Unit 5 · Level 4 → 5: Optimized, Certified, Future-Ready

PKIC Working Groups — How to Participate Meaningfully

📖 Lesson 5.5 ⏱ 25 minutes 📋 3 comprehension questions

Part 1 — Why working groups matter

The PKI Consortium does not work through top-down mandates. It works through member-driven working groups, practitioner communities that research problems, draft documents, build tools, and shape the standards and guidance that the industry relies on. The PQCMM framework you've been learning throughout this course was built by a working group. The PKIMM maturity model was built by a working group. The reference materials your organization will use for its compliance evidence were built by people who showed up, contributed, and kept showing up.

This lesson answers the practical question: what does meaningful participation actually look like? Not membership for its own sake, but contribution that helps build something and develops your own expertise at the same time.

Who this lesson is most relevant for: Anyone who wants to go beyond consuming the framework to contributing to it. Persona A (motivated learner with professional development goals) will find the most direct application here. But Personas B and C have working group roles too, organizational representatives and technical implementers are exactly the voices working groups need.

Part 2 — The three primary working groups

PKIC operates several working groups. Three are most directly relevant to this course. Click each to see what it does, what it produces, and what a new member should do first.

PQC Working Group
Post-Quantum Cryptography WG
Owns and evolves the PQCMM framework
Primary output
PQCMM — Post-Quantum Cryptography Maturity Model (the six-level framework, 0–5, this course is built on)
Current focus
Maintaining and expanding PQCMM criteria, vendor assessment guidance, and migration tooling
Who participates
Cryptographers, PKI architects, migration practitioners, vendor representatives, standards body liaisons
Meeting cadence
Regular virtual sessions; in-person at PKIC conferences (typically annual)

The PQC WG is the most technically demanding of the three. Productive contributions require familiarity with PQC algorithm properties, migration methodology, and the PQCMM criteria at a detailed level. If you have completed this course and are working through a real organizational migration, you have the foundational knowledge to contribute, but expect to read the existing drafts carefully before your first substantive contribution.

First actions for a new member

  • Read the current published PQCMM document from end to end, the working group assumes members know it
  • Review open GitHub issues or document comments to understand what is actively being discussed
  • Introduce yourself on the mailing list with your background and what you're hoping to contribute (implementation experience, organizational perspective, regional context)
  • Attend two or three sessions before speaking, understand the norms and active debates first
PKIMM Working Group
PKI Maturity Model WG
Owns the PKIMM framework and assessment methodology
Primary output
PKIMM — PKI Maturity Model, including the self-assessment tool you used in Unit 4
Current focus
Expanding PKIMM coverage, improving assessment tooling, and integrating PQC readiness more deeply into the model
Who participates
PKI program managers, compliance officers, auditors, enterprise IT professionals, CA operators
Entry point
More accessible than the PQC WG for practitioners without deep cryptography backgrounds

The PKIMM WG is an excellent entry point for practitioners who understand PKI program management, compliance, and governance but may not have deep algorithm expertise. If you have completed a real PKIMM self-assessment for your organization (which this course prepares you to do), your experience with the tool, what worked, what was unclear, what criteria felt incomplete, is genuine and valuable input. Working groups improve from practitioner feedback, and your completed Unit 4 deliverable gives you something concrete to reference.

First actions for a new member

  • Download and work through the current PKIMM assessment tool, bring notes on areas where the guidance was unclear or criteria felt misaligned with real-world PKI programs
  • Review the PKIMM methodology document, particularly the scoring and weighting approach
  • Introduce yourself with your organizational context, what sector, what size, what compliance framework you operate under
  • Offer to review a draft section, reviewing and providing written feedback is one of the most useful contributions a new member can make
TCWG
Training and Certification Working Group
Building the PKI Reference Book and broader trust infrastructure guidance
Flagship project
PKI Reference Book, a comprehensive practitioner guide to PKI deployment, operations, and governance
Current focus
Expanding reference book chapters, PQC migration guidance sections, and trust model documentation
Who participates
PKI practitioners, CA operators, enterprise architects, educators, technical writers
Entry point
The most accessible of the three, writing and editing contributions are as valued as technical ones

The TCWG's PKI Reference Book project is actively looking for contributors across skill levels. If you can write clearly about PKI concepts, which completing this course has prepared you to do, you can contribute meaningfully. Chapter drafting, technical review, example contribution, and editorial improvement are all valid entry points. This is the working group where someone who has just completed a course like this one is most likely to make an immediate, visible contribution.

First actions for a new member

  • Read the current published sections of the PKI Reference Book, understand the tone, depth, and structure the group is targeting
  • Identify a chapter or section where you have direct experience to contribute (your organization's migration story, a specific algorithm implementation, a compliance framework connection)
  • Volunteer to draft or review a section, even a 500-word contribution to a chapter draft is meaningful
  • Join the mailing list and introduce yourself with the topic area you'd like to contribute to

Part 3 — Your first 90 days as a PKIC member

Joining a working group without a plan leads to passive observation. This 90-day framework gives you a concrete sequence regardless of which working group you join. Select the phase to see the specific actions.

Days 1–30
Days 31–60
Days 61–90

Orientation and listening

  • 1
    Join PKIC as a member. Individual membership is available at pkic.org. Review the membership terms and working group charter for your chosen group.
  • 2
    Read the primary output document end-to-end. PQCMM for the PQC WG, PKIMM methodology for the PKIMM WG, PKI Reference Book drafts for the TCWG. Take notes on questions and gaps.
  • 3
    Subscribe to the mailing list and read the archives. Six months of mailing list history will tell you the active debates, the key contributors, and the tone of the group faster than any other source.
  • 4
    Attend your first session without speaking. Introduce yourself briefly if there is an introductions round. Otherwise: listen, take notes, identify two or three people whose contributions you want to follow.
  • 5
    Send one written introduction. One paragraph on your background, what you're working on, and what you hope to contribute. Short is better than long.

