
The C-ITS PKI that Europe's
roads run on.
A European leader in C-ITS
The proof, up front.
- In the EU's ECTL v8, three of the five new Root CA certificates run on SeaCat PKI — a direct stake in the pan-European C-ITS trust domain.
- More PKIs — Root CA, Enrolment Authority, and Authorization Authority — registered in the European Certificate Trust List (ECTL) than any other operator.
- Direct operator of the national C-ITS PKI for the Czech Road & Motorway Directorate (ŘSD).
- Central C-ITS security infrastructure for the Czech Republic and Slovenia.
C-ITS & connected mobility
Trust for every vehicle, every roadside unit, every message.
Cooperative, connected, and autonomous mobility only works if every participant can trust every message it receives. SeaCat PKI is the infrastructure that makes that trust real — operated at national and pan-European scale.
What it does
- Operates every role in the C-ITS trust model: Root CA, Enrolment Authority (EA), Authorization Authority (AA), and Trust List Manager (TLM).
- Standards-complete: ETSI TS 103 097, ETSI TS 102 941, IEEE 1609.2, and the EU C-ITS Certificate Policy.
- Connected to the EU CCMS and the European Certificate Trust List (ECTL).
- Interoperability proven at ETSI C-ITS Plugtests.
- Delivered on your infrastructure — or operated by us as a managed service, as we do for national C-Roads deployments.
Trusted on the road Deployed across national road authorities, vehicle makers, and the largest cooperative-mobility programmes in Europe.
Beyond the road: Industrial, IoT & OT
The same trust, for the devices that run critical infrastructure.
A smart meter, a grid controller, a hospital sensor, a piece of factory automation — each needs a strong identity, managed for years, at fleet scale, without a technician ever touching it. SeaCat PKI delivers exactly that.
Proven in the field
- PKI securing the device identity of electricity meters from ZPA Smart Energy — a Czech meter manufacturer shipping across Europe — protecting metering communication across smart-grid infrastructure.
- Securing connected medical and hospital IoT (IKEM).
- [SZ — reference to confirm and add]
What it does
- PKI for smart metering and electricity meters — issuance, rotation, and full lifecycle management across entire fleets.
- Automated certificate lifecycle for CPE and IoT devices, with SCEP enrolment.
- Identity and trust for smart grid, industrial automation, and OT environments.
- Built to run unattended: certificates renew, rotate, and revoke automatically, so a device fleet never falls out of trust.
One hardened foundation
The security engineering under both.
Deployed your way - On-premises, in a private cloud, or fully managed as a service.
Certified HSM
Keys are generated and stored in a hardware security module certified to EN 419 221-5 (EAL4+) — Utimaco CryptoServer CP5. Your trust anchors never exist in software alone.
Modern elliptic-curve cryptography
ECDSA and ECIES over NIST P-256 and Brainpool P-256/384 — the cryptography the standards demand, implemented by the engineers who helped shape them.
Full lifecycle, end to end
From the Root CA at the top of the trust chain down to the certificate on the smallest device — issuance, distribution, renewal, rotation, and revocation, all in one platform.
Sovereign by design
Operated in Europe, on your infrastructure or ours. Your root of trust stays inside your jurisdiction — never offshore, never in someone else's cloud.
Trusted where it matters
Protecting European enterprise and critical infrastructure — from national government and healthcare networks to media, logistics, and finance. The organisations that legally and strategically cannot send their data abroad run LogMan.io.
