- TL;DR: Key Takeaways
- The Scoring Model
- Architecture & Tier 0 Separation (15%)
- CA Exposure (15%)
- Certificate Templates (15%)
- Revocation & Publication Health (10%)
- Audit & Logging (10%)
- Backup & Disaster Recovery (10%)
- HSM & Key Management (10%)
- Patching & Vulnerability Management (10%)
- Incident Readiness (5%)
- Calculating and Interpreting Your Score
- How Encryption Consulting Can Help
- Conclusion
- FAQ
“Is our PKI secure” usually gets answered with a list of findings, some critical, some minor, with no way to compare this quarter against last quarter or one CA hierarchy against another. A weighted scorecard fixes that: a single, defensible number built from nine categories, each weighted by how directly it contributes to real AD CS risk, that you can track over time and actually report to leadership.
This scorecard summarizes findings that come from the detailed guidance across our broader series, particularly ADCS ESC1-ESC16 Detection Playbook and Tier 0 Microsoft ADCS Architecture and Hardening, it doesn’t replace the detection work those guides describe.
TL;DR: Key Takeaways
- Nine categories, weighted by actual risk impact, sum to a single 0-100 score, CA exposure and certificate templates carry the most weight since they cover the majority of documented certificate-based privilege escalation paths.
- A scorecard summarizes findings, it doesn’t replace the detection work that produces them, use it to track trends and prioritize, not as a substitute for a full technical assessment.
- Recalculate on a recurring schedule, template configuration, CA permissions, and patch level all change, a stale score is a misleading one.
- The fastest wins usually sit in the two highest-weighted categories, a single dangerous CA-wide flag or one over-permissioned template can move the total score meaningfully with a comparatively small fix.
The Scoring Model
| Category | Weight | Primary Reference |
|---|---|---|
| Architecture & Tier 0 Separation | 15% | Tier 0 hardening guide |
| CA Exposure | 15% | ESC detection playbook, attack path guide |
| Certificate Templates | 15% | ESC detection playbook, SAN extension guide |
| Revocation & Publication Health | 10% | Topology monitoring, CRL partitioning, Azure HA guides |
| Audit & Logging | 10% | Audit logging deep dive, event ID reference |
| Backup & Disaster Recovery | 10% | Backup and DR guides |
| HSM & Key Management | 10% | Offline root renewal, Tier 0 hardening |
| Patching & Vulnerability Management | 10% | CVE-2024-49019 and Certighost guides |
| Incident Readiness | 5% | CertiGhost investigation guide, threat hunting playbook |
Score each category from 0 to 100% maturity, multiply by its weight, and sum all nine for a total 0-100 score.
Architecture & Tier 0 Separation (15%)
- Score toward 100% when: dedicated Tier 0 administrative accounts exist with no mailbox or browser access, CA administration happens only from a Privileged Access Workstation, no service accounts are shared across tiers, and jump hosts reaching Tier 0 are themselves treated as Tier 0.
- Score toward 0% when: CA servers are administered from general-purpose admin workstations, service accounts are reused across systems of different sensitivity, and there’s no formal tier separation model in place at all.
CA Exposure (15%)
- Score toward 100% when: no dangerous CA-wide policy flags are enabled, Manage CA and Manage Certificates rights are held only by a documented, minimal set of accounts, and a recent ESC5/ESC7/ESC12/ESC16 review returned clean.
- Score toward 0% when: flags like
EDITF_ATTRIBUTESUBJECTALTNAME2are enabled, or CA-level administrative rights are broadly granted without a recent review.
Certificate Templates (15%)
- Score toward 100% when: a recent ESC1-ESC4, ESC13, and ESC15 review returned clean, enrollee-supplied-subject templates are tightly scoped with manager approval, and no schema version 1 templates remain on unpatched CAs.
- Score toward 0% when: multiple ESC1-pattern templates exist, or template reviews haven’t been performed at all.
Revocation & Publication Health (10%)
- Score toward 100% when: CRL and OCSP publication is actively monitored with synthetic retrieval checks, publication points use abstracted hostnames, and a genuinely tested failover or high-availability architecture is in place.
- Score toward 0% when: publication relies on a single on-premises server with no monitoring and no tested redundancy.
Audit & Logging (10%)
- Score toward 100% when: the CA’s AuditFilter is set to capture every category, the OS-level audit prerequisite is confirmed enabled, events forward reliably to centralized storage, and Event ID 4885 is actively monitored.
- Score toward 0% when: auditing is at default or minimal settings with no centralized collection.
Backup & Disaster Recovery (10%)
- Score toward 100% when: backups cover the database, private key, registry configuration, CAPolicy.inf, and templates together, and a full restore has been tested against a documented recovery time objective within the last year.
- Score toward 0% when: backups cover only the database and key via a basic
certutil -backup, with no restore ever tested.
HSM & Key Management (10%)
- Score toward 100% when: root and issuing CA keys are HSM-backed, key generation and renewal follow documented ceremony procedures with dual control, and NDES RA keys receive equivalent protection.
- Score toward 0% when: keys are software-protected with no formal ceremony process for generation, backup, or renewal.
