Section 01
Australia’s BIMI Position
Australia’s 841 certificates represent a mature, broad-based deployment. Unlike some markets where adoption is concentrated in one sector, Australian BIMI spans Banking (15.7%), Technology/SaaS (21%), Retail (16.8%), and Healthcare — a relatively even distribution that reflects genuine enterprise-wide uptake rather than sector-led early adoption.
The per-capita adoption story is strong. Australia has roughly 1.3% of global population but holds 4.2% of all BIMI certificates. That premium reflects the Australian enterprise market’s consistent early adoption of email trust infrastructure, driven partly by active ACSC (Australian Cyber Security Centre) guidance on email authentication standards.
In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances spanning several years. Mozilla Firefox followed with an equivalent public distrust decision. Because BIMI’s Verified Mark Certificate (VMC) and Common Mark Certificate (CMC) infrastructure relies on publicly-trusted Certificate Authority roots, this browser distrust effectively ended Entrust’s ability to issue new BIMI certificates. Entrust’s last BIMI certificate was issued in May 2025. As of the July 2026 dataset snapshot, only 0 Entrust BIMI certificates remain active globally — all expire by December 2026 with no renewal path. Existing holders must migrate to DigiCert, GlobalSign, or Sectigo before their certificate’s expiry date to avoid losing their verified inbox logo.
185 Australian certificates were issued by Entrust — all require reissuance through an active CA
Australia’s 22% Entrust concentration matches the global average exactly. At current expiry rates, the majority of these will require migration before end of 2027. DigiCert already holds 75% of the Australian market and is the natural migration destination for most.
Section 02
Sector Analysis
Banking/Financial is Australia’s standout sector in proportional terms. At 15.7% of certificates, it broadly matches the global 16.5% — strong for a market where the Big Four banks (ANZ, CBA, NAB, Westpac) have long invested in email security as a customer trust issue. Australian banks face significant brand impersonation via email, and BIMI adoption reflects a deliberate posture against that threat.
Retail at 16.8% is slightly above the global 15.5%, consistent with Australia’s sophisticated retail email marketing environment. Healthcare at 4.9% is in line with global benchmarks — significant room for growth as regulatory pressure on healthcare email security increases.
Section 03
Growth Trajectory
From 19 certificates in 2021 to 297 in 2025 — a 15.6-fold increase. The 2026 YTD pace of 176 certificates in the first half of 2026 (January 1 – July 2) projects to approximately 312 for the full year, a 5.1% increase over 2025. Growth is moderating slightly in percentage terms, consistent with a market transitioning from early-majority to mainstream adoption.
Australia has 74 CMC certificates — an 8.8% CMC share, exactly matching the global average. CMC’s prior-use mark path is well-suited to Australia’s large mid-market company segment where trademark registration is less universal than among ASX-listed enterprises.
Section 04
CA Distribution
| CA | AU certificates | AU share | Status |
|---|---|---|---|
| DigiCert | 631 | 75% | Active |
| Entrust | 185 | 22% | Discontinued — migrate on expiry |
| GlobalSign | 17 | 2% | Active · growing |
| Sectigo | 8 | 1% | Active |
Section 05
Outlook
Australia’s BIMI market is in a consolidation-and-expansion phase. The Entrust migration is the immediate priority — 185 certificates requiring reissuance over the next 12–18 months. Beyond that, growth will come from three areas: mid-market financial services deepening beyond the Big Four, healthcare sector adoption driven by ACSC guidance, and CMC-enabled deployment by retailers and consumer brands not yet holding trademark registrations.
Expert Interpretation
What Australia’s Adoption Profile Signals
“Australia’s per-capita adoption rate is one of the strongest signals of enterprise email security maturity in the Asia-Pacific region. 841 certificates from a country of 26 million means adoption is genuinely broad-based — not concentrated in a handful of multinationals. The Big Four banks, major retailers, and leading technology companies all appear in the dataset. The next cohort will be the mid-market: regional banks, state government agencies, and healthcare providers completing DMARC enforcement.”
The ACSC (Australian Cyber Security Centre) has been ahead of most government bodies globally in recommending DMARC enforcement as a baseline security control. That policy leadership has a direct correlation to Australia’s BIMI adoption rate — organisations that implemented DMARC at enforcement following ACSC guidance are exactly the organisations that then proceed to BIMI.
FAQ
Australia-Specific Questions
Does ACSC guidance require BIMI or just DMARC?
Is an Australian trademark registration required for a VMC?
Which mailbox providers show BIMI logos for Australian recipients?
Self-Assessment
Three Questions for Australian Organisations
Read next
Continue the Research
author = {VMCcerts Research},
title = {Australia BIMI Maturity Report 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/australia-bimi-maturity-report-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
AU – VMCcerts Research
TI – Australia BIMI Maturity Report 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/australia-bimi-maturity-report-2026
ER –