shouldiuse.io

Categories

VERDICT

Should I use Entrust?

Comprehensive identity-centric security solutions - entrust.com

Depends. Buy only if you're a large, compliance-heavy organization that needs PKI, HSMs, or identity verification and has security admins on staff. Small teams — and anyone buying TLS certificates — should walk away: Chrome stopped trusting Entrust roots in November 2024.

Confidence

Medium. Based on 44 public sources. Name-collisions excluded: The Entrust Group (self-directed IRAs), entrustIT (UK MSP), entrust.org.uk (UK regulator).

Ratings

  • Value for money
  • Ease of useNo usable evidence in sources
  • Feature depth
  • Support qualityNo usable evidence in sources
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Regulated enterprises needing PKI
  • Banks needing HSM-backed key management
  • Telcos and governments building digital ID
  • High-volume identity verification buyers

Not for

  • Small teams needing basic TLS or MFA — this is a PKI program, not a tool
  • Anyone buying SSL certificates — Chrome and Google products no longer trust Entrust roots
  • Startups wanting self-serve signup and transparent pricing
  • Companies without dedicated security admins

Gotchas - check before you buy

high

Buying TLS certs means a forced migration — Chrome and Google products won't trust them.

medium

Contract reinstatement fees apply if your agreement lapses.

medium

Pricing is opaque — no public price list; spend varies widely by org.

low

Reddit thread alleges Entrust emails lack a working unsubscribe.

Pros and cons

Pros

  • Gartner Leader in the 2024 Magic Quadrant for identity verification
  • Broad portfolio: IAM, IDV (Onfido), PKI, HSMs, e-signing
  • Runs a public vulnerability disclosure program with scored severities
  • Proven at national scale — Antel digital identity and signing rollout
  • Onfido acquisition adds recognized identity-verification technology

Cons

  • Google and Chrome distrusted Entrust TLS roots from November 2024
  • 2025 CVEs hit nShield HSMs, including authentication bypass and privilege escalation
  • Acknowledged a June 2022 cyberattack; initially stayed quiet
  • No transparent public pricing; quotes are sales-led
  • Sysadmins publicly warn peers off Entrust certificates

Sources & method

Analyzed 10/01/2026 - 14 sources - Concerning: 2022 breach acknowledged, 2025 nShield CVEs, and Chrome no longer trusts Entrust TLS roots.

official x4review x5security x1news x4
  • Chrome/Google distrust Entrust TLS certificates, After repeated mis-issuance findings, Google stopped trusting Entrust TLS certificate roots in Chrome from November 2024.
  • CVE-2025-59704 — nShield authentication bypass, Entrust nShield 5c HSM affected by an authentication bypass vulnerability.
  • CVE-2025-59699 — nShield privilege escalation, Privilege escalation vulnerability in Entrust nShield 5c appliances.
  • June 2022 cyberattack, Entrust acknowledged a cyberattack; security observers reported ransomware involvement.

Key stats

  • Value for money: 2/5

    Rating

  • Not disclosed

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 2/5. No public pricing; sales-led contracts
  • Ease of use. No usable evidence in sources
  • Feature depth: 4/5. IAM, IDV, PKI, HSMs, e-signing portfolio
  • Support quality. No usable evidence in sources
  • Security posture: 2/5. 2022 breach, 2025 nShield CVEs, Chrome distrust
  • 197 G2 reviews across Entrust product listings
  • Leader Gartner standing 2024 Magic Quadrant, identity verification
  • Distrusted Chrome trust Entrust TLS roots, since Nov 2024
  • 444 Glassdoor reviews employee reviews, ~70% approval

Pricing

Not disclosed

Security

Concerning: 2022 breach acknowledged, 2025 nShield CVEs, and Chrome no longer trusts Entrust TLS roots.

  • Chrome/Google distrust Entrust TLS certificatesAfter repeated mis-issuance findings, Google stopped trusting Entrust TLS certificate roots in Chrome from November 2024.¹
  • CVE-2025-59704 — nShield authentication bypassEntrust nShield 5c HSM affected by an authentication bypass vulnerability.³
  • CVE-2025-59699 — nShield privilege escalationPrivilege escalation vulnerability in Entrust nShield 5c appliances.
  • June 2022 cyberattackEntrust acknowledged a cyberattack; security observers reported ransomware involvement.⁴

What users say

Reviews credit strong identity-verification capability, but sysadmin forums turned sharply negative after Google's certificate distrust decision.

“Entrust made multiple mi...”
Reddit, r/netsec (thread on certificate distrust)

Companies that use it

  • Antel (Uruguay)⁹
Full analysis

Based on 44 public sources. Name-collisions excluded: The Entrust Group (self-directed IRAs), entrustIT (UK MSP), entrust.org.uk (UK regulator).

Enterprise identity & PKI vendor — right for big compliance-heavy orgs, overkill for small teams; Chrome distrusts its TLS certs.

Methodology

Based on 44 public sources. Name-collisions excluded: The Entrust Group (self-directed IRAs), entrustIT (UK MSP), entrust.org.uk (UK regulator).

Sources

  1. news
  2. news
  3. security
  4. news
  5. review
  6. review
  7. news
  8. official
  9. official
  10. official
  11. review
  12. review
  13. official
  14. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.