Smallstep is one of the best developer-first tools in the PKI space — step-ca and Smallstep Certificate Manager are genuinely elegant for internal mTLS. TigerTrust is not a replacement for that developer ergonomics story; it adds the enterprise CLM scope Smallstep is not aimed at: discovery across the estate, compliance evidence, IoT/TPM attestation, and multi-CA orchestration.
Smallstep excels at giving developers and SREs a first-class internal PKI. If that is your entire use case, use Smallstep. TigerTrust picks up the surface beyond it.
Smallstep is a genuinely excellent tool for what it does. This table is a scope map, not a critique.
| Capability | TigerTrust | Smallstep step-ca |
|---|---|---|
Developer-first mTLS with clean CLI Smallstep's CLI polish is deservedly loved | ||
ACME protocol | ||
Short-lived certificate workflows | ||
Kubernetes cert-manager integration | ||
Certificate discovery across the estate | ||
Cloud inventory (AWS, Azure, GCP) | ||
Compliance evidence pack (SOC 2, PCI, HIPAA) | ||
TPM 2.0 remote attestation | ||
IoT / device enrollment at scale | ||
Multi-CA orchestration (public + private) step-ca is the primary issuer in the Smallstep model |
Nobody rips out step-ca to adopt TigerTrust. You keep it as an issuer and gain the estate-wide layer above it.
Point TigerTrust at your step-ca instance. Provisioners, roles, and policies stay authoritative on the step-ca side.
Scan networks, clouds, and Kubernetes clusters. Every certificate — step-ca-issued or otherwise — enters one inventory.
Add public CAs, private CAs, ADCS, and Vault as additional issuers. Policy routes each request to the appropriate CA.
Enable the compliance evidence pack and, for hardware fleets, turn on TPM 2.0 attestation workflows.
Not at all. Smallstep's step-ca and Smallstep Certificate Manager are genuinely excellent tools for developer-first mTLS. If you are a small team that mostly needs internal service certificates and CLI ergonomics, Smallstep may be exactly right. TigerTrust targets the scope beyond that — discovery of everything you did not issue, compliance evidence, IoT/TPM identity, and orchestration across multiple CAs.
Yes. If you have invested in step-ca provisioners and internal workflows, TigerTrust can treat step-ca as one of your upstream CAs and layer discovery, alerting, and reporting on top — no rip-and-replace.
The three most common ones we hear: (1) no discovery for certificates issued outside step-ca, (2) no prebuilt compliance evidence pack, (3) no TPM-attested device enrollment for IoT or Windows fleets. TigerTrust covers all three.
We deliberately do not compete with Smallstep on CLI polish — it is excellent. TigerTrust provides an API and CLI that will feel familiar to any team already using step, plus a dashboard, ticketing integrations, and reporting for the roles that do not live on a terminal.
TigerTrust ships a TPM 2.0 attestation engine (quote, credential activation, certify, PCR gating). This is a fundamentally different workload from developer mTLS — see /solutions/tpm-iot-attestation for the deep dive.
“Our SREs love step. Compliance did not care how elegant the CLI was — they needed SOC 2 evidence, discovery, and SIEM feeds. Both teams got what they wanted.”
Keep step-ca for developer mTLS. TigerTrust adds the SIEM, ticketing, HSM, and cross-cloud integrations enterprise teams need.
The other developer-first PKI tool teams pair with an enterprise CLM layer above.
The cloud-native private CA teams evaluate alongside step-ca for workload issuance.
The Kubernetes-focused CLM that pairs cleanly with step-ca provisioners and cert-manager.
The device-identity path that goes well beyond developer mTLS — TPM 2.0 attestation at scale.