14895
DigiCert — founding pillar
73.6% of all BIMI certs
4431
Entrust active certs
CA business discontinued
562
GlobalSign total
Market entry late 2024/2025
330
SSL Corp incl. Sectigo
2025/2026 entrant
85.4%
DigiCert 2026 share
Of all new issuances
0
Entrust 2026 new certs
Zero — CA exited

Executive Summary

The BIMI certificate authority landscape in 2026 is not the market it was in 2022. Two founding pillars — DigiCert and Entrust — built the ecosystem together. One has now exited. Two new CAs have entered. And one channel provider operates under a rebranded infrastructure that traces back to DigiCert’s original market position.

Entrust discontinued its Certificate Authority business, which included the cessation of all public certificate issuance — BIMI certificates included. The 4431 organisations holding active Entrust-issued BIMI certificates are operating on legacy certificates that will not be renewed through Entrust. Their pathway is migration to recognized BIMI certificate providers – DigiCert, GlobalSign, or Sectigo before their expiry date.

DigiCert captured 85.4% of all new BIMI issuances in the first half of 2026 (January 1 – July 2). GlobalSign, which entered the BIMI market properly in 2025, has issued 562 certificates. SSL Corp — operating Sectigo as a distribution channel — has issued 330 certificates across both brands since entering in 2025. The four-CA market is now effectively a one-CA market for new issuances, with two emerging challengers.

CA Landscape

Four CAs — Three Eras

DigiCert
Founding pillar — still dominant
Founding CA
Total active certs14895 (73.6%)
2025 new issuances5941
2026 YTD issuances3889
2026 share of new certs85.4%
StatusFully active · growing
Entrust
Founding pillar — CA business discontinued
CA Exited
Total active certs4431 (21.9%)
2024 issuances (peak)1741
2025 issuances (wind-down)501
2026 YTD issuances0 — ZERO
StatusCA business discontinued
GlobalSign
Market entry late 2024 / 2025
New Entrant
Total active certs562 (2.8%)
Market entryLate 2024 (1 cert) / 2025
2025 issuances202
2026 YTD issuances359
StatusActive · expanding
SSL Corp (incl. Sectigo channel)
Entered 2025 · dual-brand distribution
New Entrant
Total active certs330 (1.6%)
SSL Corp (direct)123 certs
Sectigo (channel brand)207 certs
2026 YTD combined295
StatusActive · dual-brand

Section 01

How the BIMI CA Market Was Built — and How It Changed

19
2019–2021 · The Founding Duopoly
DigiCert and Entrust co-founded the Verified Mark Certificate (VMC) market, working alongside the BIMI Group and AuthIndicators Working Group to establish the certificate standard. Both CAs were present at the launch of commercial VMC issuance. The ecosystem’s first 51 certificates were split between them.
22
2022–2023 · Rapid Growth, Two-CA Market
BIMI adoption accelerated: 1339 new certs in 2022 (+148%), 2738 in 2023 (+104%). DigiCert and Entrust shared the market. DigiCert built dominant share through enterprise PKI cross-sell; Entrust built depth in UK, India, Canada, and Italy through existing identity management relationships.
24
Late 2024 · New Entrants Arrive
GlobalSign issued its first BIMI certificate in 2024 (1 certificate — market testing). SSL Corp began its BIMI programme. The two-CA market began its transition to a four-CA market as Entrust’s issuance volumes started declining from their 1741-certificate 2024 peak.
25
2025 · Market Entry at Scale + Entrust Wind-Down
GlobalSign issued 202 BIMI certificates — a genuine market entry. SSL Corp issued 18 directly and began issuing under the Sectigo brand (207 total Sectigo certificates, with SSL Corp as Root CA). Entrust dropped from 1741 (2024) to 501 (2025) — a 71% decline consistent with wind-down as the CA business discontinuation was prepared.
26
2026 · Entrust Exits, Market Reshapes
Entrust discontinued its CA business — ceasing all public certificate issuance including BIMI certificates. Zero new Entrust BIMI certificates in 2026 YTD. DigiCert captures 85.4% of new issuances. GlobalSign and Sectigo absorb the remainder. 4431 Entrust certificate holders face migration ahead.

