Unit 4 From Zero to Quantum-Ready · Level 3 → 4 ⭐ All 5 PKIMM Requirements
Lesson 4.6 · Hands-On Lab · 50 min

The PKIMM Self-Assessment — Doing It for Real

This is not a practice run. By the end of this lesson you will have a scored PKIMM result, a screenshot that serves as auditable compliance evidence, and a written interpretation ready to submit as your primary capstone artifact.

📋 Hands-On Lab 🏆 Primary Evidence Artifact ✅ All 5 PKIMM Knowledge & Training requirements

Part 1 · What the PKIMM Is and Why Your Score Matters

The PKI Maturity Model (PKIMM) is a framework developed by the PKI Consortium to help organizations measure and improve how well they design, operate, and maintain their public key infrastructure. "PKI" stands for Public Key Infrastructure — the system of certificates, keys, and trust authorities that underlies secure websites, email, code signing, and nearly every digital authentication mechanism your organization relies on.

The PKIMM is modeled on the Capability Maturity Model Integration (CMMI) — the same approach used to evaluate software development and organizational process quality. It evaluates PKI programs across 16 categories (PKIMM version 2.0.0, including the centralized Cryptography category under Governance), rated on a five-level scale from Level 1 (Initial) to Level 5 (Optimized).

For the Knowledge and Training category specifically, the one this entire course is designed to satisfy, the five levels mean:

PKIMM · Knowledge & Training Levels

Level 1 — Initial: There is no training or education plan for PKI personnel.
Level 2 — Foundational: A training plan exists, but no one is responsible for executing it.
Level 3 — Advanced: The training plan is integrated in the organization. PKI personnel know the plan and their responsibilities.
Level 4 — Managed: The plan is maintained and executed. Knowledge and proficiency requirements are monitored.
Level 5 — Optimized: The training plan is periodically reviewed and updated. An education plan is maintained and aligned with PKI policies and procedures.

Completing this course and producing the two unit deliverables (the self-assessment result and the annotated checklist) moves most organizations from Level 1 or 2 to Level 3, with supporting evidence for Level 4.

Your PKIMM score is not a grade on your performance. It is a diagnostic, an honest picture of where your organization or your defined scope actually stands. A Level 2 score is not a failure; it is a starting point with a clear path forward.


Part 2 · Define Your Scope Before You Start

Before opening the PKIC online tool, you need to decide what scope you are assessing. The tool asks questions about policies, personnel, systems, and procedures. Your answers depend entirely on which organization or environment you are evaluating.

You have two valid options for this lab:

Option A — Your Real Organization

Assess the organization where you work or where you manage PKI decisions. This produces the highest-value output, a scored result you can present to leadership, a CISO, or a compliance auditor as real evidence. If you have access to the information needed (certificate policies, training records, change management processes), choose this option.

Option B — Meridian Creative Agency (Fictional Profile)

If you are an individual learner without an organizational PKI context, or if you prefer not to document your employer's current state in a course submission, use the Meridian Creative Agency profile established in Unit 3. Meridian is a 48-person marketing agency with Microsoft 365, one cloud-hosted website, no on-premise servers, and no hardware security modules. All relevant answers for Meridian were defined in the Unit 3 CBOM exercise. Your Meridian score will be realistic, and somewhat low, which is appropriate for a small business at Level 1–2.

Whatever scope you choose, write it down before you open the tool. Changing your scope mid-assessment will invalidate your results.

For Persona A · Motivated Learner

If you are building toward PKIC membership or SSCP/CISSP, use Meridian unless you are actively working in a PKI role. Producing a clean, well-interpreted Meridian assessment is more valuable to your portfolio than a partial assessment of an environment you do not fully control. The interpretation you write is where your analytical skill shows.

For Persona B · SMB Decision-Maker

Use your own organization. Even if you are not deeply technical, the PKIMM tool is written in accessible language. You will not need to know what an HSM is to answer whether your organization has formal procedures for certificate issuance, you either do or you do not. Your score will likely land at Level 1 or 2, and that is the correct answer for most SMBs today. Honest is more useful than optimistic.

