Overview
Entrust was founded in 1994, headquartered in Minneapolis, Minnesota, USA. It is a globally recognized PKI security solutions provider and one of the longest-operating commercial Certificate Authorities. The Entrust SSL product line leverages over 25 years of PKI expertise — all SSL/TLS certificates are issued via FIPS 140-2 Level 3 certified nShield Hardware Security Modules (HSM), achieving the highest key protection standards in the industry. The product portfolio covers DV, OV, EV, Wildcard, and Multi-Domain certificates, with the Entrust Certificate Services (ECS) platform providing full lifecycle automation. Entrust serves more than 150 countries and has a deep customer base in government and financial sectors.
Entrust corporation See the corporation page for details. More SSL Certificate providers available on the category page.
Key Strengths
- FIPS 140-2 HSM Issuance: All certificates issued via FIPS 140-2 Level 3 certified nShield HSM — key generation, storage, and usage occur within tamper-resistant hardware, far surpassing software-only security
- 25+ Years of PKI Leadership: Operating PKI services since 1994, one of the oldest CAs with hundreds of millions of certificates issued and unmatched technical maturity
- ECS Automation Platform: Entrust Certificate Services provides RESTful APIs for certificate ordering, issuance, renewal, and revocation, enabling enterprises to reduce manual operations by over 60%
- Government & Finance Compliance: Simultaneously meets US FIPS standards, EU eIDAS regulations, and CA/Browser Forum baseline requirements — the compliance-first choice for SSL procurement
Product Ecosystem
- Entrust Certificate Services (ECS) : Enterprise certificate management platform supporting SSL/TLS, code signing, document signing, and email certificates with unified management, RESTful APIs, and automated policy configuration
- nShield HSM: Entrust's hardware security module product line offering FIPS 140-2 Level 3/4 certified key protection hardware, providing a physical security foundation for certificate issuance
- IoT Device Certificates: Device identity authentication solutions for IoT scenarios, supporting mass automated certificate enrollment, renewal, and revocation
- PKI as a Service: Entrust Cloud PKI enables organizations to obtain complete public key infrastructure without building their own CA, reducing operational complexity
Limitations
- Premium Pricing: OV certificates $400-$800/year, EV certificates up to $1,000-$2,000/year — less competitive on price compared to Sectigo and similar alternatives
- Limited China Presence: Brand recognition in China lags behind DigiCert and Sectigo, with fewer local channel partner resources
- English-Dominant Support: ECS management console and official documentation are primarily in English; Chinese-language support and technical documentation coverage need improvement
Use Cases
- Government & Public Sector (★★★★★): FIPS 140 compliance meets highest government security audit requirements; ECS platform enables centralized management
- Financial Institutions & Banks (★★★★★): High-frequency trading and online banking demand extreme key security, with nShield HSM providing hardware-level protection
- Multinational Compliance Deployments (★★★★): For organizations requiring both FIPS and eIDAS compliance, Entrust is one of the few CAs that satisfies both standards
- Personal or Small Websites (★★): Higher entry pricing; consider Let's Encrypt for free or low-cost alternatives
Pricing
| Certificate Type | Annual Price (Reference) | Key Features |
|---|---|---|
| DV SSL | $200-$400/year | Domain validation, auto-issuance, basic encryption |
| OV SSL | $400-$800/year | Organization validation, FIPS HSM issuance, business websites |
| EV SSL | $1,000-$2,000/year | Extended validation, green address bar, high-trust scenarios |
| Wildcard SSL | $600-$1,200/year | Protects primary domain and all subdomains |
| Multi-Domain SSL | Priced per domain | Single certificate covering multiple domains, managed via ECS |
Prices are for reference only. Actual pricing may vary based on promotions, channel partnerships, and volume discounts.
FAQ
- How does Entrust SSL relate to Entrust the company? Entrust SSL is the SSL/TLS certificate product line of Entrust, part of a complete digital security ecosystem alongside nShield HSM and PKI services. See Entrust corporation.
- What makes Entrust's HSM issuance better than other CAs? Entrust uses its own nShield HSM for certificate issuance, with keys generated and stored in FIPS 140-2 Level 3 certified hardware, providing physical isolation superiority over CAs relying on third-party HSMs; see CDN and SSL/TLS configuration best practices.
- Does ECS support automatic certificate renewal? Yes. ECS provides RESTful APIs and automated policy configuration to enable pre-expiry auto-renewal and redeployment, significantly reducing manual maintenance costs; see CDN and SSL/TLS configuration best practices.
- How to purchase Entrust SSL certificates in China? Purchase directly from Entrust's website or through authorized partners like 16IDC for Chinese-language purchasing guidance and technical support; see CDN and SSL/TLS configuration best practices.