# Cyber Company Profiles: Entrust

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-10
Canonical: https://cybercompanyprofiles.com/companies/entrust
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Entrust, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [entrust.com](https://www.entrust.com)
- Profile: https://cybercompanyprofiles.com/companies/entrust
- Type: Identity Access, Data Security
- Also known as: Entrust Corporation, Entrust Datacard
- Market readiness: Established (30/40)
- Defensibility: Contested (14/21)
- Founded: 1969
- Last updated: 2026-09-10

## Executive Summary

Entrust sells hardware security modules that protect cryptographic keys, private certificate authority software, identity verification, and card and ID issuance to governments, banks, and enterprises. Founded in 1969, it is a private company. TechCrunch reported in 2024 revenue just under $1 billion, profitability, and about 10,000 customers. Chrome, Google's browser, stopped trusting new Entrust website certificates in 2024 after reported compliance failures. Entrust sold that business to Sectigo in 2025 and no longer issues public certificates. Analyst firm KuppingerCole places it among 13 vendors in the top tier of its enterprise passwordless authentication report. Its position is strongest with government and bank customers and in its NIST-validated hardware security modules.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Entrust sells digital security hardware and software, spanning identity verification and authentication, card and ID issuance, certificate and key lifecycle management, hardware security modules, and post-quantum cryptography. The company is privately held. | [\[f1\]](#company-detail-sources) |
| Founded | 1969 | [\[f2\]](#company-detail-sources) |
| HQ | Shakopee, Minnesota, United States | [\[f1\]](#company-detail-sources) |
| Latest funding | Privately held by Datacard Group (acquired Entrust in 2013), with no outside venture funding and reported profitability | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| nShield HSMs | Hardware security modules that provide a FIPS-certified, tamper-resistant root of trust for generating, protecting, and managing cryptographic keys. |
| PKI and Certificate Lifecycle Management | Software for running private and managed certificate authorities and for discovering, managing, and automating keys, certificates, and secrets across an enterprise. |
| Identity Verification | AI-powered document, biometric, and data checks (built on the acquired Onfido technology) that confirm customer, citizen, and employee identities at onboarding. |
| Card and Credential Issuance | High-volume hardware, software, services, and supplies (the Datacard product line) for issuing physical and digital payment cards, national IDs, and other secure credentials. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Data | ✓ | ✓ |  |  |  |
| Devices | ✓ | ✓ |  |  |  |
| Users | ✓ | ✓ |  |  |  |
| Applications |  | ✓ |  |  |  |

Entrust issues credentials and payment cards, runs private and managed certificate authorities, provides FIPS-certified HSMs that anchor cryptographic keys, and verifies human identities at onboarding, defending data, device, user, and application trust, and is mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (30/40)**