For Persona C · IT Professional

Use your organization. You will have the context to answer the technical questions accurately. Before you start, gather: your current certificate policy or CP/CPS document (if one exists), your training records for PKI-related roles, your change management procedure, and your certificate lifecycle management (CLM) tool information. These four items cover most of the harder questions.


Part 3 · Lab Walkthrough — Step by Step

Work through each step below in order. Click a step to see the detailed instructions. Mark each step complete before moving to the next.

Step 1 — Open the PKIC PKIMM Online Tool

Complete the self-assessment exclusively via the official web-based tool hosted at pkic.org. Open the PKIMM section and start the online Quick Assessment / Self-Assessment. Do not download or use the retired Excel-based PKIMM assessment tools (.xlsx) or any /main/-pinned GitHub URLs pointing to tools/PKI_Maturity_Assessment_Tool_*.xlsx — those files were retired in PKIMM 2.0.0 and are no longer the official assessment path.

The web tool is free and does not require an account. It runs entirely in your browser, no data is sent to any server unless you choose to create a PKIC account to save your results. Creating a free account is recommended so you can return to your results later.

  • No software to install.
  • Works in any modern browser (Chrome, Firefox, Edge, Safari).
  • Session typically takes 25–40 minutes depending on how thoroughly you research answers.
If the direct link has changed

Search for "PKIC PKIMM self-assessment tool" and look for a result on pkic.org. Do not use third-party versions of the tool, only the official PKIC tool produces auditable results.

Step 2 — Confirm Your Scope and Enter the Context Fields

The tool will ask you to define the assessment context before showing you questions. This typically includes: organization type, size, industry sector, and the role of the person completing the assessment.

For your real organization: fill in these fields accurately. The context fields do not affect your score, they are metadata for your records and any future comparison assessments.

For Meridian Creative Agency: use these reference values:

  • Organization type: Private company
  • Size: 48 employees (Small)
  • Sector: Marketing / Professional Services
  • Assessor role: IT Manager (or equivalent)
  • Assessment scope: All organizational IT systems

Step 3 — Answer the Assessment Questions

The PKIMM self-assessment covers 16 categories. You will answer a series of questions for each. Questions are typically presented as maturity indicators, statements that you rate as Not Achieved, Partially Achieved, or Fully Achieved.

Practical guidance for each major category:

  • Certificate Policy (CP) and Certificate Practice Statement (CPS): Does your organization have a written document defining how certificates are issued? Most SMBs do not, answer honestly.
  • Knowledge and Training: This is the category this course directly addresses. If you are completing this course, you have a training plan in progress. You can accurately claim Partially Achieved for training plan and personnel training indicators.
  • Incident Response: Does your organization have a documented procedure for responding to a compromised certificate or private key? If not, mark Not Achieved.
  • Certificate Lifecycle Management (CLM): CLM means automated tracking, renewal, and revocation of certificates. If you are managing certificates manually via spreadsheet or calendar reminders, this is Level 1–2 behavior.
  • Cryptography (Governance): New in PKIMM 2.0.0. This category centralizes algorithm, parameter, and protocol governance. Cipher-suite documentation is assessed here, not under Key Management or Certificate Management.
  • Crypto-Agility: Can your systems swap cryptographic algorithms without a full rebuild? If you completed Unit 3 and performed the CBOM exercise, you now have more insight into this than most organizations of your size.
Resist the urge to be optimistic

Answer based on what is documented and demonstrably practiced, not what you intend to do or what you believe is probably happening somewhere. An inflated score does not make your organization more secure. An honest score gives you a useful baseline.

Step 4 — Review Your Results

When you complete all 16 categories, the tool generates a scored result. You will see:

  • An overall PKIMM maturity level (1–5)
  • A category-by-category breakdown showing which areas scored highest and lowest
  • A radar or spider chart visualizing your scores across categories
  • Recommended actions for improvement based on your current level

Spend 5–10 minutes reviewing the results before capturing them. Read the category-level breakdown carefully, the overall level is a summary, but the category scores tell you where the real gaps are. Your written interpretation in Step 6 will depend on understanding which categories dragged your score down and why.

What a typical result looks like

Most organizations completing this assessment for the first time score at Level 1 or 2 overall, with one or two categories at Level 3. Knowledge and Training often scores higher than Certificate Lifecycle Management or Incident Response, because training plans are easier to document than automated CLM systems. This is normal and expected.

