For the first few years of BIMI, the main question an organisation faced was straightforward: should we deploy it? By 2026, more organisations have moved beyond asking whether BIMI is relevant and are confronting the decisions that follow: certificate eligibility, issuer choice, renewal ownership and long-term continuity. Which certificate path fits our brand? Which issuer should we choose? Who owns renewal when it comes due? What happens if that issuer exits the market? And how do we manage this across more domains and more brands as the programme grows?
BIMI (Brand Indicators for Message Identification) is the standard that lets a verified brand logo appear next to authenticated email in supported inboxes, using a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) alongside DMARC enforcement. That mechanic hasn’t changed. What has changed is what running a BIMI programme actually requires once the logo is live — and that shift is the subject of this article.
Certificate Choice Is No Longer One-Size-Fits-All
Early BIMI conversations mostly meant one certificate type: the Verified Mark Certificate, available only to organisations with a registered trademark. That’s no longer the only path. A Common Mark Certificate now offers a second route into BIMI, built around demonstrated prior use of a logo rather than trademark registration.
Both VMC and CMC can support BIMI logo display at participating mailbox providers, but they do not provide identical verification indicators or mailbox-provider coverage. A VMC is based on a qualifying registered trademark or other recognised mark route; a CMC provides an eligible prior-use route for logos without a qualifying registered trademark. Where an organisation owns a qualifying registered trademark, a VMC generally provides the broader verification path, including eligibility for Gmail’s verified checkmark. A CMC provides an alternative for eligible logos established through prior use, though its supported indicators and mailbox-provider coverage may differ. Neither is simply the “cheaper” or “premium” option — the right choice depends on where your brand’s trademark position actually stands, not on price alone.
Certificate eligibility and DMARC readiness should be evaluated in parallel. There is little value in completing certificate selection without a viable route to DMARC enforcement, and equally little value in finishing DMARC work before discovering that the intended logo does not qualify for the expected certificate path. Our VMC and CMC explainer covers eligibility mechanics in full; VMCcerts’ VMC vs CMC buyer decision research goes deeper into how organisations are actually choosing between the two paths in 2026.
Where Does Your Brand Stand in BIMI Adoption?
See how your domain compares — and what’s missing.
Certificate Authority Concentration Makes Provider Planning More Important
The BIMI Certificate Authority landscape looks very different than it did two years ago. DigiCert now accounts for 85.4% of 2026 year-to-date issuances and 73.6% of all-time cumulative issuance, according to VMCcerts’ Certificate Authority research. That concentration is largely a byproduct of one CA’s exit from the market rather than organic market capture — worth understanding, not alarming on its own.
The market is not static. Other authorised issuers, including GlobalSign and Sectigo, are building their BIMI certificate presence, giving buyers alternatives where validation model, support, pricing or continuity requirements differ. The important decision is not simply which CA has the largest share, but which issuer and service path fit the organisation’s situation.
The practical takeaway for buyers: the CA with the highest share is not automatically the correct choice for every organisation. Provider selection should weigh validation experience, support quality, and continuity planning alongside issuance volume — which is precisely why VMCcerts separates “which CA has the most certificates” from “which CA is the right fit for your organisation.” Our provider comparison page covers how DigiCert, GlobalSign and Sectigo differ by eligibility and deployment profile, without repeating the full breakdown here.
Four BIMI Market Changes and the Decision Each One Affects
Original summary built for this article — not reproduced from a research report.
| Market change | Why it matters | Decision it affects | Best next resource |
|---|---|---|---|
| Certificate choice is no longer one path | VMC and CMC now serve different eligibility situations, not different price tiers | Which certificate type to apply for | VMC/CMC buyer decision research |
| CA issuance is concentrated post-Entrust | One CA now issues the large majority of new certificates | Which issuer to select, and how to plan for continuity | CA Market Share 2026 |
| The Entrust exit set a lifecycle precedent | A CA exit can force migration even when the organisation’s original deployment has not otherwise changed | Who owns renewal and migration risk | Provider switching guide (KB) |
| BIMI is now operational, not experimental | Programmes benefit from ongoing ownership, not a one-time deployment | How renewal and multi-domain management get resourced | Certificate renewal and lifecycle guidance |
The Entrust Exit Exposed Lifecycle Risk
Following the 2024 distrust actions affecting Entrust’s publicly trusted certificate business, Entrust exited new BIMI certificate issuance. Existing holders therefore cannot assume renewal through the original issuer and may need to move to another authorised CA. VMCcerts’ historical research identified a substantial population of Entrust-issued BIMI certificates without a renewal path through the original issuer.
The number itself matters less than the lesson it teaches: a BIMI certificate isn’t a “set and forget” purchase. Issuing a certificate is the start of an ongoing relationship with a specific Certificate Authority, and that relationship can end for reasons entirely outside an organisation’s control. Certificate holders who assumed their issuer would always be available to renew with are the ones who felt this most acutely.
One VMCcerts renewal scenario illustrates the operational side of this well: even a routine, non-forced VMC renewal involves procurement coordination, CA validation steps, and careful timing to avoid a logo gap — friction that multiplies considerably when the renewal is also a forced CA migration. Our provider-switching KB guide covers the mechanics of moving to a new CA without losing logo display; VMCcerts’ renewal service handles that migration directly for affected certificate holders.
Adoption Is Becoming Operational, Not Experimental
Put the first three changes together and a clear pattern emerges: BIMI in 2026 behaves less like a project with a finish line and more like a standing operational responsibility, similar to how organisations already treat TLS certificate management or domain renewal.
Organisations operating BIMI across multiple domains or brands benefit from a named owner for renewal, not an assumption that “someone will notice” before a certificate lapses. They benefit from monitoring upcoming expiry dates across every domain in the portfolio, not just the first one deployed. They benefit from a plan for what happens when a brand refreshes its logo, adds a new sending domain, or restructures under a new legal entity. And continuity across the people managing the programme matters — reliance on one individual can create continuity risk when responsibilities change.
None of this requires alarm — it requires the same kind of lifecycle thinking most organisations already apply to other certificate-backed infrastructure. Our renewal and revalidation KB guide explains what changes and what stays the same at each renewal; VMCcerts’ renewal service can support certificate tracking, revalidation and renewal coordination.
Get Your VMC Certificate from a Trusted Certificate Authority
Issued through DigiCert, Sectigo, and GlobalSign — the most trusted CAs in the VMC market.