WKEY NASDAQ LAES NASDAQ · SEALSQ

Group companies

More companies

Structure

The group

Six companies, one Root of Trust

WISeKey International Holding is the parent; each company sells into its own market.

See the group structure

Financials

Calendar & disclosure

Contact & alerts

Listed

NASDAQ WKEY · SIX WIHN

SEALSQ Corp reports separately as a Nasdaq-listed subsidiary.

Investor relations

About

Governance

Resources

Careers

Build trust infrastructure

Engineering, cryptography and operations roles in Geneva and beyond.

See open roles

Swiss digital trust infrastructure · Since 1999

Trusted identity for people, objects and machines.

One Swiss anchor, and everything that chains back to it — a car proving its software is genuine, a passport that can be checked anywhere, an AI agent proving what it is allowed to do. Now being rebuilt on post-quantum cryptography.

WebTrust accredited ISO/IEC 27001 Post-quantum in silicon NASDAQ WKEY · SIX WIHN
What the Swiss Root of Trust secures — select an item to read more Vehicles Passports & ID Factories AI agents Documents Medical devices Satellites Swiss Root of Trust

Vehicles

Every control unit in a car can prove a software update is genuine before it installs it — and a replacement part can prove it is not a counterfeit.

Silicon by SEALSQ

Passports & ID

A national identity document or credential can be checked as authentic by anyone, anywhere, without having to call the issuer.

Certificates by WISeKey CertifyID

Factories

Machines on a production line authenticate to each other with certificates instead of shared passwords, so one leaked secret cannot open the floor.

Silicon by SEALSQ

AI agents

An autonomous agent acting on your behalf can prove which agent it is, what it is allowed to do, and who authorised it — with a tamper-evident record of every action.

Certificates by WISeKey CertifyID · platform by WISeID Keystone

Documents

A signed contract stays provable years later — after the signer has left, and after the software that produced it is gone.

Trust services by WISeKey CertifyID

Medical devices

A connected device and the data it produces carry an identity that clinical and regulatory review can trace end to end.

Certificates by WISeKey CertifyID

Satellites

Assets with no network — ships, pipelines, remote sensors — reach the same trust anchor from orbit.

Connectivity by WISeSat

WISeKey in numbers

1999
Founded in Switzerland
27 years of operation
6B+
Roots of Trust installed
1.75B+
Secure chips installed
3,000+
Corporate & government clients
6
Operating companies in the group

Activity: cybersecurity, semiconductors, space and quantum.

What WISeKey does

Three layers of trust, one anchor

Most vendors sell one layer. WISeKey issues the identity in the silicon, manages it across its lifetime, and carries it over a network it operates — every layer chained to the same Swiss Root of Trust.

01 / SILICON

Post-quantum, cast into the chip

The QS7001 Quantum Shield implements NIST’s post-quantum algorithms in hardware, not in software on top of it. Every device leaves the production line already holding a cryptographic identity — so it is trustworthy before it connects to anything, and stays trustworthy after quantum computers arrive.

  • QS7001 Quantum Shield — NIST post-quantum algorithms in hardware
  • Entropy source validated to NIST SP 800-90B; FIPS 140-3 and Common Criteria EAL5+ on the certification roadmap
  • Aligned to the ANSSI post-quantum mandate
  • VaultIC secure elements, secure microcontrollers and QVault TPM

Designed and sold by SEALSQ, the group’s Nasdaq-listed semiconductor company.

The SEALSQ QS7001 Quantum Shield secure element, shown from both faces: a 32-pin QFN package marked QS7001, and its gold die-attach pad.
QS7001 QUANTUM SHIELD · SEALSQ
Built by
SEALSQ
Flagship
QS7001 Quantum Shield
02 / IDENTITY

The PKI other platforms are built on

WISeKey operates the certificate authorities, and builds the software that runs them. Identity platforms across the group — and organisations with platforms of their own — issue from this infrastructure rather than standing up a CA themselves.

  • Root and issuing certificate authority operations
  • CertifyID PKI product suite, including TLS Manager and the Universal Registration Authority
  • Qualified trust services and digital signature under ETSI
  • Device identity lifecycle management, from provisioning to revocation
  • Quantum-safe certificate issuance from the OISTE/WISeKey Root of Trust

Platforms issuing from this infrastructure include WISeID, WISeID Keystone and SEALCOIN — alongside third parties running their own.

