x509.systems

KKeyfactor

The open-core challenger — commercial CLM on top of EJBCA, the most deployed open-source CA.

CLM + private CASaaS + self-hostedBy KeyfactorSince 2001Open source: EJBCA Community (LGPL)
Type
CLM + private CA
How it works
Keyfactor Command handles discovery, automation and policy; EJBCA provides the CA itself; SignServer covers code and document signing. The open-source community editions let you evaluate the engine before buying the management layer.
Deployment
SaaS + self-hosted
Pricing*
Enterprise quote
Free tier
Yes
Open source
EJBCA Community (LGPL)
Compliance
FIPS 140-2, Common Criteria (EJBCA)
Best for
Teams wanting private PKI they can self-host
Notable
EJBCA is Common Criteria certified

* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.

Strengths

  • Real open-source core you can run and audit
  • Private CA and CLM from one vendor
  • Strong IoT and device-identity story
  • Free community editions for evaluation

Trade-offs

  • EJBCA has a steep operational learning curve
  • Commercial pricing is still enterprise-tier
  • Smaller partner ecosystem than Venafi

Visit Keyfactor → Documentation

Listed for comparison as of August 2026 — not an endorsement, and Keyfactor did not pay for placement. See disclosure.

Compare Keyfactor with…

Keyfactor vs DigiCertKeyfactor vs SectigoKeyfactor vs Let's Encrypt