A Common Mark Certificate is designed for organizations that use an established logo but do not yet have a qualifying registered trademark for VMC validation. Eligibility depends on more than the age of the business: the applicant must show consistent public use of the specific logo, demonstrate rights to use it and connect that logo to the legal entity and domains included in the request. Evidence may need to be reviewed separately across subsidiaries, brands and sending domains. CMC can support BIMI logo display where accepted, but provider-specific indicators, final approval and future migration to VMC depend on the organization’s circumstances and the issuing CA’s current requirements.
Many established brands use a consistent public logo but do not have a qualifying registered trademark for the mark they want to display through BIMI. A Common Mark Certificate may provide an alternative certificate path, but the difficult question is not simply what a CMC is. It is whether the organisation can prove a sufficiently established relationship between the legal entity, logo, domain and prior public use.
For the product overview, current application support and commercial CMC options, see the Common Mark Certificate product overview.
What is a Common Mark Certificate?
A Common Mark Certificate is one of the certificate-backed mark paths used in BIMI deployments. It is intended for eligible organisations that may not have a qualifying registered trademark for the logo they want to use. Instead of relying on the VMC trademark route, the issuing Certificate Authority assesses prior public or commercial use, organisation identity, domain control and rights to the logo. This guide focuses on those evidence and eligibility questions — how well that evidence connects the logo, the organisation and the domain, not simply whether a trademark exists.
An Alternative Mark-Validation Path
A CMC uses an alternative mark-validation path centred on prior public use, logo rights, organisation identity and domain relationships, rather than requiring the qualifying registered-trademark route generally used for VMC. That difference is what determines who may qualify, what evidence is required and whether CMC is the right long-term choice for a given brand — not simply whether it costs less.
This alternative path exists because many legitimate brands use an established logo without holding a qualifying registered trademark. Some hold trademarks registered at offices that aren’t recognised for VMC validation. Some have a trademark application pending rather than granted. Some sub-brands use logos that aren’t covered by a parent company’s registered mark. CMC was introduced as a separate evidence route to address that gap — it expands access; it doesn’t remove validation.
VMCcerts’ Global BIMI Adoption Report 2026 records both VMC and CMC in the observed certificate ecosystem, with CMC representing the smaller route in the reviewed dataset. This provides market context only; it does not show that either certificate is more suitable for an individual brand.
CMC and VMC: A Compact Eligibility Comparison
The table below compares the two paths on eligibility factors only — not price, not Certificate Authority choice, and not which certificate is “better.”
| Decision Question | CMC Path | VMC Path |
|---|---|---|
| Qualifying trademark available? | Not required, but other evidence is required | Generally required |
| Principal mark evidence | Prior public use and logo rights | Accepted trademark registration |
| Typical use case | Established logo without a qualifying trademark route | Trademark-backed logo |
| Organisation and domain validation | Required | Required |
| Automatic eligibility | No | No |
| Display guaranteed | No | No |
For a broader commercial comparison of BIMI certificate paths, see BIMI Certificates.
The main difference is the mark-validation path. A CMC uses an alternative path centred on prior public use, logo rights, organisation identity and domain relationships, rather than the qualifying registered-trademark route generally required for a VMC. Neither certificate is automatic, and mailbox-provider display remains subject to provider policy in both cases.
The Prior-Use Requirement
Prior use, at a business-readable level, means demonstrating that the organisation has used the specific logo publicly or commercially before the application — not simply that the company exists or that the brand is well known. Useful evidence tends to include consistency of logo use over time, dated materials such as website history and marketing collateral, customer-facing communication, public records, and domain-specific evidence connecting that exact logo to the domain requesting the certificate. Logo ownership or documented permission to use the mark is assessed alongside the use history itself.
Current DigiCert and GlobalSign guidance requires the relevant logo to have at least 12 months of documented public use before CMC verification. The issuing CA still determines whether the evidence sufficiently connects the logo, organization and requested domains.
Several nuances matter here, and they’re the reason this section exists as its own guide rather than a paragraph on the product page. A long-established company may still have weak evidence for a recently introduced logo — the company’s age doesn’t transfer to a new mark, and 12 months of use history cannot be created retroactively simply by producing an old-looking asset. A longstanding logo may be strongly associated with one domain but have little public history on another. Evidence built around a parent company doesn’t automatically establish use by a subsidiary. A logo used only privately or internally may not satisfy the public-use expectation CAs typically apply. Ultimately, the CA makes the final evidence decision, and requirements can vary by issuer.