A hardware security module mounted in a rack inside a secure data centre.
HARDWARE SECURITY MODULE · KEY CUSTODY
Built by
WISeKey Trusted Services
Flagship
CertifyID PKI suite
03 / NETWORK

Trust that reaches off the grid

Nine satellites in sun-synchronous orbit and a machine-to-machine transaction layer carry trusted identity to assets with no terrestrial connectivity — ships, pipelines, remote infrastructure, sensors in the field.

  • WISeSat nano- and picosatellites for secure IoT-from-space
  • Low-power sensors for off-grid deployment
  • SEALCOIN autonomous machine-to-machine transactions

Operated by WISeSat, with machine-to-machine settlement by SEALCOIN.

9 SATELLITES
SUN-SYNCHRONOUS · 97.3–97.6°
405–598 KM

Built by
WISeSat
Flagship
Nine-satellite constellation

Solutions

Start from the problem

Two ways in: by the industry you operate in, or by the outcome you need. Either way the language is the problem first, the technology second.

Automotive

Secure the connected car

Give every ECU and component a verifiable identity, so software updates, telematics and supply-chain parts stay authenticated across a vehicle’s whole life.

Silicon by SEALSQ

Government

Issue sovereign identity

National identity, credentials and document signing anchored in a Swiss-neutral, independently audited trust model rather than a foreign commercial CA.

Certificates by WISeKey CertifyID

Industry 4.0

Authenticate the factory floor

Provision identity at manufacture and manage it across the fleet, so industrial devices authenticate to each other without shared secrets or static keys.

Silicon by SEALSQ

Financial services

Sign with legal weight

Strong authentication and qualified electronic signature for onboarding, transaction approval and contracts that must survive regulatory scrutiny.

Trust services by WISeKey CertifyID

Health

Secure the medical device

End-to-end identity for connected medical devices and the data they produce, with the audit trail clinical and regulatory review demands.

Certificates by WISeKey CertifyID

Not listed

Describe your asset

Tell us what needs to be trusted and we will map it to the right layer of the stack.

Platform owners

Use our PKI, keep your platform

If you already run your own identity system, you do not need another one — you need the certificate authority underneath it. CertifyID gives you a dedicated CA chained to the Swiss Root of Trust, without standing one up yourself.

Delivered by WISeKey CertifyID

Brand protection

Stop counterfeit product

Cryptographic authentication in the product itself — batteries, cartridges, consumables, packaging — so customers can verify origin and you can see diversion.

Silicon by SEALSQ

Device identity

Give every device an identity

Issue, rotate and revoke device credentials from manufacture to decommissioning, with a single lifecycle view across the estate.

Silicon by SEALSQ · certificates by CertifyID

Signature

Make a document hold up

Qualified electronic signature and long-term validation, so an agreement signed today is still provable years later.

Trust services by WISeKey CertifyID

Authentication

Replace passwords

Certificate-based and mobile strong authentication for workforce and customer access, without a shared secret to steal.

Platform by WISeID

Connectivity

Connect assets off-grid

Satellite uplink and low-power sensors for assets beyond terrestrial coverage, carrying the same trusted identity as everything else.

Operated by WISeSat

Migration

Get post-quantum ready

Inventory what you have, then move signing and key exchange onto quantum-resilient algorithms. SEALSQ’s Geneva Quantum Center of Excellence coordinates post-quantum deployment across aerospace, IoT and government.

Silicon by SEALSQ · certificates by CertifyID

Why it holds

Three reasons the anchor is worth anything

A Root of Trust is only as good as the guarantees around it. Ours rest on where it sits, who checks it, and how long it stays valid.

01

Neutral

The anchor sits under Swiss jurisdiction and is governed with the OISTE Foundation — structurally separate from any single government or commercial owner. For a government or a regulated enterprise, that is the difference between trusting an institution and trusting someone else’s jurisdiction.

Held in Switzerland · governed with the OISTE Foundation

02

Verified

Independent auditors examine the root every year against the same criteria the browser and certificate-authority industry uses. It is not a claim we make about ourselves — it is a report someone else signs, and browsers act on it.

Audited annually · WebTrust for CAs, Baseline Requirements, EV, S/MIME

03

Durable

Identities issued today have to outlive the arrival of cryptographically relevant quantum computers. Post-quantum algorithms are being built into both the silicon and the PKI, so a credential issued now does not become a liability later.

