BIMI Market Changes in 2026: Adoption, CAs and Certificate Strategy

TL;DR

For the first few years of BIMI, the main question an organisation faced was straightforward: should we deploy it? By 2026, more organisations have moved beyond asking whether BIMI is relevant and are confronting the decisions that follow: certificate eligibility, issuer choice, renewal ownership and long-term continuity. Which certificate path fits our brand? Which issuer should we choose? Who owns renewal when it comes due? What happens if that issuer exits the market? And how do we manage this across more domains and more brands as the programme grows?

BIMI (Brand Indicators for Message Identification) is the standard that lets a verified brand logo appear next to authenticated email in supported inboxes, using a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) alongside DMARC enforcement. That mechanic hasn’t changed. What has changed is what running a BIMI programme actually requires once the logo is live — and that shift is the subject of this article.

Certificate Choice Is No Longer One-Size-Fits-All

Early BIMI conversations mostly meant one certificate type: the Verified Mark Certificate, available only to organisations with a registered trademark. That’s no longer the only path. A Common Mark Certificate now offers a second route into BIMI, built around demonstrated prior use of a logo rather than trademark registration.

Both VMC and CMC can support BIMI logo display at participating mailbox providers, but they do not provide identical verification indicators or mailbox-provider coverage. A VMC is based on a qualifying registered trademark or other recognised mark route; a CMC provides an eligible prior-use route for logos without a qualifying registered trademark. Where an organisation owns a qualifying registered trademark, a VMC generally provides the broader verification path, including eligibility for Gmail’s verified checkmark. A CMC provides an alternative for eligible logos established through prior use, though its supported indicators and mailbox-provider coverage may differ. Neither is simply the “cheaper” or “premium” option — the right choice depends on where your brand’s trademark position actually stands, not on price alone.

Certificate eligibility and DMARC readiness should be evaluated in parallel. There is little value in completing certificate selection without a viable route to DMARC enforcement, and equally little value in finishing DMARC work before discovering that the intended logo does not qualify for the expected certificate path. Our VMC and CMC explainer covers eligibility mechanics in full; VMCcerts’ VMC vs CMC buyer decision research goes deeper into how organisations are actually choosing between the two paths in 2026.

Where Does Your Brand Stand in BIMI Adoption?

See how your domain compares — and what’s missing.

Check BIMI Eligibility – It’s Free

BIMI Expert

Certificate Authority Concentration Makes Provider Planning More Important

The BIMI Certificate Authority landscape looks very different than it did two years ago. DigiCert now accounts for 85.4% of 2026 year-to-date issuances and 73.6% of all-time cumulative issuance, according to VMCcerts’ Certificate Authority research. That concentration is largely a byproduct of one CA’s exit from the market rather than organic market capture — worth understanding, not alarming on its own.

The market is not static. Other authorised issuers, including GlobalSign and Sectigo, are building their BIMI certificate presence, giving buyers alternatives where validation model, support, pricing or continuity requirements differ. The important decision is not simply which CA has the largest share, but which issuer and service path fit the organisation’s situation.

The practical takeaway for buyers: the CA with the highest share is not automatically the correct choice for every organisation. Provider selection should weigh validation experience, support quality, and continuity planning alongside issuance volume — which is precisely why VMCcerts separates “which CA has the most certificates” from “which CA is the right fit for your organisation.” Our provider comparison page covers how DigiCert, GlobalSign and Sectigo differ by eligibility and deployment profile, without repeating the full breakdown here.

Four BIMI Market Changes and the Decision Each One Affects

Original summary built for this article — not reproduced from a research report.

Market changeWhy it mattersDecision it affectsBest next resource
Certificate choice is no longer one pathVMC and CMC now serve different eligibility situations, not different price tiersWhich certificate type to apply forVMC/CMC buyer decision research
CA issuance is concentrated post-EntrustOne CA now issues the large majority of new certificatesWhich issuer to select, and how to plan for continuityCA Market Share 2026
The Entrust exit set a lifecycle precedentA CA exit can force migration even when the organisation’s original deployment has not otherwise changedWho owns renewal and migration riskProvider switching guide (KB)
BIMI is now operational, not experimentalProgrammes benefit from ongoing ownership, not a one-time deploymentHow renewal and multi-domain management get resourcedCertificate renewal and lifecycle guidance

The Entrust Exit Exposed Lifecycle Risk

Following the 2024 distrust actions affecting Entrust’s publicly trusted certificate business, Entrust exited new BIMI certificate issuance. Existing holders therefore cannot assume renewal through the original issuer and may need to move to another authorised CA. VMCcerts’ historical research identified a substantial population of Entrust-issued BIMI certificates without a renewal path through the original issuer.

