Responsibility for issuing certificates can be delegated by setting up subordinate Certificate Authorities (CAs). CAs can sign their own certificates (that is, they are self-signed) or they can be signed by another certificate authority. The X.509 standard includes a model for setting up a hierarchy of CAs. In this model, as shown in the following figure, the root CA is at the top of the hierarchy and is a self-signed certificate by the certificate authority. The CAs that are directly subordinate to the root CA have CA certificates signed by the root certificate authority. CAs under the subordinate CAs in the hierarchy have their CA certificates signed by the subordinate CAs.