Pricing
Three flat plans. No per-certificate, no per-user fees.
Pick the number of certificate authorities you need; issue as many certificates as the plan's hourly limit allows. Billed through the Microsoft commercial marketplace on your Azure invoice.
01 / PLANS
Basic
€199per month
1 certificate authority
3,000 certificates / hour per CA
- Portal, REST API and help center
- Intune SCEP and static-challenge SCEP for other MDMs
- ACME (certbot, win-acme, cert-manager) with External Account Binding
- CRL & OCSP publishing, domain ownership & approval
- Lifecycle e-mail notifications, append-only audit log
7-day free trial
- Most popular
Premium
€399per month
Up to 3 certificate authorities
10,000 certificates / hour per CA
- Everything in Basic
- Full Root + Subordinate hierarchies, chaining under your ADCS root
- Azure Key Vault issuance with automatic rotation
- Entra app credential rotation
- SSH certificates (OpenSSH CA) — included, no per-user fee
- SIEM export: Log Analytics / Sentinel, Splunk, webhook
Enterprise
€799per month
Up to 10 certificate authorities
25,000 certificates / hour per CA
- Everything in Premium
- Priority support
- For PKI at organisation scale — several hierarchies, many teams
- Prices are per month and exclude VAT. Yearly billing is available at ten times the monthly price — two months free.
- Billing happens through the Microsoft commercial marketplace on your existing Azure invoice; there is no separate contract or invoice from us.
- Prices are set in EUR for euro markets; Microsoft converts them for other currencies at purchase.
- A subscription is created only by activating a plan purchased on Azure Marketplace. There is no other way to create one — and no hidden tier.
02 / COMPARE
Compare plans
Every plan is the full product for its number of certificate authorities. The rows below are the only differences.
| Feature | Basic€199 per month | Premium€399 per month | Enterprise€799 per month |
|---|---|---|---|
| Certificate authorities | 1 | Up to 3 | Up to 10 |
| Issuance limit (per CA) | 3,000 / hour | 10,000 / hour | 25,000 / hour |
| Portal, REST API, Swagger | |||
| Intune SCEP & static-challenge SCEP | |||
| ACME (http-01 / dns-01, EAB) | |||
| CRL & OCSP publishing | |||
| Domain ownership & approval | |||
| Lifecycle e-mail notifications | |||
| Append-only audit log | |||
| Root + Subordinate hierarchies | — | ||
| Azure Key Vault issuance & auto-rotation | — | ||
| Entra app credential rotation | — | ||
| SSH certificates (OpenSSH CA) | — | ||
| SIEM export (Log Analytics, Splunk, webhook) | — | ||
| Priority support | — | — | |
| Free trial | 7 days | — | — |
03 / QUESTIONS
Billing questions
01How does billing work?
You subscribe on Azure Marketplace with your Azure account; the plan appears on your Azure invoice like any other Azure service. After the purchase, Azure sends you to the activation page of the portal, where the subscription is created and you become its first PKI administrator.
02Is there a free trial?
Yes — a 7-day free trial on the Basic plan, started from Azure Marketplace. The trial is the full Basic plan (1 CA, all protocols). Premium and Enterprise have no trial; if you need to evaluate them, talk to us.
03How do I upgrade or downgrade?
In the Azure portal, open the SaaS resource you purchased and click Change plan. The change is applied in place — same subscription, no reinstall, nothing to re-activate; the new CA limit and issuance rate are active within minutes. Microsoft prorates the invoice. Please don't cancel and repurchase to change plans.
04What happens to my CAs if I downgrade?
Existing CAs are never deleted. If you hold more CAs than the smaller plan allows, they keep operating, but new CAs cannot be created until the count fits the plan.
05What happens if I cancel?
Your CAs, certificates and audit history are kept, and revocation information stays published; issuance is capped at trial limits until you subscribe again.
06What counts as a certificate authority?
Every Root, Subordinate or SSH CA you create counts as one. A typical Premium layout is one Root plus one or two issuing CAs — for example an Intune SCEP CA and an ACME CA — or a Root, an issuing CA and an SSH CA.
07What happens above the issuance limit?
The API answers HTTP 429 with a Retry-After header; Intune, ACME clients and the portal retry automatically and nothing fails. Limits are set well below the measured capacity of the platform and are published in the documentation.
08Do you offer custom terms or private offers?
Yes. Private offers on Azure Marketplace let us agree custom pricing, terms or a longer trial for larger deployments and partners — get in touch.
04 / NEXT STEP
Not sure which plan fits?
Tell us how many devices, servers and apps you need to cover and we'll recommend a layout — or walk you through the product in a demo.