#Create a database and private key backup
> certutil.exe -backup <drive>:\CaBackup
#Create a certificate backup
> certutil -ca.cert "<drive>:\CaBackup\<CA_Name>.cer"
#Create a registry export
>reg export HKLM\SYSTEM\CurrentControlSet\services\CertSvc
<drive>:\CaBackup\CAregistry.reg
#stop the AD CS service
> net stop certsvc