Smallstep Certificate Manager by Smallstep is a managed certificate authority (CA) capable of issuing private x.509 TLS certificates. It builds on two open-source projects maintained by Smallstep: step-ca, a private online certificate authority for secure automated certificate management, and step, a general-purpose cryptography toolkit and client-side counterpart to step-ca. Smallstep Certificate Manager delivers highly available hosted certificate authorities, expiry notifications and alerts, a management dashboard, and active revocation. It automates the creation of authorities, provisioners, templates, and policies when you register a device or workload on the Smallstep platform. It requires you to manage the design, architecture, and configuration of your PKI. Smallstep Certificate Manager is designed to be operationally simple and easy to use, providing a flexible toolchain with server and client-side components. It supports the ACME protocol, Kubernetes workloads, single sign-on, one-time tokens, and Cloud VM instance APIs for automating certificates. It is available as a managed, linked, or on-premise solution. Smallstep Certificate Manager ensures that only company-owned devices can access sensitive resources by introducing Device Identity. It also supports legacy enrollment protocols and validation services such as SCEP, NDES, OCSP, and CRL, making it compatible with existing PKI infrastructures.