PKI vs Certums

Comparison between the traditional digital signature model (PKI) and the Certums platform

Although both models use public-key cryptography and provide legally valid signatures, Certums modernizes how electronic signatures are distributed, used and verified, removing many of the operational barriers of the classic PKI model.

Certums does not replace PKI cryptography: it uses it as its technological foundation and complements it with a modern, service-oriented architecture.

Advantages of Certums over the traditional PKI model

Summary; the detail for each point is below.

Aspect Traditional PKI model Certums
Usability & adoption Certificates, tokens and middleware per user Just authenticate and authorize
Identity & signing One certificate for everything Authentication and signing separated
Verification X.509, CRL/OCSP and technical tools CSV and QR from the browser
Preservation Depends on each system Long-lived PAdES
Trust Valid or not valid Assurance levels by risk
Platform Focused on generating the signature Comprehensive service with auditing
01

Greater ease of use and adoption

Traditional PKI model

In the traditional PKI model, each user must obtain a digital certificate, safeguard their private key, install specialized middleware and, in many cases, use cryptographic tokens or smart cards. This hinders mass adoption and creates a heavy technical-support burden.

Certums

In Certums, the user only needs to authenticate and authorize the signature. The entire cryptographic infrastructure is managed centrally and securely, removing the need to install certificates, drivers or specialized software on the citizen’s device.

Benefit: Significantly lowers the barriers to entry and makes electronic signatures easier to roll out at scale.

02

Separation of identity and signature

Traditional PKI model

In traditional PKI systems, the certificate used to authenticate is the same one that allows documents to be signed. In practice, whoever holds the certificate is able to sign.

Certums

Certums separates the two concepts. Authentication identifies the user and determines their level of trust, while signing is an independent operation that requires specific authorization and may be subject to additional policies.

Benefit: Greater control, flexibility and security, making it possible to define which users can sign, under what conditions and with what level of assurance.

03

Simple verification for any citizen

Traditional PKI model

Verifying a traditional PKI signature requires validating X.509 certificates, trust chains and revocation mechanisms (CRL or OCSP), usually through specialized tools.

Certums

Certums includes a public verification system based on a Secure Verification Code (CSV) and a QR code. Anyone can check a document’s authenticity, even when printed on paper, from a web browser and without technical knowledge. In parallel, the platform maintains full cryptographic validation through PAdES signatures and a cryptographically linked evidence chain.

Benefit: Makes authenticity checks easier for specialists as well as for citizens and public bodies.

04

Better prepared for long-term preservation

Traditional PKI model

In many PKI implementations, preserving legal validity over long periods depends on each system and on how it manages timestamps and evidence.

Certums

Certums adopts a model based on PAdES standards with a progressive evolution toward long-lived signatures through timestamping and evidence preservation.

Benefit: Greater ability to guarantee that documents remain verifiable for years, even when certificates or cryptographic algorithms change.

05

A more flexible trust model

Traditional PKI model

The classic PKI model works essentially in a binary way: the certificate is either valid or it is not.

Certums

Certums incorporates different levels of identity assurance. A user can authenticate through different mechanisms, while certain operations will only be available when there is a state-verified identity.

Benefit: Lets you match the level of security to the risk of each procedure, without requiring the highest level of authentication for every service.

06

A comprehensive electronic-signature platform

Traditional PKI model

The traditional model focuses mainly on generating the digital signature.

Certums

Certums provides a complete services platform that includes document management, signing workflows, auditing, traceability, an immutable event log, isolation between organizations and protection of personal data. All activity is recorded through cryptographic evidence that strengthens the system’s evidentiary weight.

Benefit: Turns electronic signatures into a cross-cutting service for organizations, rather than just a cryptographic tool.

Conclusion

Certums does not replace PKI cryptography; it uses it as its technological foundation and complements it with a modern, service-oriented architecture. The result is a platform that maintains the security level of PKI-based digital signatures while significantly improving the user experience, easing mass adoption, simplifying document verification, enabling different levels of trust to be managed, and providing advanced auditing, preservation and large-scale operation capabilities.

Compared with the traditional model based solely on certificates installed on the user’s device, Certums offers a more accessible, scalable and flexible solution, ready for the digital transformation of public and business services.