x509.systems

SSmallstep

Private PKI for engineers — step-ca gives you an internal ACME CA in an afternoon.

Private CA (ACME)Self-hosted + SaaSBy SmallstepSince 2017Open source: step-ca (Apache-2.0)
Type
Private CA (ACME)
How it works
step-ca is an open-source private certificate authority that speaks ACME, so internal services renew exactly the way public ones do. The hosted product adds device identity, SSH certificates and single sign-on integration.
Deployment
Self-hosted + SaaS
Pricing*
Free (OSS); hosted by quote
Free tier
Yes
Open source
step-ca (Apache-2.0)
Compliance
SOC 2 (hosted)
Best for
Internal mTLS and short-lived certificates
Notable
ACME for internal services

* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.

Strengths

  • Genuinely quick to stand up
  • ACME internally — same tooling as public TLS
  • Excellent short-lived certificate and SSH support
  • Permissive licence, no gated core

Trade-offs

  • Not a public CA — internal trust only
  • Smaller company than the incumbents
  • Governance features thinner than Venafi or Keyfactor

Visit Smallstep → Documentation

Listed for comparison as of August 2026 — not an endorsement, and Smallstep did not pay for placement. See disclosure.

Compare Smallstep with…

Smallstep vs DigiCertSmallstep vs SectigoSmallstep vs Let's Encrypt