IdenTrust, Inc.

United States · www.identrust.com · 32 vendors

IdenTrust, Inc. is a leading provider of digital certificates and Public Key Infrastructure (PKI) solutions. It offers identity-based security services for user authentication, data encryption, and digital signing across various sectors. The company's solutions help protect data, authenticate users, and enable secure online transactions for financial institutions, government agencies, healthcare providers, and enterprises.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 32 sub-vendors.

Insights

Last updated 2026-08-11 · revision 17

32 direct vendors, 384 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IdenTrust exhibits low migration readiness primarily due to the highly specialized and hardware-dependent nature of its core Public Key Infrastructure (PKI) and Hardware Security Modules (HSMs). Migrating such a critical and deeply integrated infrastructure to a cloud-native, microservices architecture presents immense technical challenges. The company operates within an extremely complex and stringent regulatory environment, including DoD ECA, DEA EPCS, WebTrust, SOC 2, GDPR, NIS2, eIDAS, HIPAA, and CCPA/CPRA. Any significant migration would necessitate extensive re-auditing and re-certification efforts across these frameworks, incurring substantial costs and time. Data residency requirements, particularly for DoD-related data in the US and GDPR/NIS2/eIDAS in the EU, further complicate cloud migration strategies by restricting cloud provider choices and data placement. While the 'PKI-as-a-Service' offering suggests some modularity and experience with managed services, a full migration of the root CA infrastructure remains a monumental task. The contradictory vendor data ('Total Vendors: 0' vs. '8 unique countries') makes vendor lock-in difficult to assess, but the specialized nature of PKI often implies reliance on a few niche vendors or significant internal system lock-in, both of which hinder migration flexibility.

Compliance

12 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

IdenTrust has confirmed EU office locations in France, Sweden, and Austria, and operates as a digital infrastructure provider — specifically a Trust Service Provider (TSP) and Certificate Authority (CA). Under NIS2 Directive (EU) 2022/2555, Trust Service Providers and digital infrastructure providers are explicitly listed as Essential or Important Entities. As a CA providing publicly trusted certificates used across critical sectors (banking, healthcare, government, energy), IdenTrust's services underpin digital infrastructure across the EU. NIS2 Article 3 covers 'trust service providers' under Annex I (Essential Entities) for digital infrastructure. The risk is High because: (1) IdenTrust's CA services are critical digital infrastructure; (2) EU member states (France, Sweden, Austria) have transposed or are transposing NIS2; (3) non-compliance penalties can reach €10M or 2% of global turnover for Essential Entities; (4) the cybersecurity incident reporting obligations are stringent (24-hour initial notification). IdenTrust's parent HID Global/ASSA ABLOY's size clearly exceeds the medium enterprise threshold (50+ employees, €10M+ turnover).

Evidence: https://www.identrust.com/about-identrust, https://www.identrust.com/identrust-accreditations, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

DEA EPCS — Compliant

IdenTrust explicitly provides EPCS-compliant certificates for healthcare providers to digitally sign controlled substance prescriptions, as required by DEA regulations under 21 CFR Part 1311. This is a core service offering with dedicated product lines and partner programs. The DEA EPCS program requires identity proofing, logical access controls, and audit logging — all of which IdenTrust's PKI infrastructure supports. Risk is Low because compliance is confirmed through active product offerings and regulatory alignment.

Evidence: https://www.identrust.com/digital-certificates/epcs-prescribing, https://www.identrust.com/my-buying-community/healthcare, https://www.identrust.com/certificates-portfolio/igc-epcs, https://www.identrust.com/partners/epcs

eIDAS Regulation — Assessment Required

IdenTrust operates as a Trust Service Provider (TSP) with EU office locations in France, Sweden, and Austria. The eIDAS Regulation (EU) 910/2014 and its successor eIDAS 2.0 govern trust services in the EU, including electronic signatures, certificates, and timestamping. As a CA issuing certificates used for digital signing in EU member states, IdenTrust may be subject to eIDAS requirements. However, eIDAS qualified trust services require specific registration with national supervisory bodies (e.g., ANSSI in France). IdenTrust's certificates are primarily US-standard (WebTrust/CA-B Forum) and may not be eIDAS-qualified, which could limit their legal recognition for certain EU use cases. Risk is Medium because: (1) EU operations are confirmed; (2) eIDAS compliance is not confirmed; (3) non-qualified certificates may have limited legal standing for certain EU transactions.

Evidence: https://www.identrust.com/about-identrust, https://www.identrust.com/identrust-accreditations, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910

Financials

Three-year financials

Financial Resilience Score: 7/10

IdenTrust's financial resilience is primarily derived from its parent company structure rather than standalone financial metrics. As a wholly-owned subsidiary of HID Global, which is itself owned by ASSA ABLOY AB (a Swedish publicly listed company with market cap generally exceeding SEK 300 billion), IdenTrust benefits from significant balance-sheet strength, R&D funding, and access to capital that would be unavailable to a standalone certificate authority. The parent group generated approximately SEK 150,981 million in net sales in FY2024 with operating income of ~SEK 24,013 million. IdenTrust itself has a durable business model with recurring subscription-like revenue from digital certificates (1-3 year validity with renewals), producing predictable cash flow. The company holds deep regulatory accreditations including WebTrust, CAB Forum Baseline, U.S. Federal Bridge cross-certification, DoD ECA authorization, DEA EPCS authorization, and AICPA SOC certifications, which create high barriers to entry and long-term customer relationships. Its 25+ year operating history as a PKI pioneer and diversified customer base across government, healthcare, financial services, and enterprise segments further supports resilience. However, resilience is tempered by industry-specific risks: the public-trust TLS/SSL market is increasingly commoditized with pressure from competitors like DigiCert, Sectigo, GlobalSign, and free CAs like Let's Encrypt. The CA industry also faces existential regulatory risk—any mis-issuance or security breach can trigger distrust by browser root programs. Concentration in U.S. government business exposes IdenTrust to federal budget cycles.

Key strengths: Backed by financially strong publicly-listed parent ASSA ABLOY (market cap >SEK 300B), Over 25 years of operating history as a PKI pioneer, Deep regulatory accreditations (WebTrust, DoD ECA, DEA EPCS, Federal Bridge) create high barriers to entry, Recurring subscription-like revenue model from certificate renewals, Diversified customer base across government, healthcare, financial services, and enterprise

Risk factors: Commoditization pressure in TLS/SSL market from competitors including free CAs like Let's Encrypt, Regulatory/compliance risk—any mis-issuance or security breach can lead to browser root program distrust, Shortening certificate lifetimes (moving to 90-day certificates) forcing infrastructure changes, Concentration in U.S. government business exposes to federal budget cycles, Limited financial transparency for third parties as no standalone accounts are published

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report