Patching & Vulnerability Management (10%)
- Score toward 100% when: every CA is current against known AD CS vulnerabilities, including CVE-2024-49019 and Certighost, and a recurring ESC detection scan is part of standing practice.
- Score toward 0% when: patch levels haven’t been verified against specific known CVEs and no recurring scanning exists.
Incident Readiness (5%)
- Score toward 100% when: a documented, AD CS-specific incident response playbook exists, covering exactly the kind of investigation steps in our CertiGhost guidance, and has been tested or tabletop-exercised.
- Score toward 0% when: no AD CS-specific incident plan exists beyond generic organizational incident response.
Calculating and Interpreting Your Score
- Multiply each category’s maturity percentage by its weight, then sum all nine, for example, a 60% score in a 15%-weighted category contributes 9 points to the total, do this across all nine categories to reach your final score out of 100.
- 90 and above reflects a strong, well-maintained posture, worth maintaining through the continuous practices covered throughout our broader series rather than treating as a finished state.
- 75 to 89 reflects adequate posture with specific, targeted gaps, identify exactly which categories are dragging the score down and address those deliberately.
- Below 75, and especially below 55, warrants prioritized remediation, particularly if the gap sits in CA exposure or templates, given their combined 30% weight and direct tie to privilege escalation risk.
- Recalculate on a recurring schedule and track the trend, not just the current number, a declining score between two calculations is often a more actionable signal than the absolute value at any single point in time.
How Encryption Consulting Can Help
Calculating this scorecard honestly requires the same detailed technical assessment work covered throughout our broader series, template and CA reviews, audit configuration checks, backup and HSM verification, and incident readiness testing, brought together into one comparable, trackable number.
Encryption Consulting’s PKI Services team supports this directly:
- Full scorecard assessment: running the underlying technical reviews across all nine categories and calculating your actual score, not a self-reported estimate.
- Prioritized remediation planning: sequencing fixes by scoring impact, starting with the highest-weighted categories where a small fix moves the total score the most.
- Ongoing scorecard tracking: recalculating on a recurring schedule so trend data actually accumulates into something meaningful.
- Executive reporting, translating the scorecard into the kind of leadership-level summary covered in our compliance monitoring guidance.
- Category-specific remediation, drawing on every deep-dive guide in our broader AD CS series to actually close the gaps the scorecard identifies.
If you want your AD CS environment scored honestly and tracked over time, our PKI Services team can run this assessment and help you improve the result.
Conclusion
A single, weighted number won’t tell you everything about your PKI’s security posture, but it will tell you whether this quarter is better or worse than last quarter, and which of nine categories deserves attention first. Weight CA exposure and certificate templates heaviest, since they cover the bulk of real-world privilege escalation risk, score honestly rather than optimistically, and recalculate often enough that the trend actually means something.
Related reading: ADCS ESC1-ESC16 Detection Playbook · Tier 0 Microsoft ADCS Architecture and Hardening · ADCS Continuous Compliance Monitoring · Continuous ADCS Risk Assessment vs One-Time Audits · CertiGhost: How to Determine Whether Your Enterprise CA Was Exploited · ADCS Threat Hunting Playbook
Want your AD CS environment scored honestly and tracked over time? Talk to our PKI Services team about running a full scorecard assessment. Encryption Consulting is ISO/IEC 27001:2022 and SOC 2 certified.
FAQ
Why are certificate templates and CA exposure weighted higher than other categories? Because they’re the two categories most directly tied to certificate-based privilege escalation, covering the majority of documented ESC1-ESC16 attack paths. A weak score here represents a more direct route to domain compromise than a weak score in a lower-weighted category like incident readiness.
What score should an organization consider acceptable? A total score of 90 or above generally reflects a strong, well-maintained posture. Scores between 75 and 89 indicate adequate posture with specific, targeted gaps worth addressing. Anything below 75, and especially below 55, warrants prioritized remediation, particularly if the gap sits in a heavily weighted category like CA exposure or templates.
How often should an AD CS security scorecard be recalculated? On a recurring schedule, at minimum quarterly, since several inputs, template configuration, CA permissions, and patch level, can change between calculations. Tracking the score’s trend over time is often more valuable than any single snapshot.
Can a scorecard replace a full AD CS security audit? No. A scorecard is a structured way to quantify and communicate posture, useful for tracking trends and prioritizing effort, but it summarizes findings rather than replacing the detailed detection work, such as a full ESC1-ESC16 assessment, that actually produces those findings.
What’s the fastest way to improve a low AD CS security score? Focus first on the two highest-weighted categories, CA exposure and certificate templates, since they combine the largest scoring impact with some of the fastest fixes available, such as disabling a dangerous CA-wide policy flag or tightening a single over-permissioned template.
- TL;DR: Key Takeaways
- The Scoring Model
- Architecture & Tier 0 Separation (15%)
- CA Exposure (15%)
- Certificate Templates (15%)
- Revocation & Publication Health (10%)
- Audit & Logging (10%)
- Backup & Disaster Recovery (10%)
- HSM & Key Management (10%)
- Patching & Vulnerability Management (10%)
- Incident Readiness (5%)
- Calculating and Interpreting Your Score
- How Encryption Consulting Can Help
- Conclusion
- FAQ
