Skip to content

Smallstep

Hardware-backed device identity and automated certificate lifecycle management, using the ACME Device Attestation standard, for Zero Trust access.

Visit Website ↗ + Add to Compare Claim This Company
70/100Meaningful Innovator

Overview

Smallstep, founded in 2016 and headquartered in California, builds a device-identity and certificate lifecycle management platform for Zero Trust access. Its core technology issues and automates hardware-backed certificates so that only verified, company-owned devices — not just valid user credentials — can reach sensitive resources such as Wi-Fi/VPN, internal web apps, cloud APIs, and Git repositories. Smallstep also maintains step-ca, a widely used open-source certificate authority toolchain, which the company states is used in some form by a large share of Fortune 100 companies (a vendor-published usage claim based on open-source telemetry).

Smallstep co-developed ACME Device Attestation (ACME DA) with Google at the IETF, building on Apple’s Managed Device Attestation and Android/Chrome OS attestation mechanisms, to create a modern, hardware-rooted replacement for the aging SCEP certificate enrollment protocol — a concrete, independently traceable standards contribution (an IETF draft exists). The company has raised $26M total, including a $19M Series A in April 2022, and was selected as a Top 10 finalist in the RSAC 2025 Conference’s 20th Annual Innovation Sandbox contest, one of the industry’s more credible independent vetting processes for emerging security vendors.

Smallstep operates in the crowded identity/PKI/certificate-management space alongside established players (e.g., Venafi, Keyfactor, HashiCorp Vault), but its open-source footprint and co-authored standards work give it more independently verifiable substance than a typical early-stage entrant.

Innovation Matrix Assessment

Innovation Velocity 7/10

Moved from open-source CA tooling to co-authoring a new IETF standard (ACME Device Attestation) with Google, building on Apple's device attestation work — a concrete, multi-year track record of turning ideas into shipped, standardized capability.

Operational Value 8/10

Automating certificate issuance/rotation and binding access to hardware-verified devices directly addresses phishing and credential-theft risk, a high-value, well-understood lever for CISOs pursuing Zero Trust.

Market Momentum 7/10

RSAC 2025 Innovation Sandbox Top-10 selection is independently judged; $26M raised across seed and Series A is press-confirmed; broad open-source step-ca adoption (vendor-reported Fortune 100 usage) is a supporting, if self-reported, signal.

Category Disruption 6/10

Device-identity/PKI automation is an established market with strong incumbents; Smallstep's standards leadership (ACME DA) is genuinely influential but incremental to the broader identity/Zero Trust category rather than creating an entirely new one.

Real-World Efficacy 6/10

The IETF standards contribution and open-source adoption are independently checkable facts, which supports a higher efficacy score than a typical vendor claim, though the specific 'Fortune 100' usage percentage is self-reported telemetry rather than third-party audited.

Enduring Relevance 8/10

Hardware-rooted device identity and automated certificate lifecycle management are foundational to Zero Trust architectures and will remain relevant as organizations extend these models to AI agents and non-human identities.

Why CISOs Should Care

Lets security teams enforce that only verified, company-owned hardware can reach sensitive systems, with certificate issuance, rotation, and revocation automated end-to-end — reducing reliance on phishable passwords and manual PKI operations.

What Makes It Different

Co-authored the ACME Device Attestation standard with Google (building on Apple's Managed Device Attestation) rather than relying on proprietary or legacy protocols like SCEP, and backs it with a widely deployed open-source CA toolchain (step-ca).

The Matrix Verdict

70/100 — MEANINGFUL INNOVATOR

A more mature, independently validated player than most candidates in this tier — real standards influence, an independent RSAC finalist placement, and broad open-source reach — placing it at the low end of the Meaningful tier.

Editorial Note: Claims vs. Verified Findings

RSAC 2025 Innovation Sandbox finalist status and the $26M funding figures are corroborated by BusinessWire press releases. The IETF co-development with Google/Apple is corroborated by Smallstep's technical blog and the public IETF draft. The '78 of Fortune 100' open-source usage figure is a vendor-published claim based on Smallstep's own telemetry and has not been independently audited.

Sources