Two press releases landed before 9 a.m. ET on Monday, and they rhyme. At 7:00, Keyfactor said its $1B+ growth investment led by Summit Partners has closed and that former CyberArk CEO Matt Cohen is joining its board (per Keyfactor). At 8:30, SAIC said it completed its acquisition of Information Security Corporation, the PKI, encryption and credential-management shop behind CertAgent (per SAIC). Terms: Undisclosed.
Different buyers, different checks, same asset: the layer that issues and manages the keys and certificates everything else trusts. Our take is that PKI has stopped being plumbing and started being a control point worth owning. Post-quantum migration and shrinking certificate lifetimes are doing the forcing.
SAIC/ISC: a prime buys a CA. ISC has sold PKI and encryption software for more than three decades. Its CertAgent certificate authority has sat on NSA’s Commercial Solutions for Classified (CSfC) Components List for more than a decade, and SAIC says ISC’s technology is deeply embedded across the intelligence community and the Department of War. SAIC, with roughly $7.3B in annual revenue by its own count, called it a strategic tuck-in. KPMG advised SAIC. TideLock Partners advised ISC.
What changes in the stack: an integrator that runs zero-trust builds now owns the CA underneath them. Expect CertAgent to ride inside SAIC task orders. If you sell PKI or PQC migration into DoD and the IC, a prime just became a competitor, not only a channel. Speculation, clearly labeled: other primes with zero-trust practices will look at the remaining independent government PKI vendors the same way.
Keyfactor: the independent gets a war chest. Summit’s round was announced July 6. Insight Partners and Sixth Street Growth keep significant ownership. Keyfactor has passed $200M ARR (per Keyfactor), and Summit says it serves more than 2,500 customers, including more than 40% of the Fortune 100. Stated uses: product, international expansion, and strategic acquisitions across machine identity, cryptography, AI security and post-quantum readiness. Valuation: Undisclosed.
The Cohen hire is the tell. He ran CyberArk into its roughly $25B sale to Palo Alto Networks (per Keyfactor), which closed February 11, 2026 (per Palo Alto Networks). CyberArk had already bought Venafi, Keyfactor’s best-known rival, from Thoma Bravo in October 2024 for about $1.54B (per CyberArk). So the biggest machine-identity independent just put on its board the operator who sold the company that now owns its rival. Read it as preparing for scale: either a long independent run or an exit at a size only a platform can pay. Which one is speculation. The $1B+ and the acquisition mandate are not.
The forcing functions have dates. Under CA/Browser Forum ballot SC-081v3, maximum public TLS certificate validity fell from 398 to 200 days on March 15, 2026. It drops to 100 days on March 15, 2027 and 47 days on March 15, 2029, and domain-validation reuse eventually shrinks to 10 days. At 47 days, every public cert in your estate turns over roughly eight times a year. Calendar reminders stop working long before that. That’s what turns discovery, automated issuance and crypto-agility into a budget line. Post-quantum migration puts the same pressure on internal PKI, because you can’t swap algorithms you haven’t inventoried.
What a practitioner should do with this. Pull your certificate inventory and sort it by issuer and renewal method. Anything a human renews is your 2027 outage. Find the hard-coded trust anchors in apps and appliances, because those break first when you rotate roots or algorithms. Then ask both camps the same question: can you find certs and keys you didn’t issue? Platforms will sell you identity plus PKI in one SKU. Independents will sell neutrality across clouds and CAs. Both pitches are fair. Know which one you’re buying, and what happens to your roadmap if your independent gets bought.
The financial read. Nobody printed a multiple today. What printed: one strategic buy with no price, one $1B+ private round with no valuation, and a board seat for the CEO behind a ~$25B exit. Don’t back into a PKI comp from that. Do mark the direction. Capital is concentrating where trust gets minted, and the 100-day deadline lands inside most buyers’ next renewal cycle.
