TL;DR (The Landscape Shift)

The DigiCert Monopoly

The BIMI certificate market has shifted from a duopoly to a near-monopoly. This structural shake-up was driven by Entrust’s forced exit from the public trust market rather than organic competition.

The Entrust Fallout

Following major compliance failures, Entrust has issued zero certificates in 2026. All 4431 legacy Entrust certificates are expiring, forcing urgent enterprise migrations.

Rise of the Challengers

Three new players have stepped in to offer alternatives, providing vital options to mitigate systemic single-provider risk. Long-term forecasts expect non-DigiCert share to bounce back to 15–18% by 2027.

85.4%
DigiCert share of new 2026 issuances
Jan–Jul 2, 2026

73.6%
DigiCert cumulative share — all-time
Of 20227 total certificates

0
Entrust BIMI certs issued in 2026
CA business discontinued

5
Active BIMI Certificate Authorities
DigiCert · GlobalSign · Sectigo · SSL Corp

01 · The Paradox

A Market That Grew 54% and Became Less Competitive Simultaneously

The BIMI certificate market added thousands of new certificates in 2025, breaking every prior issuance record. In the same period, the number of effective Certificate Authorities dropped from two to one-and-a-fraction. Entrust — which issued more than 693 BIMI certificates in its peak year — issued 501 in 2025 and zero in 2026. DigiCert, the other founding CA, absorbed the entire market.

This report documents how that happened, what 20227 certificates tell us about where the CA power sits today, and what the arrival of three new entrants (GlobalSign, Sectigo, SSL Corporation) means for the competitive landscape over the next 24 months.

“The concentration story in BIMI is not about DigiCert’s ambition — it is about Entrust’s exit. One CA lost its ability to issue publicly trusted certificates, and the other inherited its entire market. New entrants arrived, but at combined volumes that represent under 5% of 2026 YTD issuances.”

02 · CA Landscape

The Cumulative Scoreboard

Across all years of recorded BIMI certificate issuance, DigiCert holds 73.6% of all-time volume. Entrust holds 21.9% — certificates that were issued before its exit and that are now running down to expiry. GlobalSign stands at 2.8% of all-time volume, Sectigo at 1%, and SSL Corporation at 0.6%.

Annual BIMI issuances by Certificate Authority — 2021 to 2026 YTD
Stacked bars show the full transition. 2026 = Jan–Jul 2 only.

DigiCert — 2020: 33; 2021: 313; 2022: 646; 2023: 1484; 2024: 2587; 2025: 5941; 2026 YTD: 3889 | Entrust — 2020: 16; 2021: 226; 2022: 693; 2023: 1254; 2024: 1741; 2025: 501
CAAll-time certsShare (cumulative)2026 YTD shareStatus
DigiCert14895

73.6%

85.4%ACTIVE
Entrust4431

21.9%

0%EXITED
GlobalSign562

2.8%

7.9%GROWING
Sectigo207

1%

4.2%ACTIVE
SSL Corporation123

0.6%

2.3%ACTIVE
Combined SSL Corp + Sectigo

SSL Corporation and Sectigo hold a combined 1.6% of all-time volume. Separately they appear minor; combined, they represent a meaningful alternative to DigiCert for organisations seeking CA diversification.

03 · Entrust Exit

4431 Certificates. Zero Renewal Path.

Entrust’s cumulative total of 4431 BIMI certificates represents the most consequential forced-migration event in the standard’s history. These certificates are active until their Not After date — but cannot be renewed with Entrust. Every holder must migrate to another CA before expiry or lose their inbox logo.

The expiry distribution is critical for planning. Of the 4431 outstanding Entrust certificates, 4431 have already expired (as of the July 2, 2026 snapshot). The remaining 0 active certificates expire on the following schedule:

PeriodVolumeUrgency
Already expired4431Expired
2026 H20Critical
20270Urgent
2028+0Plan ahead
Entrust certificate expiry distribution
4431 already expired. Remaining 0 certs shown by expiry window.

Entrust certificates — Already expired: 4431; Expires 2026 H2: 0; Expires 2027: 0; Expires 2028+: 0
Migration planning note

Organisations with Entrust BIMI certificates expiring in 2026 H2 should begin the migration process now. Reissuance under a new CA requires: DMARC/SPF/DKIM re-verification, logo file rehosting in some cases, DNS TXT record update, and CA onboarding documentation. Allow 2–4 weeks minimum. VMCcerts provides white-glove migration support for Entrust-affected certificate holders.

04 · New Entrants

Three CAs Entered in 18 Months. How Fast Are They Growing?

