A document defining all the operational practices that will be used to maintain the required level of public-key infrastructure (PKI) security. To prove that issued certificates are valid, an enterprise must demonstrate (usually through an audit) adherence to its CPS. The Internet Engineering Task Force’s (IETF’s) request for comment (RFC) 2527 contains draft guidelines for the format and content of a CPS.

