[ KL / COMPARE / CRYPTOMATHIC-CKMS ]
CKMS is enterprise key-lifecycle management starting at six-figure annual contracts. KeyLab is the free toolkit for the everyday cryptographic operations that surround it.
Cryptomathic CKMS is an enterprise-grade Crypto Key Management System used by central banks, large issuers, and acquirers to manage the full lifecycle of cryptographic keys across HSM estates. It handles key generation, ceremonies, distribution, rotation, archival, audit logging, role-based access, and integration with major HSM vendors (Thales, Utimaco, Atos). Pricing is enterprise-tier — typically starting at €150,000+/year and scaling with HSM count.
KeyLab is not a KMS. It is the engineer-facing tactical toolkit you use alongside any KMS — including CKMS. KeyLab does not manage your keys; it lets you calculate PIN Blocks, derive DUKPT keys, wrap TR-31 blocks, simulate payShield commands, parse EMV TLV, and verify cryptographic operations during development, certification, and incident response. Free, browser-based, no install.
The two products solve different problems. If you are running a payment processor with thousands of keys under PCI PIN Security, you almost certainly need a KMS like CKMS (or competitor like Thales CipherTrust, Utimaco ESKM, Futurex VirtuCrypt). You will ALSO need a toolkit like KeyLab for your engineers to do the daily ad-hoc cryptographic work that no KMS exposes a UI for.
| Feature | KeyLab | Cryptomathic CKMS |
|---|---|---|
| Category | Engineer toolkit | Enterprise KMS |
| Price | Free | Six-figure annual contracts |
| Key lifecycle management | No | Yes (full) |
| HSM-vendor integration | No (simulator only) | Yes (Thales, Utimaco, Atos, etc.) |
| Tactical cryptographic operations | Yes | Limited (UI is admin-focused) |
| Browser-accessible | Yes | No (admin console only) |
| Setup time | 0 minutes | Weeks (HSM integration, audit setup) |
| Suitable for incident response | Yes (fast tactical answers) | Yes (but heavy) |
| Suitable for developer workflow | Yes | No (operations-only) |
| Audit logging | Basic (Enterprise plan) | Full PCI/SOX compliance |