Entrust Corporation

United States · owned by Thoma Bravo (United States) · entrust.com · 57 vendors

Entrust is a global cybersecurity company specializing in identity-centric security solutions, including digital certificates, PKI, identity verification, payments security, and data encryption. The company serves governments, financial institutions, and enterprises worldwide with solutions for securing identities, transactions, and data. Entrust is headquartered in Shakopee, Minnesota, USA.

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 4 categories; runs on 57 sub-vendors.

Insights

Last updated 2026-05-05 · revision 9

57 direct vendors, 414 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Entrust's migration readiness is difficult to fully ascertain due to significant gaps in the provided data. The most critical missing piece is the "Internal Tech Stack," which prevents any assessment of whether their current systems are legacy, monolithic, or already aligned with modern cloud-native, containerized, or microservices architectures. This is fundamental to determining the effort and complexity of a migration. Furthermore, the "Vendor Lock-in Risk: Unknown" is a major impediment to assessment. While the geographic diversity of vendor HQs is noted, the actual number of vendors and the extent of lock-in are unknown, making it impossible to gauge the complexity of transitioning away from existing services. The "Total Vendors: 0" data point is contradictory and unhelpful in this context. On the positive side, Entrust already offers cloud services with data centers in multiple regions, including North America and Europe, allowing for regional data residency choices. This indicates they possess existing cloud infrastructure and an understanding of data location requirements, which could facilitate their own migration efforts. Their deep expertise in navigating a complex regulatory environment, including certifications like ISO 27001, SOC 2 Type 2, PCI DSS, and FIPS 140-2, and their applicability to NIS2, suggests they have robust processes for managing compliance. However, this extensive regulatory landscape also means any migration would need to meticulously adhere to these stringent requirements, potentially increasing complexity and cost. The absence of financial stability data also means their capacity to fund a significant migration project cannot be assessed.

Compliance

4 in-scope frameworks identified; showing 3.

HIPAA (source) — Assessment Required

If Entrust provides cybersecurity or digital identity solutions to healthcare organizations, they may handle Protected Health Information (PHI) and would be considered a Business Associate under HIPAA. Non-compliance can result in significant fines and legal liability. The risk level is medium as it depends on their specific client base and service offerings in the healthcare sector.

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for cybersecurity and cloud service providers as it demonstrates security, availability, and confidentiality controls. Customers increasingly require SOC2 compliance for vendor relationships. While not legally mandated, lack of SOC2 certification can impact business competitiveness and customer trust in the cybersecurity industry.

ISO 27001 (source) — Assessment Required

ISO 27001 is a critical standard for cybersecurity companies as it demonstrates systematic information security management. While not legally required, it's often a customer requirement and competitive necessity in the cybersecurity industry. The risk is medium as lack of certification could impact business opportunities and customer confidence.

Financials

Three-year financials

Financial Resilience Score: 6/10

Entrust Corporation is a privately held company majority-owned by Thoma Bravo and does not publish audited financial statements, making precise financial resilience assessment difficult. Qualitatively, the company benefits from a diversified portfolio across three secular-growth markets: digital identity, payments/card issuance, and cryptographic security (PKI/HSM). It has a strong installed base in financial services and government ID issuance with a recurring hardware + consumables + software model, providing revenue stability. The company's long-tenured private-equity backing implies access to capital for M&A, evidenced by multiple sizeable acquisitions including nShield HSM (2019, ~$500M), Onfido (2024, ~$400M+), HyTrust, Evidos, and others. Its product positioning is aligned with regulatory tailwinds such as post-quantum cryptography migration, eIDAS 2.0, digital identity wallets, and Zero Trust mandates. However, key concerns include significant leverage typical of Thoma Bravo-owned tech companies, sensitivity to interest rates and EBITDA performance for debt service, limited financial transparency due to private status, and a June 2022 LockBit ransomware incident that posed reputational risk for a security vendor. Heavy acquisition cadence introduces integration risk, and hardware exposure creates supply-chain sensitivity.

Key strengths: Diversified portfolio across digital identity, payments/card issuance, and cryptographic security, Strong installed base in financial services and government ID issuance, Recurring hardware + consumables + software revenue model, Long-tenured Thoma Bravo private-equity backing providing capital access, Product positioning aligned with regulatory tailwinds (post-quantum cryptography, eIDAS 2.0, Zero Trust), Active M&A track record (nShield, Onfido, HyTrust, Evidos), Serves customers in 150+ countries

Risk factors: Significant leverage typical of Thoma Bravo-owned companies, Debt service sensitivity to interest rates and EBITDA performance, Limited financial transparency due to private status, June 2022 LockBit ransomware incident creating reputational risk, Intense competition from DigiCert, Sectigo, IDEMIA, Thales, Okta, Ping Identity, Jumio, Veriff, Microsoft, Integration risk from heavy acquisition cadence (notably Onfido in 2024), Hardware exposure creating supply-chain and component-cost sensitivity

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report