.
- “A product listed in the PQC Capabilities Matrix is quantum-safe.” The matrix records a self-reported capability claim, with an explicit no-endorsement disclaimer. Validation and fitness for your deployment remain your evaluation to run.
Questions people ask
Is PKI Consortium membership paid? Membership is free, and the consortium describes its members as CAs, regulators, supervisory bodies, industry experts, and other stakeholders.
Where can I watch the PQC Conference talks? The consortium publishes conference recordings and agendas on pkic.org, which makes the archive a free primary source on deployment practice.
How does this differ from the PQC Coalition? The PQC Coalition is a MITRE-convened group focused on migration guidance for the NIST standards; the PKI Consortium is a broader PKI industry association whose post-quantum contribution runs through its conference series and capabilities matrix. A migration team ends up using material from both.
Everything here is the map, given freely. When your team needs vendor claims like a matrix row turned into verified answers about your own certificate estate, that’s the work I do.
Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.