Security & Compliance / PKI Consultant UK

PKI & Certificate Services — Windows ADCS Design, Migration & Remediation

PKI is high-risk, low-visibility infrastructure. Root CA expiry, undocumented certificate templates, ADCS installed in the wrong place, and fragile renewal processes can sit quietly for years before they become an outage, a failed assurance review, or a security incident.

Certificate authorities need calm engineering, not guesswork.

We assess, design, recover, migrate, and document Microsoft ADCS environments for public-sector, healthcare, regulated enterprise, and MSP teams that have inherited certificate services they cannot confidently explain. The work covers two-tier CA design, root and issuing CA build, template review, auto-enrolment, renewal planning, certificate lifecycle documentation, safe decommissioning, and BAU handover.

Assessment and remediation

Review ADCS placement, templates, policy modules, publication points, expiry risk, CRL/AIA paths, and dependent systems before changing anything.

  • ADCS assessment
  • PKIview
  • Certutil evidence
  • Risk register

Two-tier CA design

Design and build an offline root and issuing CA pattern that fits the organisation, with secure administration, renewal runbooks, and support documentation.

  • Windows Server 2022
  • Root CA renewal
  • Issuing CA build
  • BAU handover

Safe decommissioning

Where certificate services are unused or incorrectly deployed, we prove dependency status, document the evidence, and plan removal with no avoidable network impact.

  • Dependency checks
  • Decommission plan
  • Change evidence
  • Support transfer

Anonymised delivery evidence.

  • For a regulated water-sector organisation, assessed and safely decommissioned an ADCS implementation incorrectly deployed on a domain controller; Certutil and PKIview confirmed it was unconfigured and unused, with zero impact on the wider network.
  • For an NHS body, expedited the build of a Windows Server 2022 two-node certificate authority ahead of imminent root authority expiry, migrating end-user compute and network infrastructure within a compressed timeline.
  • Within a NATO-classified environment, resolved blocking ADCS and certificate-services issues that were preventing completion of a major messaging platform upgrade, then documented the implementation and trained internal support teams.

Best fit.

This service is for NHS trusts, local authorities, regulated enterprises, and MSPs that have inherited an undocumented or at-risk certificate authority. It connects naturally with security and compliance architecture and cloud and infrastructure architecture where certificate services underpin identity, remote access, device trust, or secure service publishing.