About Policy as Code Engine policies

  • Release version: Australia
  • Updated July 24, 2026
  • 1 minute to read
  • Cryptographic Asset Compliance uses Policy as Code Engine (PaCE) policies to evaluate your cryptographic assets and flag risk.

    Policies evaluate cryptographic assets and raises a risk indicator when an asset meets a risk condition. Separate policies apply to certificates, AWS KMS keys, and Azure Key Vault keys. Note that some policies calculate the overall risk level for an asset by combining the results of the other policies rather than raising an indicator of their own. For more information, see Cryptographic Asset Compliance policies.

    Most policies are active by default and run automatically, so you don't have to set them up. However, the certificate authority trust policy is inactive by default because it depends on the certificate authorities that your organization trusts. You activate it after you add those authorities. For more information, see Configure trusted certificate authorities.

    Managing policies

    You can manage policies using PaCE. You can activate or deactivate a policy and edit its configuration, including the risk criticality that it assigns and review or revert your changes. For more information, see Manage PaCE policies.

    Note:
    Because a change affects how risk is calculated for the assets that the policy evaluates, avoid changing a policy, other than adding trusted certificate authorities.