The CMC Multi-Domain Scenario: Prior-Use Evidence Unavailable and Domain Reset Path illustrates this directly: a real (anonymised) deployment where prior-use evidence supported a primary domain but not a secondary one, requiring a domain-specific reset and resubmission. For the baseline question of whether BIMI is possible at all without a trademark, see Can I Get BIMI Without a Registered Trademark?
Prior-use evidence generally needs to show that the organisation has used the relevant logo publicly or commercially before the application. Depending on the issuer and case, useful evidence may include dated website history, marketing materials, customer communications, public brand assets or other records connecting the logo, organisation and domain. Evidence for one logo, entity or domain may not automatically support another. Final acceptance remains with the issuing Certificate Authority.
Why “No Trademark Required” Does Not Mean “No Validation Required”
Not requiring the VMC trademark route does not remove validation. It shifts the application to an alternative evidence framework covering organisation identity, domain control, logo rights, prior use and BIMI readiness. At a high level, CA review groups into four areas.
Organisation and applicant
Legal entity confirmation, applicant authority to request the certificate, and identity checks on the person or team submitting the application.
Domain and sending identity
Domain control, confirmation of the relevant sending identity, and DMARC readiness — see DMARC Alone Isn’t Enough for BIMI for what enforcement-level readiness involves.
Logo rights and prior use
Ownership or right to use the mark, documented public or commercial history, consistency of the logo across channels, and a clear connection between that specific logo, the entity and the domain — see Can I Get BIMI Without a Registered Trademark? for the underlying eligibility logic.
BIMI deployment readiness
A suitable logo asset, a correctly published BIMI record, certificate deployment, and awareness of provider-specific display requirements — the Mark Certificate Setup Guide and the CA identity and logo review scenario cover this stage in more depth.
This article intentionally doesn’t reproduce exact DNS syntax, complete document checklists, or exact video-verification steps — those change by issuer and are covered where they’re kept current, on the pages linked above.
What Problem Does the CMC Path Solve?
The CMC evidence path answers a specific eligibility gap, not a general alternative to trademark protection: an established but unregistered logo, a pending trademark application, a registered office that VMC doesn’t accept, a graphical mark not covered by a word-mark registration, or a sub-brand with its own independent use history. The candidate profiles below work through each of these situations in more depth.
Who May Be a Strong CMC Candidate?
The profiles below may be worth assessing against CMC criteria — none of them qualify automatically.
Brands that match one or more of these profiles can request a preliminary CMC eligibility assessment.
Who May Not Qualify Yet?
Is Your Logo CMC Ready?
Does your logo have enough history and evidence for a Common Mark Certificate?
Multi-Domain CMC Considerations
A certificate request covering multiple domains needs a careful, domain-by-domain evidence review — prior use isn’t a single organisation-wide fact, and different brands or sub-brands within the same company may have very different use histories. One domain may qualify while another does not, and a newer domain shouldn’t be assumed to inherit the evidence history of an older, established one. Parent and subsidiary relationships often need their own documentation, and one evidence package should not be assumed to cover every domain in a request. Some domains may need separate treatment entirely, and a VMC may end up more suitable for one domain while CMC is considered for another, depending on what evidence each domain can produce.
The CMC multi-domain scenario referenced above is a useful illustration of exactly this pattern in practice, not a replacement for reviewing your own domains individually. There’s no universal statement about how many domains a single CMC can or should cover — that depends entirely on what each domain’s evidence supports.
Potentially, but multi-domain eligibility should not be assumed. The issuing CA may need to validate the organisation’s relationship to each domain and determine whether the logo’s prior-use evidence applies across the requested identities. A logo may be well established on one domain but newly introduced on another. Review the evidence domain by domain before deciding how to structure the certificate request.
Mailbox Display and Verification Indicators
Both CMC and VMC can be used within certificate-backed BIMI workflows, but display itself depends on mailbox-provider support and policy, not on the certificate type alone. Logo rendering is controlled by the receiving mailbox provider, and current provider support can change over time. CMC and VMC may not receive identical mailbox-provider indicators. If a specific Gmail verification indicator or another provider-specific visual experience is a purchasing requirement, confirm the current certificate and provider policy before applying — don’t assume either certificate path produces the same visual result in every inbox.