Section 02

The Entrust Exit — Impact on 4431 Active Certificate Holders

Why Entrust Exited the CA Market

In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances. Mozilla Firefox followed with an equivalent distrust decision. Because BIMI’s Verified Mark Certificate (VMC) and Common Mark Certificate (CMC) infrastructure depends on publicly-trusted Certificate Authority roots, this browser distrust decision effectively ended Entrust’s ability to issue any new BIMI certificates. Entrust’s last BIMI certificate was issued in May 2025 — a brief continuation period covering certificates in pipeline before the distrust became fully effective. As of the July 2026 dataset snapshot, only 0 Entrust BIMI certificates remain active globally; all expire by December 2026. No renewal path exists with Entrust. Holders must migrate to an active CA (DigiCert, GlobalSign, or Sectigo) before their certificate’s “Not After” date to avoid an inbox logo gap.

Entrust BIMI Issuances by Year — Foundation to Exit
Annual new Entrust BIMI certificate issuances · VMCcerts Research, 2026-07-02

Entrust’s discontinuation of its CA business is the most operationally significant event in the BIMI certificate market to date. As a founding CA that held 21.9% of all active BIMI certificates at peak, its exit leaves a substantial population of certificate holders requiring migration.

For All Entrust BIMI Certificate Holders

Your existing Entrust BIMI certificate remains valid until its printed expiry date. When that date arrives, Entrust will not issue a renewal certificate. You must migrate to an alternative CA — DigiCert, GlobalSign, or Sectigo — before your expiry date. Begin the migration process at least 60–90 days before expiry. The migration requires the new CA to independently validate your trademark or commercial use evidence.

CountryActive Entrust Certs% of Country BIMIMigration Priority
GB United Kingdom66338.1%Critical — 38.1% of UK market at risk
US United States180520.8%High volume — largest absolute exposure
IN India31733.7%High — BFSI concentration
CA Canada20730.9%High — confirm expiry dates now
IT Italy11638%High — begin migration planning
DE Germany22218.6%Moderate — monitor expiry schedule
AU Australia18522%Moderate
NL Netherlands11121.1%Moderate
FR France10716.1%Plan ahead
ES Spain9528.1%High — migration needed

Section 03

GlobalSign and Sectigo — The New Market Entrants

GlobalSign and Sectigo — 2026 YTD New BIMI Issuances by Country
Combined new entrant issuances Jan–Jul 2, 2026 · VMCcerts Research, 2026-07-02

GlobalSign

GlobalSign is a well-established global CA with decades of TLS and code-signing certificate history. Its BIMI programme launched properly in 2025 with 202 certificates — a deliberate market entry, not a pilot. In the first half of 2026 (January 1 – July 2) it has already issued 359 certificates, surpassing its full 2025 output. Japan (78) and the US (81) are its primary 2026 markets, with India (44), Australia (17), and Germany (15) following.

GlobalSign entered the BIMI market at a strategically advantageous moment — precisely as Entrust was winding down. Its enterprise PKI relationships in Japan (where it holds 19.5% of the country’s BIMI CA share) and India (8%) position it well to absorb displaced Entrust demand in those markets.

SSL Corp and the Sectigo Channel

SSL Corp operates as the Root CA for BIMI certificates issued under the Sectigo brand. This is a distribution architecture, not a separate CA: SSL Corp issues and roots the certificate; Sectigo operates as an intermediate CA brand and reseller channel. The two entities combined represent 330 active BIMI certificates — 123 direct SSL Corp issuances and 207 under the Sectigo brand.

Sectigo’s Background in BIMI

Sectigo’s BIMI certificate product was originally associated with DigiCert’s brand infrastructure before Sectigo’s separation and independent branding. The Sectigo BIMI product has since been restructured under SSL Corp’s Root CA infrastructure. When evaluating a Sectigo BIMI certificate, the Root CA in the certificate chain is SSL Corp — this is relevant for organisations conducting CA due diligence or verifying certificate chain trust.

The combined Sectigo 2026 YTD output of 295 certificates in the first half of 2026 (January 1 – July 2) represents a significant ramp from their 2025 entry. The US (110), India (47), and Canada (35) are their strongest 2026 markets, reflecting strong adoption across several English-speaking markets.

Section 04

2026 New Issuance Market — DigiCert’s Near-Monopoly

2026 YTD New BIMI Issuances by CA (Jan–Jul 2, 2026)
Flow share of new certs — not cumulative · VMCcerts Research, 2026-07-02
CACumulative Share (all time)2026 YTD Share (new only)Direction
DigiCert73.6%85.4%↑ Gaining rapidly
Entrust21.9%0%↓↓ Exited
GlobalSign2.8%7.9%↑ Expanding
Sectigo1.6%6.5%↑ Growing fast

In 2026, 85.4% of every new BIMI certificate issued goes through DigiCert. GlobalSign and Sectigo together account for the remaining 14.6%. The market has structurally shifted from a two-CA founding duopoly to a DigiCert-dominant market with two challenger entrants absorbing what growth they can capture from displaced Entrust demand and new adopters.

