Overview

Founded in 1994 and headquartered in Minneapolis, Minnesota, USA, Entrust is a global leader in enterprise digital security and SSL certificate and Public Key Infrastructure (PKI) solutions. Originally operating as the security division of the Royal Bank of Canada before spinning off independently, Entrust has grown into a digital security company with annual revenue exceeding $350 million, serving over 10,000 enterprise clients across government, finance, healthcare, and manufacturing sectors.

Entrust's core offerings include SSL/TLS certificates, Hardware Security Modules (HSM), digital signatures, document signing, and IoT certificate management. In the SSL certificate space, Entrust is one of the few providers capable of both building PKI infrastructure and issuing end-entity certificates. Its nShield HSM product line has over 20 years of deployment experience in banking and government markets.

Key Strengths

  • Full-Stack PKI Solutions: Entrust delivers end-to-end PKI services from Certificate Authority (CA) deployment and key lifecycle management to encryption gateways. Its PKI platform handles over 5,000 OCSP queries per second with a 99.99% service availability SLA, providing a reliable foundation for enterprise PKI deployments.
  • Financial-Grade HSM Security: The nShield HSM series is certified to FIPS 140-2 Level 3 and Common Criteria EAL4+, with keys stored in tamper-resistant hardware. Widely deployed in banking transaction systems, payment card data protection, and government digital identity projects. Combined with security strategies, it builds multi-layer encryption trust frameworks.
  • Complete SSL/TLS Coverage: Offers DV, OV, EV, Wildcard, and Multi-Domain (SAN/UCC) certificates. All root certificates are pre-installed in major browsers with 99%+ compatibility. See SSL certificate type comparison for guidance.
  • Mature Digital Signing Ecosystem: Entrust signing solutions are included in Adobe Approved Trust List (AATL) and EU eIDAS trusted lists, supporting PDF document signing, code signing, and e-seals, processing over 1 million signing requests daily. Ideal for e-contracts, software distribution, and government document workflows.
  • Large-Scale IoT Certificate Management: Provides automated certificate enrollment, renewal, and revocation APIs for IoT scenarios, managing over 5 million certificates for connected cars, industrial sensors, and smart home devices. Supports MQTT and TLS mutual authentication.

Product Ecosystem

SSL/TLS Certificates

Entrust offers QuickSSL Premium (DV), True BusinessID (OV), Extended Validation (EV), Wildcard, and Multi-Domain certificate series. DV issuance in minutes, OV in 1-3 business days, EV in 1-5 business days. All certificates are compatible with 99%+ of browsers and mobile devices.

nShield HSM Hardware Security Module

The nShield series includes Solo (standalone), Connect (network-connected), and as a Service (cloud) deployment models. FIPS 140-2 Level 3 certified, providing financial-grade key storage and protection. Deployed in banking transaction systems, payment processing, digital identity, and code signing scenarios.

Entrust Signature Suite

Unified digital signature management platform supporting PDF document signing, code signing, and e-seals. Included in AATL and eIDAS trusted lists, integrating seamlessly with Adobe Acrobat and Microsoft Office. Suitable for e-contract approval workflows, software distribution signing, and government document authentication.

Entrust IoT Security

Certificate lifecycle management solution for IoT devices supporting auto-enrollment, bulk issuance, renewal, and revocation. Over 5 million IoT devices authenticated, supporting connected vehicle V2X communications, industrial sensor authentication, and smart home device identity management.

Limitations

  • High Enterprise Pricing: Entrust EV certificates typically cost $200-$800/year per certificate, approximately 30%-50% more than comparable products from Sectigo — a significant expense for budget-conscious SMBs.
  • Complex Management Backend: The PKI management console integrates CA management, HSM configuration, and signing policies — initial deployment generally requires dedicated training or experienced technical personnel, with a steep learning curve.
  • Poor Value for Individuals & Small Teams: The entry-level DV certificate starts at ~$80/year with no free auto-issuance option like Let's Encrypt. For personal blogs or small static sites, this represents significant over-provisioning and high cost.
  • No Refund Policy: Once issued, Entrust certificates are generally non-refundable. Buyers should use the online certificate compatibility checker before purchasing to avoid compatibility issues.

Use Cases

  • Government & Public Sector (★★★★★): Entrust holds federal PKI credentials from the U.S. government and multiple national trust roots, making it a preferred choice for government digital identity systems. Pair with CDN acceleration for nationwide HTTPS optimization.
  • Financial Institutions (★★★★★): nShield HSM has over 20 years of deployment experience in banking transaction encryption and payment card data protection, meeting PCI DSS and SOX compliance.
  • Large Enterprise PKI Deployments (★★★★☆): Suitable for enterprises needing to build or outsource PKI infrastructure, supporting private CAs, policy engines, and multi-tier certificate management.
  • Code/Document Signing Teams (★★★★☆): Direct AATL and eIDAS integration makes Entrust a strong choice for software distribution and e-contract workflows.
  • Personal Sites / Small Projects (★★☆☆☆): Poor value proposition; consider Let's Encrypt (free) or Sectigo (entry-level ~$30/year) instead.

Pricing

Certificate Type Product Annual Fee (approx.) Highlights
DV QuickSSL Premium $80 Single domain, minutes issuance
OV True BusinessID $200 Includes organization validation
EV Extended Validation $400-$800 Green address bar, highest trust
Wildcard QuickSSL Wildcard $350 Domain + all subdomains
Multi-Domain True BusinessID Multi-Domain $300 Supports 3-100 domains

Prices are estimated retail; actual costs may vary due to promotions or volume discounts.

FAQ

  • How is Entrust different from regular SSL certificate providers? Entrust offers not just SSL/TLS certificates but complete PKI infrastructure and HSM hardware, covering security needs from cryptographic algorithms to physical hardware. Its nShield HSM is a core product for banking and government markets; see CDN and SSL/TLS configuration best practices.
  • Which browsers trust Entrust certificates? Entrust root certificates are pre-installed in all major browsers including Chrome, Firefox, Safari, Edge, and mobile browsers, with over 99% compatibility. Verify compatibility using Entrust's online certificate checker; see CDN and SSL/TLS configuration best practices.
  • Does Entrust support automated certificate management? Yes. Entrust supports the ACME protocol and RESTful APIs for automated DV certificate enrollment, validation, and renewal, suitable for DevOps environments. See SSL certificate management best practices for guidance.
  • Who should use Entrust's HSM products? Primarily banks, government agencies, payment processors, and large cloud providers requiring FIPS or Common Criteria certified key security. nShield HSM supports Solo, Connect, and cloud service deployment models; see website security best practices.