Smallstep
Hardware-backed device identity and automated certificate lifecycle management, using the ACME Device Attestation standard, for Zero Trust access.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Smallstep, founded in 2016 and headquartered in California, builds a device-identity and certificate lifecycle management platform for Zero Trust access. Its core technology issues and automates hardware-backed certificates so that only verified, company-owned devices — not just valid user credentials — can reach sensitive resources such as Wi-Fi/VPN, internal web apps, cloud APIs, and Git repositories. Smallstep also maintains step-ca, a widely used open-source certificate authority toolchain, which the company states is used in some form by a large share of Fortune 100 companies (a vendor-published usage claim based on open-source telemetry).
Smallstep co-developed ACME Device Attestation (ACME DA) with Google at the IETF, building on Apple’s Managed Device Attestation and Android/Chrome OS attestation mechanisms, to create a modern, hardware-rooted replacement for the aging SCEP certificate enrollment protocol — a concrete, independently traceable standards contribution (an IETF draft exists). The company has raised $26M total, including a $19M Series A in April 2022, and was selected as a Top 10 finalist in the RSAC 2025 Conference’s 20th Annual Innovation Sandbox contest, one of the industry’s more credible independent vetting processes for emerging security vendors.
Smallstep operates in the crowded identity/PKI/certificate-management space alongside established players (e.g., Venafi, Keyfactor, HashiCorp Vault), but its open-source footprint and co-authored standards work give it more independently verifiable substance than a typical early-stage entrant.
Innovation Matrix Assessment
Moved from open-source CA tooling to co-authoring a new IETF standard (ACME Device Attestation) with Google, building on Apple's device attestation work — a concrete, multi-year track record of turning ideas into shipped, standardized capability.
Automating certificate issuance/rotation and binding access to hardware-verified devices directly addresses phishing and credential-theft risk, a high-value, well-understood lever for CISOs pursuing Zero Trust.
RSAC 2025 Innovation Sandbox Top-10 selection is independently judged; $26M raised across seed and Series A is press-confirmed; broad open-source step-ca adoption (vendor-reported Fortune 100 usage) is a supporting, if self-reported, signal.
Device-identity/PKI automation is an established market with strong incumbents; Smallstep's standards leadership (ACME DA) is genuinely influential but incremental to the broader identity/Zero Trust category rather than creating an entirely new one.
The IETF standards contribution and open-source adoption are independently checkable facts, which supports a higher efficacy score than a typical vendor claim, though the specific 'Fortune 100' usage percentage is self-reported telemetry rather than third-party audited.
Hardware-rooted device identity and automated certificate lifecycle management are foundational to Zero Trust architectures and will remain relevant as organizations extend these models to AI agents and non-human identities.
Why CISOs Should Care
Lets security teams enforce that only verified, company-owned hardware can reach sensitive systems, with certificate issuance, rotation, and revocation automated end-to-end — reducing reliance on phishable passwords and manual PKI operations.
What Makes It Different
Co-authored the ACME Device Attestation standard with Google (building on Apple's Managed Device Attestation) rather than relying on proprietary or legacy protocols like SCEP, and backs it with a widely deployed open-source CA toolchain (step-ca).
The Matrix Verdict
70/100 — MEANINGFUL INNOVATOR
A more mature, independently validated player than most candidates in this tier — real standards influence, an independent RSAC finalist placement, and broad open-source reach — placing it at the low end of the Meaningful tier.
Editorial Note: Claims vs. Verified Findings
RSAC 2025 Innovation Sandbox finalist status and the $26M funding figures are corroborated by BusinessWire press releases. The IETF co-development with Google/Apple is corroborated by Smallstep's technical blog and the public IETF draft. The '78 of Fortune 100' open-source usage figure is a vendor-published claim based on Smallstep's own telemetry and has not been independently audited.
Sources
Alternatives to Smallstep
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.