Certificate Management Protocol Comparison
OSCP / CMC / CMP / SCEP / EST / ACME

This table provides an overview and comparison of different certificate management protocols

 OCSPCMCCMPSCEPESTACME
Full NameOnline Certificate Status ProtocolCertificate Management over CMSCertificate Management ProtocolSimple Certificate Enrollment ProtocolEnrollment over Secure TransportAutomated Certificate Management Environment
Main RFCRFC 6960RFC 5272RFC 9810RFC 8894RFC 7030RFC 8555
RFC Date201320082025202020132019
RFC StatusStandards TrackStandards TrackStandards TrackInformational Standards TrackStandards Track
Server-Side Key Generation
Certificate Enrollment
Certificate Renewal
Certificate Validation
Certificate Revocation
Certificate TypeRSA, ECDSARSA, ECDSARSA, ECDSARSA only RSA, ECDSARSA, ECDSA
Transport ProtocolHTTPHTTP(s), TCPHTTP(s), TCPHTTPHTTPsHTTPs
Authentication MethodsN/ATLS-basedDigital Signatures,
Shared Secrets
Shared Secrets only TLS-based,
HTTP Basic/Digest Authentication
Challenge-based
DeploymentSimpleComplex Complex SimpleMedium complexitySimple
Typical Use CaseFor certificate validation purpose onlyFor telecom and railway communication networksFor legacy applications
like network devices
(Routers, Firewalls...)
For IoT devices,
EST succeeds SCEP by addressing its security weaknesses
For certificate management for
public servers
Related ORYX ProductCycloneCRYPTO--CycloneSCEPCycloneESTCycloneACME

Feel free to contact us to help refine your use case.