Analyzed 2026-07-09. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | Entrust names a precise buyer and problem, securing the identity lifecycle from onboarding through key and certificate management, and the pain is corroborated by non-vendor evidence: Google's 2024 distrust showed how fragile certificate trust is, NIST's finalized post-quantum standards signal a transition the sector must begin, and the CA/Browser Forum governs the category. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s16](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The portfolio carries detailed product pages plus an independent external validation point: NIST validated the nShield 5s hardware security module under its Cryptographic Module Validation Program, and named deployments such as ZF Friedrichshafen appear. Direct peers like Thales hold comparable FIPS-certified HSM and key-management depth and DigiCert comparable PKI and public-CA depth, so this is differentiated and corroborated rather than validated at a level peers fail to match. \[[s14](#profile-analysis-sources), [s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Market Timing | 4/5 | Multiple buyer-side drivers are active within the window: NIST finalized post-quantum encryption standards in 2024 and urged administrators to begin transitioning, and KuppingerCole's coverage of enterprise passwordless authentication marks active demand in an analyst-recognized category Entrust serves. \[[s16](#profile-analysis-sources), [s13](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Leadership is verifiable and domain-matched, with CEO Tony Ball drawn from HID Global and Gemalto, but the public certificate-authority compliance failures that Google cited as eroding confidence in Entrust's competence and integrity are a credibility scar that holds the score at the experienced-but-unproven level. \[[s5](#profile-analysis-sources), [s9](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Traction is multiply sourced: TechCrunch reports, citing the company, profitability with revenue near a billion dollars and about 10,000 customers, KuppingerCole independently names it an Overall Leader in passwordless authentication, and named deployments such as ZF Friedrichshafen appear. The public-CA customer exodus holds it short of the top score. \[[s12](#profile-analysis-sources), [s13](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Funding Efficiency | 4/5 | Entrust reported through TechCrunch in 2024 sustained profitability and revenue near a billion dollars, and as a private, family-owned company it has absorbed four acquisitions including Onfido while shipping a broad portfolio at scale. The figures are company-reported rather than audited, and the public certificate line was divested after the browser distrust, which keep efficiency from the independently confirmed 5. \[[s12](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Identity verification, PKI, HSMs, and credential issuance are established categories buyers place without coaching, and KuppingerCole independently names Entrust an Overall Leader while the CA/Browser Forum lists it as a member, multiply evidenced. Entrust is one of several named leaders rather than a category definer, so 4 not 5, level with Thales and DigiCert. \[[s13](#profile-analysis-sources), [s17](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | The NIST-validated nShield hardware and PKI roots create real switching friction a newcomer cannot quickly replicate, but cloud providers bundle certificate and key management below Entrust and identity platforms fold verification above it, and the 2024 distrust stripped the browser-root moat that DigiCert still holds at 4, so the position is adequately defended rather than structurally moated. \[[s14](#profile-analysis-sources), [s9](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |

### Business Risks

- The browser-distrust episode could keep dragging on the brand even though the public certificate authority was sold, deterring buyers of the surviving private PKI, HSM, and identity lines.
- Cloud providers and identity platforms reaching the same regulated buyers could bundle certificate, key, and verification management, compressing Entrust's standalone value.
- Onfido's identity-verification business could underperform its acquisition price if integration stalls or AI-driven fraud outpaces detection.
- The December 2025 nShield vulnerability NVD documents (CVE-2025-59702) could force firmware remediation discipline, and a missed update would undercut the hardware trust Entrust sells.

### Problem & Market

Entrust sells trust to compliance-driven institutions, and it defines the problem precisely. Its pitch is that identity is the common thread across fraud and cyber threats, and it secures every step of the identity lifecycle, from verifying a person at onboarding to managing the keys and certificates behind machine connections.

Independent evidence corroborates the pain at scale. NIST finalized its first post-quantum encryption standards in 2024 and urged administrators to begin transitioning, a dated signal that regulated organizations must start inventorying and replacing quantum-vulnerable cryptography before harvest-now-decrypt-later attacks mature. The same period exposed how fragile certificate trust is, when Google stopped trusting Entrust's newly issued public certificates over what it called a pattern of concerning behaviors. Both pressures land in the finance, technology, and government budgets Entrust targets. \[[s1](#profile-analysis-sources), [s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Product Capabilities

Entrust runs an unusually broad trust stack for one vendor. The nShield hardware security modules provide a FIPS-certified root of trust, the PKI line runs private and managed certificate authorities with certificate lifecycle management, identity verification built on the acquired Onfido technology applies document, biometric, and data checks, and the Datacard line issues physical and digital cards and government credentials.

Depth is evidenced beyond marketing. NIST validated the nShield 5s hardware security module under its Cryptographic Module Validation Program, an independent FIPS check a newcomer cannot quickly pass, and the HSM and PKI product pages carry technical detail with named deployments such as ZF Friedrichshafen.

