TigerTrust vs Smallstep

When you outgrow developer-first mTLS.

Smallstep is one of the best developer-first tools in the PKI space — step-ca and Smallstep Certificate Manager are genuinely elegant for internal mTLS. TigerTrust is not a replacement for that developer ergonomics story; it adds the enterprise CLM scope Smallstep is not aimed at: discovery across the estate, compliance evidence, IoT/TPM attestation, and multi-CA orchestration.

Why teams add TigerTrust

Two different scopes. Both legitimate.

Smallstep excels at giving developers and SREs a first-class internal PKI. If that is your entire use case, use Smallstep. TigerTrust picks up the surface beyond it.

Estate-wide discovery
Network scanning, cloud discovery, and CT-log correlation surface certificates issued outside step-ca — including shadow OpenSSL certs from years ago.
Compliance evidence pack
Prebuilt SOC 2, PCI, and HIPAA reports with audit-ready evidence exports. Not something step-ca is designed to produce.
TPM 2.0 attestation for IoT
Full TPM quote / credential activation / certify / PCR gating for device fleets. A fundamentally different workload from developer mTLS.
Multi-CA orchestration
step-ca as one issuer alongside DigiCert, Sectigo, Entrust, Let's Encrypt, private CAs, ADCS, and Vault — under one policy plane.
Where the scopes differ

Smallstep for developers. TigerTrust for the estate.

Without Smallstep
  • Certificate visibility scoped mainly to what step-ca issues
  • No prebuilt compliance evidence pack for SOC 2 / PCI / HIPAA
  • No TPM-attested device enrollment for IoT or hardware fleets
  • Policy scoped per step-ca provisioner, not across issuers
  • Enterprise ticketing / reporting integrations are limited
With TigerTrust
  • Every certificate in the estate, regardless of issuer
  • Compliance evidence packs and audit-ready signed exports
  • TPM 2.0 attestation, PCR gating, and IoT enrollment at scale
  • Cross-issuer policy enforcement and weak-key posture reporting
  • Native ServiceNow, Slack, PagerDuty, and SIEM integrations

Capability comparison, honest about the overlap.

Smallstep is a genuinely excellent tool for what it does. This table is a scope map, not a critique.

CapabilityTigerTrustSmallstep step-ca
Developer-first mTLS with clean CLI
Smallstep's CLI polish is deservedly loved
ACME protocol
Short-lived certificate workflows
Kubernetes cert-manager integration
Certificate discovery across the estate
Cloud inventory (AWS, Azure, GCP)
Compliance evidence pack (SOC 2, PCI, HIPAA)
TPM 2.0 remote attestation
IoT / device enrollment at scale
Multi-CA orchestration (public + private)
step-ca is the primary issuer in the Smallstep model

Add TigerTrust around step-ca.

Nobody rips out step-ca to adopt TigerTrust. You keep it as an issuer and gain the estate-wide layer above it.

01

Connect step-ca as an issuer

Point TigerTrust at your step-ca instance. Provisioners, roles, and policies stay authoritative on the step-ca side.

02

Turn on discovery

Scan networks, clouds, and Kubernetes clusters. Every certificate — step-ca-issued or otherwise — enters one inventory.

03

Extend to other issuers

Add public CAs, private CAs, ADCS, and Vault as additional issuers. Policy routes each request to the appropriate CA.

04

Wire up compliance and IoT if needed

Enable the compliance evidence pack and, for hardware fleets, turn on TPM 2.0 attestation workflows.

Frequently asked questions

Is Smallstep bad?

Not at all. Smallstep's step-ca and Smallstep Certificate Manager are genuinely excellent tools for developer-first mTLS. If you are a small team that mostly needs internal service certificates and CLI ergonomics, Smallstep may be exactly right. TigerTrust targets the scope beyond that — discovery of everything you did not issue, compliance evidence, IoT/TPM identity, and orchestration across multiple CAs.

Can we use step-ca as an issuer under TigerTrust?

Yes. If you have invested in step-ca provisioners and internal workflows, TigerTrust can treat step-ca as one of your upstream CAs and layer discovery, alerting, and reporting on top — no rip-and-replace.

What are the main capability gaps?

The three most common ones we hear: (1) no discovery for certificates issued outside step-ca, (2) no prebuilt compliance evidence pack, (3) no TPM-attested device enrollment for IoT or Windows fleets. TigerTrust covers all three.

How does TigerTrust compare on developer ergonomics?

We deliberately do not compete with Smallstep on CLI polish — it is excellent. TigerTrust provides an API and CLI that will feel familiar to any team already using step, plus a dashboard, ticketing integrations, and reporting for the roles that do not live on a terminal.

What about IoT and TPM attestation specifically?

TigerTrust ships a TPM 2.0 attestation engine (quote, credential activation, certify, PCR gating). This is a fundamentally different workload from developer mTLS — see /solutions/tpm-iot-attestation for the deep dive.

Case study
High-growth SaaS · Developer platform

Kept step-ca for service mTLS, added the estate layer for everything else.

Our SREs love step. Compliance did not care how elegant the CLI was — they needed SOC 2 evidence, discovery, and SIEM feeds. Both teams got what they wanted.
Head of Security Engineering
2 wk
Time to unified inventory
280K
Certificates outside step-ca discovered
100%
SOC 2 controls automated
Integrations

The enterprise surface Smallstep does not ship.

Keep step-ca for developer mTLS. TigerTrust adds the SIEM, ticketing, HSM, and cross-cloud integrations enterprise teams need.

step-ca / Smallstep
CA
Splunk
SIEM
Microsoft Sentinel
SIEM
ServiceNow
ITSM
Jira Service Management
ITSM
AWS / Azure / GCP
Discovery
Thales Luna HSM
HSM
Entrust nShield HSM
HSM
Kubernetes cert-manager
DevOps

Keep step-ca. Add the estate layer.