GlobalSign launched BIMI issuance in late 2024 with a single test certificate. By the July 2, 2026 snapshot, it has issued 562 certificates — a 177.7% increase from its first full year (2024: 1 cert, 2025: 202 certs, 2026 YTD: 359 certs). Its growth trajectory is the steepest of any CA in the BIMI market, from zero baseline.

Sectigo (207 certificates) and SSL Corporation (123 certificates) entered more recently and are at earlier growth stages. Their combined 1.6% market share understates their trajectory — both entered during 2025 and have grown monthly since launch.

New CA entrant growth — 2024 to 2026 YTD
GlobalSign entered late 2024. Sectigo and SSL Corp entered 2025. All quarterly data from CT logs.

GlobalSign — Q4 2024: 1; Q1 2025: 2; Q2 2025: 19; Q3 2025: 85; Q4 2025: 96; Q1 2026: 136; Q2 2026 YTD: 219 | SSL Corp / Sectigo — Q4 2024: 0; Q1 2025: 0; Q2 2025: 6; Q3 2025: 3; Q4 2025: 26; Q1 2026: 132; Q2 2026 YTD: 160
Dominant
DigiCert
85.4% of 2026 issuances. Absorbed Entrust’s market. Largest BIMI-qualified CA by volume. Near-monopoly position but faces structural concentration risk.
Exited
Entrust
4431 legacy certificates in rundown. Zero new issuances since May 2025. All holders on forced migration path.
Fastest growing
GlobalSign
177.7% growth from first to second year. Established TLS CA with existing enterprise relationships. Most credible DigiCert challenger.
Niche — growing
Sectigo + SSL Corp
Combined 1.6% market share. Both growing monthly. Sectigo (207 certs) ahead of SSL Corp (123 certs). Price-competitive positioning.

05 · Concentration Risk

What Happens If the Dominant CA Encounters a Problem?

The Entrust situation is not a hypothetical — it happened. A CA that held 21.9% of all-time BIMI certificates lost public trust status and exited the market. Organisations that held Entrust certificates faced a forced migration. Most managed it successfully, but the process required time, planning, and CA relationships that not every certificate holder had established.

With DigiCert now at 73.6% of cumulative issuances and 85.4% of 2026 YTD issuances, a DigiCert disruption would be significantly larger in scale than the Entrust exit. The concentration risk is real and structurally embedded in the current market.

2026 new issuance share by CA
Year-to-date issuances by Certificate Authority as of July 2, 2026.

DigiCert (85.4%): 3889; GlobalSign (7.9%): 359; Sectigo (4.2%): 190; SSL Corp (2.3%): 105
Concentration risk signal

The prudent response to 85.4% CA concentration is not alarm — it is planning. Organisations deploying BIMI now should understand what CA migration looks like operationally, maintain an up-to-date understanding of their certificate Not After dates, and track the BIMI CA landscape. VMCcerts monitors all 5 active CAs and provides advance notice to clients of market-structure changes.

Why new entrant growth matters disproportionately

At current growth rates, GlobalSign could reach 8–10% market share in new issuances by end of 2027. That is still a minority share, but it is enough to represent a fully functional alternative for organisations seeking CA diversification. Combined with Sectigo and SSL Corp, the non-DigiCert share of new issuances could reach 15–18% by 2027. The concentration peak may have already occurred in 2026 H1.

Methodology

Data Sources and Research Notes

This report derives entirely from Certificate Transparency (CT) log data. The dataset contains 20227 BIMI certificate records with a snapshot date of 2026-07-02. CA identification uses the Intermediate CA field in the CT log record, with Root CA as fallback for multi-path issuance structures. All-time share percentages are calculated against the total issued corpus, not the active corpus.

Sectigo and SSL Corporation share CA infrastructure in certain issuance configurations. In volume tables, they are shown separately. In concentration analysis, the 1.6% figure reflects their combined share. The “active certificates” figure of 0 for Entrust is derived from the subset of Entrust-issued certificates whose Not After date was after 2026-07-02 in the dataset. The 4431 “already expired” figure represents Entrust certificates with a Not After date before the snapshot date.

Expert Interpretation

Three Things This CA Data Tells Us Beyond the Market Share Numbers

The BIMI CA market is structurally healthier than the 85.4% headline suggests. DigiCert’s dominance is partly a statistical artefact of Entrust’s forced exit — not organic market capture. The correct comparison is: where would DigiCert’s 2026 share be if Entrust had continued operating at its 2024 pace (1,741 certs)? Roughly 65–70%, not 85.4%. That is concentrated but not unprecedented for a nascent market with high technical barriers to entry.

GlobalSign’s 177.7% first-to-second-year growth is the most important signal in this dataset. It shows that the market absorbs new entrants. An established CA with existing enterprise relationships can gain meaningful share within twelve months of launch. This matters for the long-term concentration question — the 85.4% figure is a transitional state, not a stable equilibrium.

