TeskaLabs SeaCat PKI

The C-ITS PKI that Europe's roads run on.

SeaCat PKI operates more of Europe's connected-mobility trust infrastructure than any other provider — the Root, Enrolment, and Authorization authorities that let vehicles and roadside systems trust every message they exchange. Standards-complete, sovereign, and run by the engineers who built it.

Request a consultation Read the technical spec

A European leader in C-ITS

The proof, up front.

Three of five new Root CAs in ECTL v8

In the EU's ECTL v8, three of the five new Root CA certificates run on SeaCat PKI — a direct stake in the pan-European C-ITS trust domain.

The most PKIs in the ECTL

More PKIs — Root CA, Enrolment Authority, and Authorization Authority — registered in the European Certificate Trust List than any other operator.

National C-ITS operator

Direct operator of the national C-ITS PKI for the Czech Road & Motorway Directorate (ŘSD).

Central infrastructure for two states

Central C-ITS security infrastructure for the Czech Republic and Slovenia.

C-ITS & connected mobility

Trust for every vehicle, every roadside unit, every message.

Cooperative, connected, and autonomous mobility only works if every participant can trust every message it receives. SeaCat PKI is the infrastructure that makes that trust real — operated at national and pan-European scale.

Every role in the trust model

Root CA, Enrolment Authority (EA), Authorization Authority (AA), and Trust List Manager (TLM) — all operated in one platform.

Standards-complete

ETSI TS 103 097, ETSI TS 102 941, IEEE 1609.2, and the EU C-ITS Certificate Policy. Connected to the EU CCMS and the European Certificate Trust List, with interoperability proven at ETSI C-ITS Plugtests.

Yours or ours

Delivered on your infrastructure — or operated by us as a managed service, as we do for national C-Roads deployments.

Beyond the road: industrial, IoT & OT

The same trust, for the devices that run critical infrastructure.

A smart meter, a grid controller, a hospital sensor, a piece of factory automation — each needs a strong identity, managed for years, at fleet scale, without a technician ever touching it. SeaCat PKI delivers exactly that.

Smart metering at national scale

PKI securing the device identity of electricity meters from ZPA Smart Energy, a Czech manufacturer shipping across Europe — protecting metering communication across smart-grid infrastructure.

Healthcare and connected medical IoT

Securing connected medical and hospital IoT environments, including IKEM.

Unattended by design

Automated certificate lifecycle for CPE and IoT devices with SCEP enrolment. Certificates renew, rotate, and revoke automatically, so a device fleet never falls out of trust.

One hardened foundation

The security engineering under both.

Certified HSM

Keys are generated and stored in a hardware security module certified to EN 419 221-5 (EAL4+) — Utimaco CryptoServer CP5. Your trust anchors never exist in software alone.

Modern elliptic-curve cryptography

ECDSA and ECIES over NIST P-256 and Brainpool P-256/384 — the cryptography the standards demand, implemented by the engineers who helped shape them.

Full lifecycle, end to end

From the Root CA at the top of the trust chain down to the certificate on the smallest device — issuance, distribution, renewal, rotation, and revocation, all in one platform.

Sovereign by design

Operated in Europe, on your infrastructure or ours. Your root of trust stays inside your jurisdiction — never offshore, never in someone else's cloud.

Frequently asked questions

What is a C-ITS PKI, and why does connected mobility need one?

Cooperative Intelligent Transport Systems let vehicles and roadside units exchange safety messages. A receiver has to know a message came from a legitimate, unrevoked participant — and it has to know within milliseconds. A C-ITS PKI issues and manages the short-lived certificates that make that decision possible, at motorway scale.

Can SeaCat PKI operate all the C-ITS trust roles?

Yes. SeaCat PKI implements Root CA, Enrolment Authority, Authorization Authority, and Trust List Manager, and is connected to the EU CCMS and the European Certificate Trust List.

How does SeaCat PKI secure IoT and OT devices at scale?

Each device gets a cryptographic identity issued at manufacture or first connection, then renewed, rotated, and revoked automatically over its service life — with SCEP enrolment for CPE and industrial equipment. No technician visit is required to keep a fleet in trust.

Where are the private keys kept?

In a hardware security module certified to EN 419 221-5 (EAL4+), Utimaco CryptoServer CP5. Keys are generated inside the HSM and never exist in software alone.

Can you operate the PKI for us, or does it run on our infrastructure?

Either. SeaCat PKI can be deployed on-premises, in your private cloud, or run by us as a fully managed service — which is how several national C-Roads deployments operate today.

Build on a root of trust that Europe already relies on.

Talk to the engineers who operate national C-ITS trust infrastructure and manage IoT certificate fleets at scale — and design the PKI your programme needs, on your terms.

Request a consultation sales@teskalabs.com

Book a demo

Tell us what you are building and one of our engineers will get back to you — usually within one working day.

We use your details only to answer your enquiry. No newsletter, no resale of data. Privacy policy