An Offline Root CA is used when particularly high requirements apply to protecting the central trust anchor of a PKI. Its private key remains disconnected from the network during normal operations.
The Root CA is activated only for a limited number of controlled operations, such as issuing or renewing Sub-CA certificates or making structural changes to the PKI. This model is particularly common in security-critical and regulated environments.