Entrust’s 4431 legacy certificates will be fully retired by 2028. That retirement will coincide with the full maturation of GlobalSign, Sectigo, and SSL Corp. The CA landscape in 2028 will look substantially more competitive than today — not because DigiCert loses share organically, but because the Entrust-migration cohort will have already moved to new CAs and the new-entrant growth is compounding.

Self-Assessment

Four Questions for CA and Certificate Planning

1

Was your BIMI certificate issued by Entrust?

Check your certificate’s Intermediate CA field. If it reads “Entrust” – any Entrust entity – you are on a forced migration path. Check your Not After date. If you are expiring before December 2026, begin migration planning immediately.

2

Which CA issued your current certificate and when does it expire?

This is the most fundamental piece of BIMI certificate hygiene. Know your CA, your expiry date, and your renewal timeline. A certificate that expires without renewal removes your logo from recipient inboxes with zero warning to recipients.

Have you evaluated the new entrant CAs for your next renewal?

GlobalSign (2.8% share, growing fast), Sectigo (1%), and SSL Corp (0.6%) are all issuing BIMI certificates today. At renewal, comparing pricing and support across all 5 active CAs takes less time than most certificate holders assume.

If DigiCert’s trust status were to be challenged, how would you respond?

The Entrust event was not unprecedented — it was the application of existing CA/Browser Forum policies. Having a CA migration plan in place before you need it is the appropriate response to any single-CA concentration risk, not a sign of distrust in your current provider.

FAQ

Frequently Asked Questions

Why did Entrust exit the BIMI CA market?

In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances. Mozilla Firefox followed. Because BIMI certificates rely on publicly-trusted CA roots, this browser distrust effectively ended Entrust's ability to issue valid BIMI certificates. Entrust's last BIMI certificate was issued in May 2025. All existing Entrust BIMI certificate holders must migrate to a different CA before their certificate expires, as Entrust has no renewal path.

Are there meaningful differences between BIMI certificates from different CAs?

The certificate type (VMC or CMC) and the underlying standards are consistent across CAs — a BIMI VMC from GlobalSign delivers the same inbox logo display as one from DigiCert, provided all mailbox provider requirements are met. Differences lie in pricing, support model, renewal process, and the CA's integration with resellers and deployment partners. VMCcerts works with DigiCert, GlobalSign, Sectigo, and SSL Corporation and can advise on the right CA choice for your organisation's specific situation.

How do I know when my BIMI certificate expires?

Your BIMI certificate's Not After date is embedded in the certificate itself and visible via OpenSSL command-line tools, through your CA's dashboard if you have direct access, or through certificate monitoring services. VMCcerts monitors certificate expiry as part of its managed BIMI service and sends advance renewal notifications. The standard BIMI certificate term is 12 months; some CAs offer 24-month terms. Check your certificate details before expiry rather than relying on calendar reminders.

Does DigiCert's market dominance affect the cost of BIMI certificates?

Pricing for BIMI certificates has remained broadly stable despite the concentration increase, partly because the entry of GlobalSign, Sectigo, and SSL Corp creates competitive pressure even at low market share levels. VMCcerts negotiates pricing across 5 active CAs and typically achieves better rates than direct CA pricing for clients. The 85.4% DigiCert share has not resulted in observable price increases in our market monitoring.

How quickly can a CA migration be completed?

A straightforward CA migration — same logo, same domain, same mark type — can typically be completed in 1–2 weeks with a fully prepared organisation. The main steps are: documentation submission to the new CA, validation of DMARC/SPF/DKIM records, logo file verification, certificate issuance, and DNS TXT record update. The DNS update takes effect within TTL (typically 1–24 hours). For organisations without an established CA relationship, allow 2–4 weeks. VMCcerts expedites this for clients with existing accounts.
Holding an Entrust certificate? We handle the migration.
VMCcerts is a major partner of all 5 active BIMI Certificate Authorities. We manage migrations, renewals, and new deployments – including expedited Entrust migrations for clients with 2026 expiry dates.
Cite This Report



VMCcerts Research. (2026). BIMI CA Market Share Report 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/bimi-ca-market-share-2026
VMCcerts Research. “BIMI CA Market Share Report 2026.” VMCcerts, 2026, https://vmccerts.com/research/bimi-ca-market-share-2026.
@techreport{vmccerts2026CAMarketShare,
author = {VMCcerts Research},
title = {BIMI CA Market Share Report 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/bimi-ca-market-share-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – BIMI CA Market Share Report 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/bimi-ca-market-share-2026
ER –