Expert Interpretation

VMCcerts Research Analysis

The founding duopoly shaped the ecosystem’s geographic and sector distribution

DigiCert and Entrust did not build identical customer bases. DigiCert’s enterprise PKI relationships ran deepest in US technology, German enterprise, and French financial services. Entrust’s ran deepest in UK financial services, India BFSI, Canadian public sector, and Italian retail. These relationship patterns are visible in the current CA market share by country — the UK’s 38.1% Entrust share and India’s 33.7% are direct legacies of Entrust’s enterprise identity management depth in those markets, not outcomes of BIMI product comparison.

Entrust’s exit was orderly and foreseeable from the data — the wind-down began in 2025

Entrust dropped from 1741 new BIMI certificates in 2024 to 501 in 2025 — a 71% decline. This was not a market share loss to competitors. It was a planned reduction consistent with an orderly CA business wind-down. Organisations that renewed Entrust certificates in 2025 likely received certificates with terms ending in 2026 or 2027 — these are the expiry events that certificate holders now need to plan around.

GlobalSign and Sectigo entered at exactly the right moment — the question is market capacity

With 4431 Entrust certificates requiring eventual migration and DigiCert already capturing 85.4% of new issuances, the question for GlobalSign and Sectigo is whether they can process migration volume at the scale that Entrust’s exit creates. Their combined 2026 YTD output of ~654 certificates suggests they are growing but not yet at replacement capacity for Entrust’s historical 1741+ annual run rate. DigiCert will absorb the majority of Entrust migrations.

FAQ

Frequently Asked Questions

My Entrust BIMI certificate is still working. Why do I need to plan migration now?

Your certificate is valid until its printed expiry date regardless of Entrust's CA status. The migration is needed because when that date arrives, there is no renewal path through Entrust. A BIMI certificate expiry means immediate loss of your verified inbox logo — with no grace period. The migration to an alternative CA (DigiCert, GlobalSign, or Sectigo) must be completed before your expiry date. Beginning 60–90 days before expiry gives you adequate time for trademark revalidation, new certificate issuance, and DNS update.

What is the relationship between Sectigo and SSL Corp in BIMI certificates?

SSL Corp operates as the Root CA — the trust anchor — for BIMI certificates issued under the Sectigo brand. Sectigo functions as an intermediate CA and reseller channel within SSL Corp's certificate infrastructure. When you examine a Sectigo BIMI certificate's chain of trust, the Root CA is SSL Corp. This arrangement is similar to how many large certificate distribution businesses work: a channel brand sells under its own name while the underlying cryptographic trust derives from a different Root CA.

Can I migrate from Entrust to GlobalSign or SSL Corp instead of DigiCert?

Yes. Any of the three active CAs — DigiCert, GlobalSign, and Sectigo — can issue a replacement BIMI certificate after independently validating your trademark (VMC) or commercial use evidence (CMC). The validation process is CA-specific but broadly similar in requirements across all three. GlobalSign has demonstrated particular strength in Japan, India, and Australia markets; Sectigo has been more focused on the US, Canada, and UK. Compare pricing, support quality, and account management capability alongside product eligibility when selecting a replacement CA.

When will Entrust certificates start expiring in volume?

Entrust's 2025 issuances (501 certificates) began reaching their 13-month terms in early-to-mid 2026. The dataset's visible expiry data for Entrust shows only June 2026 (19 certificates) — most Entrust expiry data is in the metadata of certificates issued across 2023 and 2024. The 1741 certificates from 2024 will expire across 2025–2026; the 501 from 2025 across 2026–2027. Certificate holders should check their specific expiry date directly from their certificate file or their CA dashboard.
CA Migration Support
VMCcerts supports Entrust certificate holders through migration to DigiCert, GlobalSign, or Sectigo — including trademark revalidation preparation, CA evaluation, and gap-free transition planning.
Cite This Report



VMCcerts Research. (2026). BIMI CA Landscape and Migration Patterns 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/bimi-ca-migration-patterns-2026
VMCcerts Research. “BIMI CA Landscape and Migration Patterns 2026.” VMCcerts, 2026, https://vmccerts.com/research/bimi-ca-migration-patterns-2026.
@techreport{vmccerts2026CAMigrationPatterns,
author = {VMCcerts Research},
title = {BIMI CA Landscape and Migration Patterns 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/bimi-ca-migration-patterns-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – BIMI CA Landscape and Migration Patterns 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/bimi-ca-migration-patterns-2026
ER –