The Root CA is the highest trust authority in a hierarchical PKI. Its certificate is self-signed and serves as the trust anchor for the Certification Authorities below it.
Because the Root CA’s private key requires a particularly high level of protection, the Root CA is often operated offline in environments with high security requirements and activated only for a limited number of controlled operations.