The newest direction is post-quantum cryptography, which Wikipedia lists among Entrust's capabilities. NIST finalized the quantum-safe standards in 2024, and the estate-wide migration they set in motion is the kind of cryptographic change the HSM and PKI lines are built to manage. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s14](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Competitive Positioning

Entrust competes on breadth and on a hardware root of trust it manufactures. In PKI and machine identity it overlaps with Keyfactor and Thales, both rivals in hardware security modules and certificate management, and with DigiCert, the public certificate authority that still holds the browser-root position Entrust lost. In identity and access it sits adjacent to CyberArk and Okta, which reach the same regulated buyers from the access-management side.

The competitive risk is absorption from both directions. Cloud providers bundle basic certificate and key management beneath Entrust, and identity platforms fold verification and authentication into suites above it. The breadth that differentiates Entrust also means no single line is insulated from a platform vendor deciding to bundle it. \[[s8](#profile-analysis-sources), [s9](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Go-to-Market & Traction

Go-to-market reaches enterprise and government buyers at scale. TechCrunch reported in 2024 that the privately held company was profitable, with revenue near a billion dollars and about 10,000 customers, a base a younger rival cannot quickly assemble.

Independent recognition reinforces the traction. KuppingerCole named Entrust an Overall Leader in passwordless authentication for enterprises, and the nShield HSM line shows named deployments such as ZF Friedrichshafen securing manufacturing.

The Onfido purchase shows how Entrust buys into adjacent demand through acquisition. The deal added an identity-verification business with its own customers, which expands reach but raises the integration and retention questions that come with absorbing an acquired motion. \[[s12](#profile-analysis-sources), [s13](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Team & Credibility

Entrust leadership is experienced and domain-matched. CEO Tony Ball, who took the role in 2026, joined Entrust in 2016 and brings more than two decades of leadership across identity and security technologies after senior roles at HID Global and Gemalto.

The team's record is operating an at-scale, multi-line security business rather than a marquee startup exit. Entrust has acquired nCipher, HyTrust, WorldReach, and Onfido while running issuance and cryptography lines across regulated markets.

The credibility complication is the public certificate-authority failure. Google attributed its distrust to a pattern of compliance failures and withdrew the trust of its root program, and for a vendor whose product is trust, that withdrawal is a mark the leadership now works back from. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s9](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Trust Readiness

Entrust holds genuine product-level security credentials. NIST validated the nShield 5s hardware security module under its Cryptographic Module Validation Program, the kind of independent FIPS check regulated buyers require and a determined newcomer cannot quickly satisfy.

Against that, the 2024 distrust of Entrust's newly issued public TLS certificates, which Google set in motion over a pattern of compliance failures, is the rare case of a trust vendor losing the trust of the programs that govern certificate trust. Entrust sold that public certificate business to Sectigo, which by its own account migrated more than half a million certificates away, and the remaining identity, PKI, and HSM lines now carry the burden of proving they were never the part in question.

A security review should also weigh recently disclosed nShield vulnerabilities. NVD documents CVE-2025-59702, a December 2025 issue in the nShield Connect XC, 5c, and HSMi that lets a physically proximate attacker with elevated privileges falsify tamper events, so physical custody and firmware currency belong in the buyer's diligence. \[[s14](#profile-analysis-sources), [s9](#profile-analysis-sources), [s11](#profile-analysis-sources), [s15](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Keyfactor | competes with |  |
| Thales | competes with |  |
| DigiCert | competes with |  |
| CyberArk | adjacent |  |
| Okta | adjacent |  |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-09-10. Scope: whole company.