The number itself matters less than the lesson it teaches: a BIMI certificate isn’t a “set and forget” purchase. Issuing a certificate is the start of an ongoing relationship with a specific Certificate Authority, and that relationship can end for reasons entirely outside an organisation’s control. Certificate holders who assumed their issuer would always be available to renew with are the ones who felt this most acutely.

One VMCcerts renewal scenario illustrates the operational side of this well: even a routine, non-forced VMC renewal involves procurement coordination, CA validation steps, and careful timing to avoid a logo gap — friction that multiplies considerably when the renewal is also a forced CA migration. Our provider-switching KB guide covers the mechanics of moving to a new CA without losing logo display; VMCcerts’ renewal service handles that migration directly for affected certificate holders.

Adoption Is Becoming Operational, Not Experimental

Put the first three changes together and a clear pattern emerges: BIMI in 2026 behaves less like a project with a finish line and more like a standing operational responsibility, similar to how organisations already treat TLS certificate management or domain renewal.

Organisations operating BIMI across multiple domains or brands benefit from a named owner for renewal, not an assumption that “someone will notice” before a certificate lapses. They benefit from monitoring upcoming expiry dates across every domain in the portfolio, not just the first one deployed. They benefit from a plan for what happens when a brand refreshes its logo, adds a new sending domain, or restructures under a new legal entity. And continuity across the people managing the programme matters — reliance on one individual can create continuity risk when responsibilities change.

None of this requires alarm — it requires the same kind of lifecycle thinking most organisations already apply to other certificate-backed infrastructure. Our renewal and revalidation KB guide explains what changes and what stays the same at each renewal; VMCcerts’ renewal service can support certificate tracking, revalidation and renewal coordination.

Get Your VMC Certificate from a Trusted Certificate Authority

Issued through DigiCert, Sectigo, and GlobalSign — the most trusted CAs in the VMC market.

Starting From$749/yr

View Product

Frequently Asked Questions

What was the biggest change in the BIMI certificate market in 2026?

The biggest shift is less about adoption growing and more about what running a BIMI programme now requires. The market has moved from initial deployment interest toward certificate choice, issuer continuity, and lifecycle ownership becoming central, ongoing decisions rather than one-time setup steps. Organisations that treated their first certificate as the finish line are now catching up to renewal, migration, and multi-domain planning they didn't originally budget time for. See VMCcerts' State of Inbox Trust 2026 report for the full annual picture.

Does the growth of CMC mean VMC is becoming less important?

No. CMC provides an eligible prior-use route for organisations without a qualifying registered trademark, expanding who can access BIMI — but VMC and CMC do not offer identical verification indicators. Where an organization holds a qualifying registered trademark, VMC generally provides the broader verification path, including eligibility for Gmail's verified checkmark; CMC remains a genuine alternative, not merely a cheaper substitute. The right choice depends on your brand's current trademark position. See our VMC/CMC explainer, or explore the Common Mark Certificate path directly.

Why does Certificate Authority concentration matter to buyers?

Because issuer choice affects more than the certificate you receive today — it affects continuity, validation experience, and how easily you can migrate later if something changes. Market share alone doesn't determine the best path for your organisation; a CA's support quality and your own eligibility profile matter just as much. The Entrust exit is a concrete example of why this isn't theoretical. See VMCcerts' CA Market Share research and our provider comparison page.

What did the Entrust exit teach BIMI certificate holders?

That certificate issuance is not the end of the lifecycle. A Certificate Authority can lose its ability to issue trusted certificates for reasons entirely outside a customer's control. Organisations still relying on an Entrust-issued BIMI certificate need to confirm its status and plan migration before renewal or expiry, since no renewal path exists through the original issuer. The practical lesson is to understand your issuer relationship and have a continuity plan before you need one, not after. See our provider-switching KB guide or VMCcerts' renewal service.

Which organisations should reassess their BIMI strategy now?

A few groups in particular: organisations still holding an Entrust-issued certificate, brands weighing VMC against CMC for the first time, multi-brand or multi-domain organisations managing several certificates at once, anyone approaching a renewal date, brands with DMARC enforcement already in place but no BIMI deployment yet, and agencies managing BIMI across multiple clients. Check your BIMI readiness or explore VMC and CMC certificate options.
Is your BIMI record working correctly?
53.6% of BIMI records contain errors. Check yours — and see if your logo is actually displaying.