It'll be tough when ICAs rotate every 5/6 months and may even randomise.
Plus, if you do any key pinning, you'd probably do well to also pin a backup public key you haven't used in case your CA/infra collapses and you quickly need to redo your HTTPS setup.
It’s best to simply not use public certs for pinning, if you really must do it.