Entrust holds its position through who buys it and how hard its core is to build, not through proprietary data, which the cited record does not document. About 10,000 customers include governments and major banks, where procurement can add replacement friction. Running FIPS-certified hardware and certificate authorities takes years of engineering, and a customer that roots trust chains in nShield hardware faces reissuance work on exit the cited record does not size. Its compliance standing is real but not absolute. The 2024 browser distrust of Entrust public certificates, since sold to Sectigo, showed Google can withdraw trust from even a long-held position. Identity verification and card issuance are weaker, because platforms could bundle them, which the cited record does not document.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | The core HSM and on-prem PKI lines are software and hardware customers configure and operate themselves, and they pay for those capabilities rather than a managed-judgment service that accepts accountability, though Entrust also sells managed PKI, PKIaaS, and verification services alongside the self-operated core. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Switching Cost | 2/3 | A customer that runs its certificate authorities and machine identities on Entrust PKI and NIST-validated nShield hardware has to reissue those credentials and re-establish the trust chains on a replacement. The cited record documents the mechanism but does not size the exit, so the documented case is meaningful friction, not a genuinely expensive migration. \[[s14](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | Entrust ships NIST-validated FIPS hardware, an independently audited cryptographic-module business, and sits among the CA/Browser Forum members that set public-certificate rules, but the 2024 browser distrust of its public roots shows the posture is not the absolute liability gate a 3 would need. \[[s14](#deep-dive-sources), [s17](#deep-dive-sources), [s9](#deep-dive-sources), [s10](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | FIPS-certified hardware security modules, certificate authorities at scale, and a post-quantum migration demand security-critical hardware and distributed-systems engineering that takes years of specialized expertise, underlined by the physically-proximate hardware flaw NVD disclosed in CVE-2025-59702. \[[s14](#deep-dive-sources), [s15](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | Entrust has sold to governments and regulated financial institutions at scale, with TechCrunch reporting in 2024 about 10,000 customers including governments and major banks, where procurement and legal gate any replacement, clearing the regulated-buyer bar. \[[s12](#deep-dive-sources)\] |
| Layer | 2/3 | The nShield HSMs and PKI sit in the trust path other systems depend on, but the whole-company offering also spans identity verification and card issuance that act as application-layer services on top, so the blended position is a platform with application features rather than pure infrastructure. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The acquired Onfido verification line may benefit from fraud-signal learning across document and biometric checks, but the cited material documents no named, non-public corpus, so the data posture sits at the reproducible level. \[[s12](#deep-dive-sources), [s4](#deep-dive-sources)\] |

### Strategic Market Segmentation

Entrust sells to compliance-driven institutions that must prove identity and protect cryptographic trust across people, data, and machines. The buyer is the security, identity, or payments leader in finance, technology, and government, and the pain is concrete: onboarding a person without letting fraud through, issuing credentials at national scale, and keeping every machine connection trusted as certificates and keys multiply.

The segment skews to large regulated organizations. TechCrunch reported in 2024 about 10,000 customers including governments and major banks, the accounts where procurement and audit gate any change to trust infrastructure.

The post-quantum transition widens the same segment rather than replacing it. NIST finalized its first post-quantum encryption standards in 2024 and urged administrators to begin transitioning, which reframes the existing cryptography buyer as the same leader now accountable for a migration across the estate. \[[s1](#deep-dive-sources), [s12](#deep-dive-sources), [s16](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Entrust spans an unusually broad trust stack for one vendor. The nShield hardware security modules provide a FIPS-certified root of trust, the PKI line runs private and managed certificate authorities with certificate lifecycle management, identity verification applies document, biometric, and data checks, and the Datacard line issues physical and digital cards and government credentials.

The capability that ties to the AI framing is identity verification built on the acquired Onfido technology. Entrust markets AI-powered checks that return results within seconds, the part of the portfolio where a data advantage could in principle compound, though the cited material documents no such corpus.

The newest direction is post-quantum cryptography, which Wikipedia lists among Entrust's capabilities. NIST validated the nShield 5s under its Cryptographic Module Validation Program and finalized the quantum-safe standards in 2024, the estate-wide migration the HSM and PKI lines are built to manage. \[[s4](#deep-dive-sources), [s8](#deep-dive-sources), [s14](#deep-dive-sources), [s16](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Go-to-market reaches enterprise and government buyers at scale. TechCrunch reported in 2024 the privately held company carried revenue near a billion dollars and about 10,000 customers including governments and major banks.