No. A Common Mark Certificate can support certificate-backed BIMI identity, but mailbox providers decide whether and how a logo or verification indicator is displayed. Display can depend on DMARC enforcement, sending reputation, provider support, certificate status, BIMI configuration and other provider-specific conditions. Confirm the target mailbox-provider experience before choosing the certificate path.
For current, provider-specific display behaviour rather than general assumptions, see Gmail BIMI Verification Process: Six Checks Before Logo Display and Microsoft 365 BIMI Support. If a logo that was previously displaying stops appearing, Why Isn’t My BIMI Logo Showing? covers the common causes.
CMC Limitations
What a CMC does not provide
- No automatic eligibility
- No guaranteed mailbox display
- No guaranteed verification indicator
- No guaranteed open-rate or revenue improvement
- No complete phishing protection
- No replacement for DMARC
- No replacement for trademark registration where legal protection is the objective
- Prior-use evidence can be rejected
- Evidence may vary by domain or entity
- Display can change by provider over time
- Certificate lifecycle and renewal still require active ownership
- Logo or rebrand changes may require revalidation
- May not satisfy a buyer whose core objective specifically requires a VMC-only display experience
These limitations are worth stating plainly. A buyer who understands them upfront is in a stronger position to choose the right path — and less likely to be surprised later by what CMC was never designed to do. Measuring whether a certificate actually changed behaviour after deployment is a separate exercise from eligibility; see How to Measure VMC and BIMI Performance Without Overstating ROI for a structured approach.
Your Logo. Your Brand. Verified.
Strengthen brand recognition and trust with a Common Mark Certificate.
Moving From CMC to VMC Later
A brand may reasonably start with a CMC and later obtain a qualifying registered trademark, at which point moving to VMC becomes worth evaluating. That move isn’t necessarily an automatic conversion — a new application and its own validation are typically required, and trademark acceptance, organisation details and logo alignment all get checked again as part of that process. Depending on how the certificate is deployed, the hosted certificate file or the BIMI DNS record’s a= reference may need updating, and that transition is worth planning deliberately to avoid an interruption in display continuity.
Historical CMC eligibility doesn’t guarantee VMC eligibility — the two are separate evaluations, as covered in Can I Get BIMI Without a Registered Trademark? VMC may become preferable once the registered-trademark route is in place, particularly where a specific display experience or stronger governance objective is the priority. Certificate lifecycle and renewal ownership matters throughout this transition; see What Happens When a VMC Certificate Expires? for what continuity looks like once a certificate — CMC or VMC — is in place.
CMC Decision Framework
| Brand Situation | Path to Assess |
|---|---|
| Qualifying trademark already exists | Assess VMC |
| No qualifying trademark, established logo use | Assess CMC |
| Trademark pending | Compare CMC now with VMC later |
| Logo recently launched | Prior-use evidence may be insufficient — build history first |
| Trademark office not accepted for VMC | Assess CMC or an alternate accepted-office trademark route |
| Word mark exists but the graphical logo differs | Review VMC alignment and CMC evidence side by side |
| Multiple domains involved | Review evidence per domain before ordering |
| Specific checkmark or indicator required | Confirm mailbox-provider and certificate-path support directly |
| DMARC not yet enforced | Fix the authentication foundation first |
| Rebrand underway | Delay or carefully plan evidence and certificate transition |
A starting framework for assessment, not an automated eligibility guarantee. Ready to weigh a specific brand situation? Evaluate the Common Mark Certificate path.
What to Verify Before Applying
Pre-application checklist
- Organisation name and legal entity
- Applicant authority
- Domain ownership and control
- DMARC enforcement state
- Sending-domain inventory
- Logo version in use
- Logo ownership or right of use
- Prior-use evidence available
- Evidence dates
- Domain-specific logo association
- Existing trademarks, if any
- Pending trademarks, if any
- Desired mailbox-provider display
- Multi-domain scope
- Rebrand plans
- Renewal and lifecycle owner
Where to Go Next
| Reader Need | Correct Destination |
|---|---|
| Compare CMC and VMC paths generally | BIMI Certificates |
| Learn whether BIMI works without a trademark | BIMI Without a Trademark (KB) |
| Understand pending-trademark options | My Trademark Is Pending (KB) |
| Improve DMARC enforcement | DMARC Services |
Navigation, not a summary — each destination owns detail this article doesn’t reproduce.