This is not a practice run. By the end of this lesson you will have a scored PKIMM result, a screenshot that serves as auditable compliance evidence, and a written interpretation ready to submit as your primary capstone artifact.
The PKI Maturity Model (PKIMM) is a framework developed by the PKI Consortium to help organizations measure and improve how well they design, operate, and maintain their public key infrastructure. "PKI" stands for Public Key Infrastructure — the system of certificates, keys, and trust authorities that underlies secure websites, email, code signing, and nearly every digital authentication mechanism your organization relies on.
The PKIMM is modeled on the Capability Maturity Model Integration (CMMI) — the same approach used to evaluate software development and organizational process quality. It evaluates PKI programs across 16 categories (PKIMM version 2.0.0, including the centralized Cryptography category under Governance), rated on a five-level scale from Level 1 (Initial) to Level 5 (Optimized).
For the Knowledge and Training category specifically, the one this entire course is designed to satisfy, the five levels mean:
Level 1 — Initial: There is no training or education plan for PKI personnel.
Level 2 — Foundational: A training plan exists, but no one is responsible for executing it.
Level 3 — Advanced: The training plan is integrated in the organization. PKI personnel know the plan and their responsibilities.
Level 4 — Managed: The plan is maintained and executed. Knowledge and proficiency requirements are monitored.
Level 5 — Optimized: The training plan is periodically reviewed and updated. An education plan is maintained and aligned with PKI policies and procedures.
Completing this course and producing the two unit deliverables (the self-assessment result and the annotated checklist) moves most organizations from Level 1 or 2 to Level 3, with supporting evidence for Level 4.
Your PKIMM score is not a grade on your performance. It is a diagnostic, an honest picture of where your organization or your defined scope actually stands. A Level 2 score is not a failure; it is a starting point with a clear path forward.
Before opening the PKIC online tool, you need to decide what scope you are assessing. The tool asks questions about policies, personnel, systems, and procedures. Your answers depend entirely on which organization or environment you are evaluating.
You have two valid options for this lab:
Assess the organization where you work or where you manage PKI decisions. This produces the highest-value output, a scored result you can present to leadership, a CISO, or a compliance auditor as real evidence. If you have access to the information needed (certificate policies, training records, change management processes), choose this option.
If you are an individual learner without an organizational PKI context, or if you prefer not to document your employer's current state in a course submission, use the Meridian Creative Agency profile established in Unit 3. Meridian is a 48-person marketing agency with Microsoft 365, one cloud-hosted website, no on-premise servers, and no hardware security modules. All relevant answers for Meridian were defined in the Unit 3 CBOM exercise. Your Meridian score will be realistic, and somewhat low, which is appropriate for a small business at Level 1–2.
Whatever scope you choose, write it down before you open the tool. Changing your scope mid-assessment will invalidate your results.
If you are building toward PKIC membership or SSCP/CISSP, use Meridian unless you are actively working in a PKI role. Producing a clean, well-interpreted Meridian assessment is more valuable to your portfolio than a partial assessment of an environment you do not fully control. The interpretation you write is where your analytical skill shows.
Use your own organization. Even if you are not deeply technical, the PKIMM tool is written in accessible language. You will not need to know what an HSM is to answer whether your organization has formal procedures for certificate issuance, you either do or you do not. Your score will likely land at Level 1 or 2, and that is the correct answer for most SMBs today. Honest is more useful than optimistic.
Use your organization. You will have the context to answer the technical questions accurately. Before you start, gather: your current certificate policy or CP/CPS document (if one exists), your training records for PKI-related roles, your change management procedure, and your certificate lifecycle management (CLM) tool information. These four items cover most of the harder questions.
Work through each step below in order. Click a step to see the detailed instructions. Mark each step complete before moving to the next.
Complete the self-assessment exclusively via the official web-based tool hosted at
pkic.org. Open the PKIMM section and start the online Quick Assessment
/ Self-Assessment. Do not download or use the retired Excel-based PKIMM assessment tools
(.xlsx) or any /main/-pinned GitHub URLs pointing to
tools/PKI_Maturity_Assessment_Tool_*.xlsx — those files were retired in
PKIMM 2.0.0 and are no longer the official assessment path.
The web tool is free and does not require an account. It runs entirely in your browser, no data is sent to any server unless you choose to create a PKIC account to save your results. Creating a free account is recommended so you can return to your results later.
Search for "PKIC PKIMM self-assessment tool" and look for a result on pkic.org. Do not use third-party versions of the tool, only the official PKIC tool produces auditable results.
The tool will ask you to define the assessment context before showing you questions. This typically includes: organization type, size, industry sector, and the role of the person completing the assessment.
For your real organization: fill in these fields accurately. The context fields do not affect your score, they are metadata for your records and any future comparison assessments.
For Meridian Creative Agency: use these reference values:
The PKIMM self-assessment covers 16 categories. You will answer a series of questions for each. Questions are typically presented as maturity indicators, statements that you rate as Not Achieved, Partially Achieved, or Fully Achieved.
Practical guidance for each major category:
Answer based on what is documented and demonstrably practiced, not what you intend to do or what you believe is probably happening somewhere. An inflated score does not make your organization more secure. An honest score gives you a useful baseline.
When you complete all 16 categories, the tool generates a scored result. You will see:
Spend 5–10 minutes reviewing the results before capturing them. Read the category-level breakdown carefully, the overall level is a summary, but the category scores tell you where the real gaps are. Your written interpretation in Step 6 will depend on understanding which categories dragged your score down and why.
Most organizations completing this assessment for the first time score at Level 1 or 2 overall, with one or two categories at Level 3. Knowledge and Training often scores higher than Certificate Lifecycle Management or Incident Response, because training plans are easier to document than automated CLM systems. This is normal and expected.
This step is mandatory. Your screenshot is the auditable evidence artifact that goes into your capstone submission and satisfies the PKIMM Knowledge and Training evidence requirement.
Without a saved screenshot or export, your assessment has no evidence value. A verbal description of your score is not an acceptable compliance artifact. The file you save here is what a PKIMM assessor would request if your organization were being evaluated.
How to capture your evidence:
Save your file as: PKIMM_Assessment_[YourName or Meridian]_[Date].pdf
This file name format makes it immediately identifiable when it is submitted as part of your capstone evidence package.
Your written interpretation transforms a score into understanding. It demonstrates that you can read the results, identify what they mean, and recommend concrete next steps. This is where a Deliverable A submission earns full marks, not in the score itself.
Your 300-word interpretation must cover exactly three things:
A strong interpretation reads like a short memo to a CISO or operations manager, factual, specific, and actionable. It does not apologize for the score. It does not pad word count with definitions. It states what the score reveals and what should happen next. That is the professional output this evidence artifact is designed to demonstrate.
PKIMM_Assessment_[Name]_[Date].pdf
Three questions. Select the best answer and check your thinking.