Named deployments and independent recognition anchor the traction. ZF Friedrichshafen uses nShield HSMs to protect manufacturing, and KuppingerCole named Entrust an Overall Leader in passwordless authentication for enterprises.

The Onfido purchase shows how Entrust buys into adjacent demand through acquisition. The deal added an identity-verification business with its own customers, which expands reach but raises the integration and retention questions that come with absorbing an acquired motion. \[[s12](#deep-dive-sources), [s13](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Pricing Model

Entrust sells into negotiated enterprise and government agreements rather than published list pricing. The reviewed product pages market HSMs, PKI, verification, and issuance without dollar figures, which signals a sales-led motion aimed at large deals whose scope depends on which lines a buyer adopts.

How the unit of value differs by line is unverified inference from category convention, because the reviewed pages document no meters: hardware security modules tend to price on appliances and capacity, verification on transactions, and issuance on credential volume. On that reading a buyer assembling several Entrust lines would negotiate across distinct meters rather than one seat count.

The absence of published pricing fits the category and the buyer. Trust infrastructure and credential issuance are bought by regulated institutions through procurement, so a negotiated quote is the norm, though it offers an outside reader no forecastable per-unit benchmark. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Product Delivery & Operations

Entrust delivers across the deployment shapes its regulated buyers require, from on-premises hardware to managed and cloud services. The nShield HSMs are physical appliances customers install, the PKI line offers a software appliance and managed certificate authorities, and verification runs as a service that returns results within seconds.

The operational core is that Entrust becomes part of the trust path. A certificate authority and the hardware that anchors keys issue the credentials production systems depend on, so a careful security review will probe availability, disaster recovery, and the integrity of the issuance pipeline before rooting trust in it.

The 2024 distrust episode is the operational cautionary tale. Google attributed the distrust to a pattern of compliance failures in the certificate-authority practice, the standard a buyer will hold the surviving lines to. \[[s4](#deep-dive-sources), [s9](#deep-dive-sources), [s7](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Earning Customers' Trust

Entrust holds genuine product-level security credentials. NIST validated the nShield 5s hardware security module under its Cryptographic Module Validation Program, the kind of independent FIPS check regulated buyers require, and Entrust remains among the CA/Browser Forum members that govern public-certificate standards.

The complication is that a trust vendor lost the trust of the programs that govern certificate trust. Google distrusted Entrust public TLS certificates in 2024 over a pattern of compliance failures, and Entrust sold that public certificate business to Sectigo, so the remaining identity, PKI, and HSM lines now carry the burden of proving they were never the part in question.

A security review should also weigh recently disclosed hardware issues. NVD documents CVE-2025-59702, a December 2025 issue in the nShield Connect XC, 5c, and HSMi that lets a physically proximate attacker with elevated privileges falsify tamper events, so physical custody and firmware currency belong in the buyer's diligence. \[[s14](#deep-dive-sources), [s9](#deep-dive-sources), [s10](#deep-dive-sources), [s15](#deep-dive-sources), [s17](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Entrust positions as the place regulated buyers manage trust across people, data, and machines rather than a feature inside one cloud's identity service. The HSMs anchor keys other systems rely on, the PKI line issues the certificates those systems present, and verification confirms the humans behind them, so several lines reinforce one identity-centric pitch.

The breadth was assembled partly through acquisition. nCipher brought the HSM line, HyTrust added data security, and Onfido added verification, so the platform consolidates capabilities a typical enterprise would otherwise buy from several vendors, at the cost of integrating distinct acquired products.

