Critical Components of Device Identity Platform | Smallstep

ICCE: The foundation of device identity

You can’t enforce Zero Trust without proving device identity. Smallstep uses certificates to authenticate every connection, including services, workloads, AI agents, and MCP-based tools.

Secure Wi-Fi with hardware-backed EAP-TLS

Device-bound credentials for Okta Workforce Identity

ZTNA without passwords or agents

Hardware-backed SSH for engineers

SaaS access gated by verified device identity

mTLS for internal services and workloads

Critical components of device identity

Combined inventory

Without a comprehensive and trusted device inventory, you can't confidently rely on device identity for secure authentication. Smallstep Inventory is purpose-built for cybersecurity—it complements, but doesn't replace, your existing IT asset management (ITAM) tools.

Managed credentials

Once you have confidence in your trusted device inventory, Smallstep securely issues credentials to your trusted endpoints. Smallstep supports high-assurance enrollment via ACME Device Attestation on all major platforms (Windows, Mac, Linux), leveraging hardware-backed, non-exportable credentials.

Resource configuration

Configuration management across platforms can be challenging. After issuing credentials, Smallstep automatically configures your endpoints to authenticate securely to resources such as Wi-Fi, VPN, and SaaS apps. Our cross-platform agent seamlessly handles credential and configuration management for all of your endpoints - with or without your existing MDM solutions.

Policy enforcement

Effective security requires verifying device identity at the moment resources are accessed. Authentication can occur directly at the resource level (such as an application or server verifying credentials) or via a centralized enforcement point (such as a proxy or gateway) that controls and authorizes access. Smallstep flexibly supports both enforcement approaches, ensuring your security policies are consistently applied across your infrastructure.

Trusted at Enterprise Scale

Used by global banks, healthcare networks, fintechs, and public-sector organizations. Built on step and step-ca, trusted by 3,000+ organizations, including finance and defense. Powers Wi-Fi, ZTNA, SSH, and internal access modernization at scale. Learn how high-assurance device identity completes your Zero Trust architecture — without friction.

FAQs critical components

What are the “critical components” in Smallstep’s device and workload identity architecture?

How does Smallstep ensure cryptographic trust across distributed components?

How do Critical Components map to the four steps of establishing device identity?

What is the role of the Smallstep Attestation CA, and how is it different from other CAs?

How does Smallstep ensure revoked devices cannot obtain new credentials?

How do CAs and agents communicate securely with attestation services?

Can these components be deployed in distributed or hybrid architectures?

How does Smallstep validate manufacturer attestation chains at scale?

How does Smallstep integrate with external identity systems (MDM, IdP, IAM, SIEM)?

How are the critical components hardened against CA compromise or misuse?

How do critical components support workload identity (not just devices)?

How do all critical components together enforce a Zero Trust model?