2.1
Typical overall score (first assessment)
3+
Knowledge & Training (after this course)
1–2
CLM and Incident Response (most SMBs)

Step 5 — Screenshot and Save Your Results

This step is mandatory. Your screenshot is the auditable evidence artifact that goes into your capstone submission and satisfies the PKIMM Knowledge and Training evidence requirement.

⚠ Do not skip this step

Without a saved screenshot or export, your assessment has no evidence value. A verbal description of your score is not an acceptable compliance artifact. The file you save here is what a PKIMM assessor would request if your organization were being evaluated.

How to capture your evidence:

  • Screenshot (minimum): Capture the full results page showing your overall level, the category breakdown, and the radar chart. On Windows: Win + Shift + S. On Mac: Cmd + Shift + 4. On mobile: Power + Volume Down.
  • Export PDF (preferred): If the tool offers a "Download Results" or "Export to PDF" option, use it. The PDF includes timestamps and category details not always visible in a screenshot.
  • If you created a PKIC account: Your results are saved to your account. Download and save a local copy as a backup.

Save your file as: PKIMM_Assessment_[YourName or Meridian]_[Date].pdf

This file name format makes it immediately identifiable when it is submitted as part of your capstone evidence package.

Step 6 — Write Your 300-Word Interpretation

Your written interpretation transforms a score into understanding. It demonstrates that you can read the results, identify what they mean, and recommend concrete next steps. This is where a Deliverable A submission earns full marks, not in the score itself.

Your 300-word interpretation must cover exactly three things:

  • Your current PKIMM level — State it clearly and explain what it means in practice. Not just "Level 2" but "Level 2, which means our training plan exists in outline form but lacks documented execution and consistent delivery across all PKI-relevant personnel."
  • Your top three gaps — Identify the three categories with the lowest scores and explain, in plain language, what is missing. A gap is not just a low number, it is a specific missing practice, document, or process.
  • Recommended first 90-day actions — Name three concrete, achievable actions your defined scope could take in the next 90 days. Not aspirational five-year plans, actual next steps. For an SMB, this might be: (1) document the informal training that already happens, (2) implement automated certificate expiry alerts, (3) assign a named person as PKI owner.
What a strong interpretation looks like

A strong interpretation reads like a short memo to a CISO or operations manager, factual, specific, and actionable. It does not apologize for the score. It does not pad word count with definitions. It states what the score reveals and what should happen next. That is the professional output this evidence artifact is designed to demonstrate.


Your Deliverable A Evidence Package

Deliverable A — What You Are Submitting

1
PKIMM self-assessment screenshot or PDF export — the scored results page showing your overall level, category breakdown, and radar chart. File name: PKIMM_Assessment_[Name]_[Date].pdf
2
300-word written interpretation — covering your current PKIMM level, top three gaps, and recommended first 90-day actions. Can be submitted as a Word document, PDF, or typed directly into the platform submission field.
PKIMM compliance satisfied: This deliverable simultaneously satisfies the Personnel Training, Training Plan, Knowledge Review, Security Awareness Training, and Education Plan requirements. All five Knowledge and Training indicators are evidenced by this submission.

Comprehension Check: Lesson 4.6

Three questions. Select the best answer and check your thinking.

1. You complete the PKIMM self-assessment and receive an overall score of Level 2, but your Knowledge and Training category scores at Level 3. Which statement best describes what this means?
2. A colleague says: "I answered some of the PKIMM questions optimistically: I marked things as achieved even if we only do them informally, because we will formalize them soon." What is the main problem with this approach?
3. Why is a screenshot or PDF export of your PKIMM results required, rather than simply describing your score in the written interpretation?
Deliverable A · Unit 4

PKIMM Self-Assessment — Submission Checklist

Before submitting Deliverable A, confirm you have all three components.

PKIMM tool results, screenshot (PNG/JPG) or exported PDF with overall level and category breakdown visible
300-word written interpretation covering: current PKIMM level, top three gaps, recommended first 90-day actions
Defined scope documented, either your real organization name or "Meridian Creative Agency (fictional)"