The competitive exposure is absorption from both directions. Cloud providers could bundle certificate and key management beneath Entrust, and identity platforms could fold verification and authentication into suites above it, though the reviewed record does not document such bundled offerings. The 2024 loss of its public roots shows that even a long-held trust position can be withdrawn, so no single line is insulated from a platform vendor deciding to bundle it. \[[s8](#deep-dive-sources), [s9](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Team & Execution Capability

Entrust leadership is experienced and domain-matched. CEO Tony Ball, who took the role in 2026, joined Entrust in 2016 and brings more than two decades of leadership across identity and security technologies after senior roles at HID Global and Gemalto.

The team's track record is operating an at-scale, multi-line security business rather than a marquee startup exit. Entrust has acquired nCipher, HyTrust, WorldReach, and Onfido while running issuance and cryptography lines across regulated markets.

The credibility complication is the public certificate-authority failure. Google attributed its distrust to a pattern of compliance failures that withdrew the trust of its root program, a mark the leadership now works back from while integrating Onfido. \[[s5](#deep-dive-sources), [s8](#deep-dive-sources), [s9](#deep-dive-sources), [s10](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Wikipedia: Entrust company overview](https://en.wikipedia.org/wiki/Entrust) | research | 2026-06-21 |
| f2 | [Entrust Datacard becomes Entrust (company heritage)](https://www.entrust.com/company/newsroom/entrust-datacard-becomes-entrust) | official | 2026-06-21 |
| f3 | [TechCrunch: Entrust private ownership, revenue, and profitability](https://techcrunch.com/2024/02/06/confirmed-entrust-is-buying-ai-based-id-verification-startup-onfido-sources-say-for-more-than-400m/) | press | 2026-06-28 |
| f4 | [Entrust identity-centric security solutions](https://www.entrust.com/solutions) | official | 2026-06-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Entrust homepage identity-centric security](https://www.entrust.com) “Identity-Centric Security ... Protecting People, Devices, and Data” | official | 2026-06-28 |
| s2 | [Entrust nShield hardware security modules](https://www.entrust.com/products/hsm) “Comprehensive FIPS-certified HSM solutions for enterprise cryptographic security. ... ZF Friedrichshafen AG Secures Wireless Manufacturing with Entrust nShield HSMs” | official | 2026-06-28 |
| s3 | [Entrust PKI software solutions](https://www.entrust.com/products/pki) “All-in-one software-based PKI appliance for simplified, scalable, and secure PKI management.” | official | 2026-06-28 |
| s4 | [Entrust identity verification solutions](https://www.entrust.com/products/identity-verification) “Onboard customers, employees, and contractors faster with AI-powered identity verification that returns results within seconds.” | official | 2026-06-28 |
| s5 | [Entrust leadership team and CEO Tony Ball](https://www.entrust.com/company/leadership) “Tony Ball is the Chief Executive Officer of Entrust ... Tony brings more than two decades of global leadership experience across identity, authentication, and security technologies. Since joining Entrust in 2016 ... Tony held senior executive roles at HID Global and Gemalto” | official | 2026-06-28 |
| s6 | [Entrust: Restoring Trust after the Chrome distrust decision](https://www.entrust.com/blog/2024/07/restoring-trust-an-update-on-our-progress) “We are committed to restoring trust with the browser and web community and returning to the Chrome Root Store.” | official | 2026-06-28 |
| s7 | [Entrust completes Onfido acquisition](https://www.entrust.com/company/newsroom/entrust-completes-acquisition-of-onfido-creating-a-new-era-of-identity-centric-security) “Entrust, a global leader in trusted payments, identities, and data security, today announced it completed its acquisition of Onfido, a global leader in identity verification.” | official | 2026-06-28 |
