Keyfactor has expanded its
Global Partner Program to help channel partners build services around machine identity management and post-quantum security. The updated program, aimed at MSPs, MSSPs, systems integrators, and solution providers, includes training, certifications, lab resources, and support for services such as cryptographic discovery, PKI modernization, crypto-agility, and post-quantum readiness.
The company is also encouraging partners to create post-quantum cryptography centers of excellence. These practices could support customer assessments, migration planning, implementation, and ongoing governance.
For service providers, the larger opportunity comes after the first assessment.
Louise McEvoy, senior vice president of global channel sales at Keyfactor, told ChannelE2E, “The strongest MSP/MSSP opportunity is not a one-time quantum assessment. It’s the opportunity to become the customer’s long-term digital trust operator, continuously managing machine identities and cryptography as technology, risk, and standards evolve."
AI creates more machine identities
AI is adding more applications, agents, workloads, certificates, keys, and service accounts to enterprise environments. Each one needs an identity and a secure way to connect with other systems. That creates more work for security and IT teams. Many organizations already struggle to find certificates, track expiration dates, enforce policies, and understand which systems depend on specific keys or algorithms.
McEvoy said the clearest opportunity for service providers sits across machine identity management, cryptographic risk, and crypto-agility.
“Discovery is the starting point,” she said. “Customers need an accurate, continuously updated view of their certificates, keys, algorithms, and cryptographic dependencies across cloud and on-premises infrastructure, applications, devices, and AI workloads.”
Once partners have that inventory, they can help customers prioritize risk, automate certificate renewals, modernize PKI, and enforce security policies.
MSPs can manage much of the day-to-day work. MSSPs can add continuous risk monitoring, compliance, and governance. Many service providers already manage customer cloud environments, identity systems, security platforms, and IT operations. That gives them a strong starting point for machine identity and cryptographic services.
“As we expand our partner ecosystem, MSPs and MSSPs are an increasingly important part of how we see this market scaling,” McEvoy said. “We see a strong opportunity to work with service-led partners to shape repeatable services and joint go-to-market motions, combining their operational reach and trusted customer relationships with Keyfactor’s machine identity and cryptographic capabilities.”
Post-quantum planning moves to partners
Organizations are also starting to prepare for the risk that quantum computing could weaken widely used encryption methods. And the first step is understanding where cryptography is used. Customers then need to identify the most important systems and plan how to replace older algorithms without disrupting operations. That work can span cloud services, applications, devices, and third-party platforms.
Keyfactor’s updated program includes skills-based badges and certifications based on partner roles and services. It also includes a post-quantum cryptography lab that partners can use for training and testing. The idea is to help partners build repeatable services instead of treating every post-quantum project as a separate engagement.
“The announcement strengthens the foundation for that progression, from assessment through migration, implementation, ongoing operations, and cryptographic governance, delivered through a broader cloud and technology ecosystem,” McEvoy said.
MSPs can start with a focused practice
Most MSPs do not have deep cryptography expertise in-house. McEvoy said they do not need to build a large research team before entering the market.
They do need people who understand PKI, machine identities, service design, automation, and integration. They also need to explain technical problems in terms that customers can understand, including business risk and next steps.
“MSPs do not need to build a cryptography research organization before they can enter this market,” McEvoy said. “They need a focused and credible core practice, including service architecture, PKI and machine identity expertise, automation and integration skills, and the ability to translate technical findings into business risk and a practical modernization roadmap.”
Partners will also need hands-on training, certifications, lab environments, and clear playbooks for assessments, remediation, migration, and ongoing management. They must be able to support several customers securely. That includes access controls, separation of duties, change management, service-level agreements, escalation processes, and reporting.
McEvoy recommends starting with one or two clearly defined services. Partners can then expand into broader PKI modernization and post-quantum migration work.
“That’s why our expanded program emphasizes role-based skills, certification, hands-on lab environments, and service-delivery competencies,” she said. “Those capabilities create the foundation for deeper collaboration with service-led partners and for taking repeatable customer offerings to market together.”
Turning discovery into recurring services
An initial assessment gives customers a list of certificates, keys, algorithms, and dependencies. The ongoing opportunity comes from keeping that information current and acting on it.
“The key is to treat discovery as the beginning of an operating cycle, not the end of a project: discover, prioritize, remediate, automate, and govern,” McEvoy said.
After the assessment, providers can monitor the customer’s cryptographic environment, renew certificates, rotate keys, manage policy exceptions, and track post-quantum migration work.
They can also connect these processes to the customer’s IT service management, DevOps, cloud and security tools. Providers can sell the ongoing work as a managed service, with separate projects for major remediation or migration work.
McEvoy said partners should measure results such as inventory coverage, automation rates, remediation time, policy compliance, and reductions in unmanaged assets.
“That creates visible customer value and a sustainable recurring-revenue model for the provider,” she said.
Cloud marketplaces support the sales model
Keyfactor is also expanding its work with AWS, Microsoft Azure, Google Cloud, and other cloud providers. The program is designed to help partners sell through cloud marketplaces, use hyperscaler funding programs, and work with Keyfactor on joint sales opportunities.
It also includes incentives, opportunity protection, account planning, co-marketing, and joint pursuit support.
For partners, cloud marketplaces can make purchasing easier and help attach digital trust services to larger cloud and security projects.
McEvoy said service providers will still need support from technology vendors, cloud providers, and specialist consultants.
“This will be an ecosystem play,” she said. “The strongest providers will integrate with the customer’s cloud, identity, DevOps, IT operations, and security platforms, and bring in specialist expertise where needed.”
A wider role for MSPs and MSSPs
The program is available to partners serving financial services, telecommunications, automotive, government, health care, industrial, and consumer IoT, software, and other regulated sectors.
The main service opportunity sits in the work surrounding the technology. Customers need help finding cryptographic assets, planning migrations, setting policies, meeting compliance requirements and managing systems over time.
“We see a strong opportunity to go to market together around repeatable, outcome-based services that combine their operational scale and customer proximity with Keyfactor’s platform and domain expertise,” McEvoy said. “The goal is one coherent customer outcome, not a collection of disconnected tools and projects.”