Government · Industry · Academe

Building the chain of trust for a digital Philippines.

The Philippines PKI Council brings together government agencies, banks, enterprises, and certification providers to advance public key infrastructure as the backbone of secure digital transactions nationwide.

About the Council

A shared foundation for digital trust

As government services, banking, and commerce move online, the integrity of a digital signature or certificate becomes as important as the transaction it secures. The Council exists to keep that foundation strong.

Public Key Infrastructure is a universally adopted technology that uses asymmetric cryptography to establish the identity of a person, device, or server in a verifiable way. It is the layer that lets a digital signature carry legal weight, a government transaction be trusted end to end, and a private connection stay private.

The Council exists to promote awareness and adoption of PKI, encourage interoperability between the systems that issue and rely on digital certificates, and give the organizations working in this space — regulators, trust service providers, technology solution providers, and researchers — a shared platform to coordinate on standards and practice.

Standards & interoperability

Aligning certificate practices across issuers so that trust established in one sector transfers cleanly to another.

Policy advocacy

Working alongside regulators and standards bodies to shape workable, practical digital trust regulation.

Education & awareness

Bringing PKI fundamentals to boards and C-suites, not just technical teams, so trust decisions are made with full context.

Cross-sector collaboration

Convening the people who issue certificates with the people who depend on them, on neutral, recurring ground.

Knowledge

The technology behind the trust

A working reference for the three concepts every member organization needs to be fluent in: how digital trust is established today, how it must change for the quantum era, and how to keep track of it all.

01

Public Key Infrastructure (PKI)

PKI is the system of certificate authorities, registration authorities, and cryptographic key pairs that lets two parties who have never met trust each other online. A Certificate Authority (CA) verifies an applicant's identity and issues a digital certificate binding their identity to a public key. That certificate is what makes a digital signature legally attributable, a website connection genuinely private, and a government e-service verifiable end to end.

As government services, banking, and commerce move online, PKI stops being a back-office IT detail and becomes critical national infrastructure. A correctly issued, correctly validated certificate is what makes a digital transaction trustworthy at national scale.

02

Post-Quantum Cryptography (PQC)

Today's PKI relies on RSA and elliptic-curve algorithms whose security depends on math problems that are hard for classical computers but solvable by a sufficiently capable quantum computer. PQC is the new generation of algorithms — standardized by NIST as ML-KEM, ML-DSA, and SLH-DSA — designed to resist both classical and quantum attacks.

The urgency isn't theoretical. Encrypted data intercepted today can be stored and decrypted later once quantum computing matures, a risk known as "harvest now, decrypt later." Any organization issuing long-lived certificates or signing long-lived documents needs a migration plan now, not after a quantum computer exists.

03

Cryptography Bill of Materials (CBOM)

A CBOM is a structured inventory of every cryptographic asset in an organization's systems — algorithms, key lengths, certificates, libraries, and where each is used. It does for cryptography what a Software Bill of Materials (SBOM) does for code dependencies: it makes an invisible layer visible and auditable.

A CBOM is the practical starting point for PQC migration. An organization cannot replace what it cannot see, and most enterprises underestimate how much legacy, hard-coded, and third-party cryptography is embedded in their systems until they build one.

Members

Membership

Registration process will begin soon

The Council's membership registration is being finalized. Organizations that issue, regulate, or rely on digital certificates — government agencies, banks, enterprises, certification authorities, and academic institutions — will be able to register their interest here shortly.

Events

Events

Coming soon

The Council's founding assembly and its calendar of briefings and member plenaries will be announced here once dates are confirmed.

News

News

Coming soon

Announcements, policy notes, and updates from the Council will be published here as they happen.