| s8 | [Wikipedia: Entrust company overview and acquisition history](https://en.wikipedia.org/wiki/Entrust) “Entrust operated a publicly trusted certificate authority until selling its public certificate business to Sectigo in January 2025. Notable acquisitions include nCipher (2019), HyTrust (2021), WorldReach (2021), and Onfido (2024).” | research | 2026-06-28 |
| s9 | [Google Online Security Blog: Entrust Certificate Distrust](https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html) “Over the past several years, publicly disclosed incident reports highlighted a pattern of concerning behaviors by Entrust that fall short of the above expectations, and has eroded confidence in their competence, reliability, and integrity as a publicly-trusted CA Owner.” | press | 2026-06-28 |
| s10 | [Infosecurity Magazine: Chrome Update Will Block Entrust Certificates by November 2024](https://www.infosecurity-magazine.com/news/chrome-update-will-block-entrust/) “Chrome version 127 and higher will no longer trust new TLS server authentication certificates from Entrust and AffirmTrust. The move follows a series of reported compliance failures, unfulfilled improvement commitments and insufficient progress in addressing publicly disclosed incident reports.” | press | 2026-06-28 |
| s11 | [MES Computing: Sectigo Completes Entrust Certificate Migration Following Acquisition](https://www.mescomputing.com/news/security/sectigo-completes-entrust-certificate-migration-following-acquisition) “Sectigo called the migration the "largest-ever automated migration of public certificate infrastructure," saying it had migrated more than a half-million certificates.” | press | 2026-06-28 |
| s12 | [TechCrunch: Entrust buying Onfido, with revenue, profitability, and ownership detail](https://techcrunch.com/2024/02/06/confirmed-entrust-is-buying-ai-based-id-verification-startup-onfido-sources-say-for-more-than-400m/) “Entrust itself is profitable, and it has been for a number of years, and it currently has "just under $1 billion" in revenue annually with about 10,000 customers ... It has no shareholders as such and is privately owned by a German family” | press | 2026-06-28 |
| s13 | [KuppingerCole Leadership Compass: Passwordless Authentication for Enterprises (Entrust Overall Leader)](https://www.kuppingercole.com/research/lc80877/passwordless-authentication-for-enterprises) “The Overall Leaders (in alphabetical order) are 1Kosmos, Beyond Identity, Cisco, CyberArk, Entrust, HID, HYPR, IBM, Microsoft, Okta, OneSpan, Ping Identity, and Thales.” | research | 2026-06-28 |
| s14 | [NIST CMVP: Entrust nShield validated cryptographic modules](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules/search?SearchMode=Basic&Vendor=Entrust&CertificateStatus=Active&ValidationYear=0) “5329 \| Entrust Corporation \| nShield 5s Hardware Security Module \| Hardware \| 06/15/2026” | research | 2026-07-10 |
| s15 | [NVD CVE-2025-59702: Entrust nShield tamper-event falsification](https://nvd.nist.gov/vuln/detail/CVE-2025-59702) “Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.” | research | 2026-06-28 |
| s16 | [NIST: First three finalized post-quantum encryption standards (FIPS 203/204/205)](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards) “NIST has released a final set of encryption tools designed to withstand the attack of a quantum computer. ... NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.” | research | 2026-06-28 |
| s17 | [CA/Browser Forum members list (Entrust as Certification Authority)](https://cabforum.org/about/membership/members/) “The CA/Browser Forum includes the following members: Certification Authorities ... DigiCert ... Entrust ... Sectigo” | regulatory | 2026-06-28 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Entrust homepage identity-centric security](https://www.entrust.com) “Identity-Centric Security ... Protecting People, Devices, and Data” | official | 2026-06-28 |
| s2 | [Entrust nShield hardware security modules](https://www.entrust.com/products/hsm) “Comprehensive FIPS-certified HSM solutions for enterprise cryptographic security. ... ZF Friedrichshafen AG Secures Wireless Manufacturing with Entrust nShield HSMs” | official | 2026-06-28 |
| s3 | [Entrust PKI software solutions](https://www.entrust.com/products/pki) “All-in-one software-based PKI appliance for simplified, scalable, and secure PKI management.” | official | 2026-06-28 |
