Great question and some great answers too.
Keep in mind that you're about 90% ahead of most other people simply by considering this issue rather than blindly charging ahead.
Having kept that in mind and taken the other advice here, I would simply add: don't rest on your laurels; keep an eye on security and cryptography news for both general issues relating to certificate issuing, revocation, cracking, etc. and most definately on vulnerabilites and issues with the specific products you use to generate and manage your keys.
Lastly: physical security. Making something 'hacker proof' is no help if I can just get a job as a contract cleaner in your building and then put the disk containing your root cert in my pocket one day. You'd be surprised how many people miss that one.