#1 Global Leader in Digital Trust & Quantum-Safe Security.    Discover how Keyfactor makes it possible.

Schneider Electric Secures Device and Software Trust at Global Scale

Schneider Electric, a global energy technology leader, modernized its firmware, software, and device identity infrastructure by replacing purpose-built systems with a centralized PKI and signing platform. With Keyfactor, Schneider now secures millions of devices and signing events annually while reducing costs, improving compliance, and preparing for the future of digital trust.

10x
reduction in software signing costs
80%
decrease in key ceremony costs
1,000,000+
signing events supported annually

As Schneider Electric’s connected products and digital services expanded globally, the organization outgrew its existing firmware and software signing approach. Purpose-built tools supported early growth, but as scale and regulatory demands increased, siloed workflows, limited cross-team visibility, and rising operational overhead emerged. This created an opportunity for a more unified, scalable approach that could better support global growth and evolving compliance requirements.

By partnering with Keyfactor, Schneider unified certificate issuance, firmware signing, and software signing under a single, standards-based platform. Today, Schneider secures device identities at scale, supports high-volume and low-frequency signing workflows seamlessly, and maintains audit-ready compliance across global business units while significantly reducing operational costs and preparing for post-quantum cryptography.

The Challenge

Schneider Electric initially leveraged purpose-built systems for firmware and software signing that supported its early product lines. As product portfolios and signing volumes expanded, these separate systems became increasingly complex to manage, creating fragmented workflows, limited end-to-end visibility, and higher maintenance overhead. At the same time, evolving regulatory requirements highlighted the need for a more scalable approach to PKI and code signing to support continued global growth.


“Before we engaged with Keyfactor, we had a purpose-built solution for firmware and a SaaS solution for software. They really didn’t know each other, they weren’t scalable, and they were expensive to operate and maintain.

Fred Cohn Digital Risk Leader, IoT Practice, Schneider Electric
  • Automation

    Manual certificate generation and renewal processes increased risk and operational burden as signing volumes grew.

  • Siloed Systems

    Disparate tools limited visibility, preventing teams from sharing a consistent view of PKI and signing operations across the enterprise.

  • Scale

    Homegrown and SaaS solutions could not support expanding software builds, device lifecycles, and global compliance demands.

The Solution

Centralized, Scalable PKI and Signing

Schneider Electric selected Keyfactor EJBCA and SignServer to replace siloed firmware and software signing systems with a centralized, standards-based PKI and signing platform. With Keyfactor, Schneider now manages certificates and signing operations from a single trusted foundation while supporting diverse deployment models. Keyfactor also provides Schneider with a future-ready roadmap, enabling crypto-agility and preparation for post-quantum cryptography as standards evolve.

Keyfactor helped us deliver products at scale because the solution can handle the variance in signing activities – from legacy software to leading-edge IoT systems – all in one consistent way.

Fred Cohn Digital Risk Leader, IoT Practice, Schneider Electric

Business Impact

Since adopting Keyfactor, Schneider Electric has strengthened global security and compliance while realizing significant cost savings. Software signing costs were reduced and key ceremony costs dropped by 80%. Schneider also gained a scalable architecture capable of supporting millions of signing events annually without proportional cost increases. The company is now well-positioned to meet current and future regulatory requirements with confidence.


  • Dramatic cost reduction

    Schneider achieved a 10x reduction in software signing costs and an 80% decrease in key ceremony expenses.

  • Scalable operations

    Keyfactor supports both high-volume daily signing and infrequent firmware releases without added complexity or cost.

  • Compliance and future readiness

    Schneider maintains audit-ready compliance with standards like IEC 62443 and is prepared for emerging mandates such as the EU Cyber Resilience Act and post-quantum cryptography.

By transitioning from our old SaaS software signing solution to Keyfactor, we saw an order of magnitude drop in operating costs. On the firmware side, using EJBCA has cut our key ceremony costs to about one-fifth of what they were before.

Fred Cohn Digital Risk Leader, IoT Practice, Schneider Electric

Customer Details

Industry
Energy & Manufacturing
Location
France (Global Operations)
# Employees
140,000+
Website
Products & Services Used
EJBCA, SignServer