← All vendors
SSmallstep
Private PKI for engineers — step-ca gives you an internal ACME CA in an afternoon.
Private CA (ACME)Self-hosted + SaaSBy SmallstepSince 2017Open source: step-ca (Apache-2.0)
- Type
- Private CA (ACME)
- How it works
- step-ca is an open-source private certificate authority that speaks ACME, so internal services renew exactly the way public ones do. The hosted product adds device identity, SSH certificates and single sign-on integration.
- Deployment
- Self-hosted + SaaS
- Pricing*
- Free (OSS); hosted by quote
- Free tier
- Yes
- Open source
- step-ca (Apache-2.0)
- Compliance
- SOC 2 (hosted)
- Best for
- Internal mTLS and short-lived certificates
- Notable
- ACME for internal services
* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.
Strengths
- Genuinely quick to stand up
- ACME internally — same tooling as public TLS
- Excellent short-lived certificate and SSH support
- Permissive licence, no gated core
Trade-offs
- Not a public CA — internal trust only
- Smaller company than the incumbents
- Governance features thinner than Venafi or Keyfactor
Visit Smallstep → Documentation
Listed for comparison as of August 2026 — not an endorsement, and Smallstep did not pay for placement. See disclosure.
Compare Smallstep with…