First contribution

  • 1
    Identify one specific contribution opportunity. A document section that needs a reviewer, an open issue you have direct experience with, a chapter topic where your organization's story is relevant. Be specific, "I can help with X" lands better than "I'd like to contribute."
  • 2
    Submit your first written contribution. This might be a review comment on a draft, a response to an open question on the mailing list, or a short draft section. Quality matters more than length, one precise, well-reasoned paragraph is more valuable than three pages of loosely organized thoughts.
  • 3
    Attend two more sessions. You should now recognize the recurring contributors and understand the meeting rhythm. Ask one question or make one comment per session, more than that early on can crowd out established contributors.
  • 4
    Connect with one working group member directly. A brief follow-up message after a session, "I found your point about X interesting, here's how it relates to what we're seeing in our organization", builds the relationships that make working group participation sustainable.

Establishing a recurring role

  • 1
    Complete your first deliverable. Whatever contribution you started in Days 31–60, finish it. Follow-through is how working group members build reputation. The people who say they'll do something and then do it are the ones who get asked to take on more.
  • 2
    Propose your next contribution. Based on what you've learned in the first 60 days, identify where your skills and experience are most needed. Propose it explicitly, "I'd like to take on the [X] section in the next draft cycle", so the group can plan around your commitment.
  • 3
    Bring one new voice. If someone in your organization or network would benefit from PKIC membership, introduce them. Working groups grow through referral from trusted members, and the person you bring reflects on your own judgment.
  • 4
    Reflect on what you've learned. The 90-day mark is a good point to ask: what have I contributed? What have I learned that I couldn't have learned any other way? What do I want to do in the next 90 days? Write it down, this becomes the foundation of your Personal PQC Readiness Roadmap entry for working group engagement.

Part 4 — What PKIC membership is and how to join

The PKI Consortium (pkic.org) is an open, vendor-neutral industry organization. Membership is available to individuals and organizations. Individual practitioners can join directly, you do not need an organizational sponsor.

How to join: Visit pkic.org, navigate to the membership section, and complete the membership application. Review the working group charters to identify which group aligns with your goals. You can participate in multiple working groups, many active members do, but starting with one is the recommended approach.

Working group participation typically happens through:

A note on time commitment: Meaningful participation does not require 20 hours a week. Reading agendas and meeting notes, attending one session a month, and submitting one written contribution per quarter is enough to be a recognized, valued member. The members who contribute the most are usually those who do one thing consistently well, not those who spread themselves across every topic.

Part 5 — Finding your entry point

Persona A — Motivated Learner

The TCWG's PKI Reference Book project is your best first entry point. You can write. You understand the framework. You have the learner's perspective, which is exactly what a reference document needs to be accessible to the next generation of practitioners. Offer to draft or review a section on PQC migration fundamentals, CBOM methodology, or PQCMM level descriptions. These are topics you've just spent five units studying.

Once you're established in the TCWG, the PQC WG is a natural next step, especially if your interests trend toward the entrepreneurial and technical intersection. The PKIC working group participation record is also a credential you can cite in your Personal PQC Readiness Roadmap. Under the PKIC engagement section, you can write: "Target: join TCWG by [date], submit first written contribution by [date+30 days], attend three sessions by [date+90 days]." That is a specific, measurable commitment.

Persona B — SMB Decision-Maker

The PKIMM WG is the most relevant group for a decision-maker. The maturity model benefits enormously from the perspective of organizations that are not large enterprises or CA vendors: SMBs navigating migration with limited resources represent a significant constituency that is often underrepresented in standards work.

Your entry contribution could be as simple as: "Here is what the PKIMM self-assessment looked like from the perspective of a 50-person organization without a dedicated security team. Here are the criteria that were unclear, the ones that didn't apply, and the ones that were most useful." That kind of structured feedback from a real practitioner is the raw material that makes maturity models better. You don't need cryptographic expertise to make that contribution, you need honest organizational experience, which you have.

Persona C — IT Professional

All three working groups need your kind of contribution. Technical implementation experience, what it actually looks like to deploy hybrid TLS in a production environment, what the CBOM process revealed, what vendor conversations taught you, is exactly the grounding that keeps standards documents connected to reality.

Consider targeting the PQC WG if your work has given you direct exposure to PQCMM criteria evaluation or vendor assessment. Consider the PKIMM WG if your focus has been on PKI program governance and compliance documentation. The TCWG benefits from technical reviewers who can confirm that reference book sections accurately reflect real deployment scenarios. Any of the three is a strong fit, pick the one that maps most directly to the work you're doing right now and commit to 90 days of active participation.

?

Comprehension check

Question 1 of 3
A practitioner has just completed a PKIMM self-assessment for their organization and found several criteria that felt unclear or misaligned with their real-world PKI program. Which working group is most directly positioned to benefit from this feedback, and why?
Question 2 of 3
In the first 30 days of PKIC working group membership, what is the most important behavior for a new member?
Question 3 of 3
A motivated learner who has just completed this course wants to contribute to PKIC but does not have deep cryptographic algorithm expertise. Which working group and contribution type are the best fit?
out of 3 correct

Coming up next
Lesson 5.6 — The Digital Equity Imperative