Post-quantum programme · NIST-standardised algorithms in silicon and PKI

The root certificate

The anchor · live chain of trust IN BROWSER TRUST STORES
Subject
CN = OISTE WISeKey Global Root GB CA
OU = OISTE Foundation Endorsed
O = WISeKey   C = CH
Issuer
Self-signed — nothing sits above it
Serial
76:b1:20:52:74:f0:85:87:46:b3:f8:23:1a:f6:c2:c0
Valid
1 Dec 2014 → 1 Dec 2039
Public key
RSA 2048-bit
Signature
sha256WithRSAEncryption
SHA-256
6B9C08E8 6EB0F767 CFAD65CD 98B62149 E5494A67 F5845E7B D1ED019F 27B86BD6
Audit
WebTrust — CAs, Baseline Requirements, EV, S/MIME
Post-quantum migration industry transition
2024
FIPS 203 / 204 / 205 published
2025–26
Inventory & hybrid deployment
2030
CNSA 2.0 signing milestone
2033
Broad transition target

Published in the PKI repository

How the chain works

Every certificate WISeKey issues chains back to a self-signed root held offline under ceremony control. Beneath it sit eleven subordinate certificate authorities, each scoped to one purpose — TLS, secure email, document signing, device identity — so a compromise in one is contained and does not reach the anchor.

The root shown in the hero is OISTE WISeKey Global Root GB CA. Its SHA-256 fingerprint is published, and you can check it against any browser trust store or a certificate transparency log without asking us.

SHA-256
6B9C08E8 6EB0F767 CFAD65CD 98B62149
E5494A67 F5845E7B D1ED019F 27B86BD6
Subordinates
11 issuing CAs, scoped by purpose

The post-quantum timeline

Standards are published and public-sector transition horizons are set. These are industry-wide milestones, not WISeKey-specific commitments.

2024

NIST publishes FIPS 203, 204 and 205

ML-KEM · ML-DSA · SLH-DSA

2025–26

Inventory and hybrid deployment across industry

crypto-agility, dual-stack certificates

2030

CNSA 2.0 milestone for software and firmware signing

public sector transition horizon

2033

Broad transition target


Accreditations and certifications

WebTrust for Certification Authorities
Annual audit of CA operations. AICPA / CPA Canada criteria.
WebTrust for Baseline Requirements
Controls assessed against the CA/Browser Forum Baseline Requirements.
WebTrust for Extended Validation
Controls assessed against the CA/B Forum EV guidelines.
WebTrust for S/MIME
Secure email certificate issuance controls.
WebTrust for Network Security
Network and certificate system security requirements.
ISO/IEC 27001
Information security management. Scope pending confirmation.
ISO 9001 — Bureau Veritas
Quality management. Scope pending confirmation.
Qualified CSP under ETSI
Qualified certification service provider status.

Certifying bodies: AICPA, CPA Canada, Bureau Veritas.

PKI documentation repository

The group

One holding company, six operating brands

WISeKey International Holding is the parent. Select any company for detail, or go straight to its own site.

WISeKey International Holding

PARENT · GENEVA, SWITZERLAND · FOUNDED 1999

NASDAQ WKEYSIX WIHN

Investors

Listed in the United States and Switzerland

Reporting, filings and the corporate calendar are one click from here. SEALSQ Corp reports separately as a Nasdaq-listed subsidiary.

WKEY
WISeKey International Holding
Nasdaq Stock Market
Investor relations
WIHN
WISeKey International Holding
SIX Swiss Exchange
Investor relations
LAES
SEALSQ Corp
Nasdaq Stock Market · separately listed subsidiary
SEALSQ investors (opens in a new tab)

Filings & disclosure

ReportsAnnual and interim financial reportsOpen
SECEDGAR filings · CIK 0001738699Open
SECSection 16 insider filingsOpen
CalendarCorporate calendar & general meetingsOpen
AlertsInvestor mailing listSubscribe

Partners & clients

Working alongside

Organisations WISeKey works with across the technology, cloud and integration ecosystem.

Logo tiles pending supplied SVGs.

Contact

Talk to an expert

Tell us what you need to trust — a device, a document, a fleet, a supply chain — and we will route you to the engineer or commercial lead who handles it.

Sales
Products, pricing, pilots and integration
Investor relations
Shareholders, analysts and filings
Press
Interviews, assets and statements
Headquarters
Geneva, Switzerland
Pont-Rouge

Send an enquiry

What is this about?

The more specific the constraint, the better we can route it.

Typical response within one business day.