| s4 | [Entrust identity verification solutions](https://www.entrust.com/products/identity-verification) “Onboard customers, employees, and contractors faster with AI-powered identity verification that returns results within seconds.” | official | 2026-06-28 |
| s5 | [Entrust leadership team and CEO Tony Ball](https://www.entrust.com/company/leadership) “Tony Ball is the Chief Executive Officer of Entrust ... Tony brings more than two decades of global leadership experience across identity, authentication, and security technologies. Since joining Entrust in 2016 ... Tony held senior executive roles at HID Global and Gemalto” | official | 2026-06-28 |
| s7 | [Entrust completes Onfido acquisition](https://www.entrust.com/company/newsroom/entrust-completes-acquisition-of-onfido-creating-a-new-era-of-identity-centric-security) “Entrust, a global leader in trusted payments, identities, and data security, today announced it completed its acquisition of Onfido, a global leader in identity verification.” | official | 2026-06-28 |
| s8 | [Wikipedia: Entrust company overview and acquisition history](https://en.wikipedia.org/wiki/Entrust) “Entrust operated a publicly trusted certificate authority until selling its public certificate business to Sectigo in January 2025. Notable acquisitions include nCipher (2019), HyTrust (2021), WorldReach (2021), and Onfido (2024).” | research | 2026-06-28 |
| s9 | [Google Online Security Blog: Entrust Certificate Distrust](https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html) “Over the past several years, publicly disclosed incident reports highlighted a pattern of concerning behaviors by Entrust that fall short of the above expectations, and has eroded confidence in their competence, reliability, and integrity as a publicly-trusted CA Owner.” | press | 2026-06-28 |
| s10 | [Infosecurity Magazine: Chrome Update Will Block Entrust Certificates by November 2024](https://www.infosecurity-magazine.com/news/chrome-update-will-block-entrust/) “Chrome version 127 and higher will no longer trust new TLS server authentication certificates from Entrust and AffirmTrust. The move follows a series of reported compliance failures, unfulfilled improvement commitments and insufficient progress in addressing publicly disclosed incident reports.” | press | 2026-06-28 |
| s12 | [TechCrunch: Entrust revenue and customer base at Onfido acquisition](https://techcrunch.com/2024/02/06/confirmed-entrust-is-buying-ai-based-id-verification-startup-onfido-sources-say-for-more-than-400m/) “it currently has "just under $1 billion" in revenue annually with about 10,000 customers, including governments, major banks around the world and large enterprises.” | press | 2026-06-28 |
| s13 | [KuppingerCole Leadership Compass: Passwordless Authentication for Enterprises (Entrust Overall Leader)](https://www.kuppingercole.com/research/lc80877/passwordless-authentication-for-enterprises) “The Overall Leaders (in alphabetical order) are 1Kosmos, Beyond Identity, Cisco, CyberArk, Entrust, HID, HYPR, IBM, Microsoft, Okta, OneSpan, Ping Identity, and Thales.” | research | 2026-06-28 |
| s14 | [NIST CMVP: Entrust nShield validated cryptographic modules](https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search?SearchMode=Basic&Vendor=Entrust&CertificateStatus=Active&ValidationYear=0) “5329 \| Entrust Corporation \| nShield 5s Hardware Security Module \| Hardware \| 06/15/2026” | research | 2026-06-28 |
| s15 | [NVD CVE-2025-59702: Entrust nShield tamper-event falsification](https://nvd.nist.gov/vuln/detail/CVE-2025-59702) “Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.” | research | 2026-06-28 |
| s16 | [NIST: First three finalized post-quantum encryption standards (FIPS 203/204/205)](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards) “NIST has released a final set of encryption tools designed to withstand the attack of a quantum computer. ... NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.” | research | 2026-06-28 |
| s17 | [CA/Browser Forum members list (Entrust as Certification Authority)](https://cabforum.org/about/membership/members/) “The CA/Browser Forum includes the following members: Certification Authorities ... DigiCert ... Entrust ... Sectigo” | regulatory | 2026-06-28 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
