LICENSEWARE

Entrust Cryptographic Security Platform and PKI licensing

This article is about licensing the Entrust Cryptographic Security Platform (CSP, including PKI Hub) and the PKI hosted services such as PKI as a Service. It is not about nShield HSM hardware licensing, Entrust Identity, or the public TLS certificates Entrust sold to Sectigo, which have their own articles, and it is not legal advice.

On This Page

The Entrust Cryptographic Security Platform (CSP) is Entrust’s software whose licensed capabilities, as the add-on list shows, span certificate management, key and secret management, compliance management and HSM management; it may be deployed on the customer’s own infrastructure or in commercial cloud environments.[1] Its licensing page, titled “Customer license”, describes a base package extended by add-on licences. The same documentation family covers PKI as a Service (PKIaaS), a hosted offering licensed as a prepaid subscription. After the 2025 sale of its public certificate business, Entrust states that it continues to provide private and managed PKI, certificate lifecycle management and digital signing,[6] which makes these products the core of the Entrust certificate estate that a licence manager reconciles.

Contract documents

Entrust’s Terms and Conditions page states that general terms may be superseded by product schedules and by any separate master agreement.[5] The PKI terms page separates hosted services, each with its own terms of use and schedules, from PKI software. The hosted services listed are Entrust Managed PKI, Cryptography as a Service, Managed Root CA, Managed Microsoft PKI, Managed Certificate Hub, PKI as a Service and Verified PKI as a Service.[4] PKI software “is subject to the end user license that must be accepted at the time of download/installation”; if no more specific licence is provided, the software is covered by the End User License on that page.[4] For PKIaaS, the Definitions page defines the governing agreement as the PKIaaS terms of use, the PKIaaS schedule, the Entrust General Terms and Conditions provided with the schedule, and the order.[2]

CSP authorised use

The licensing section defines the customer as one that has purchased one or more CSP licences or an individual authorised by it. CSP is licensed for internal use for the customer’s own business purposes. Employees of external contractors may use it, but only on the customer’s behalf in operating or managing the customer’s business and its own cryptographic assets, and the customer may give digital certificates to users outside the organisation solely to enable communications and resource access between the customer and that user.[1] Unless an express agreement signed by Entrust says otherwise, neither the customer nor any user may use CSP “to set up or provide its own cryptographic management, analysis, or reporting service for other companies”, giving managed service provider and systems integrator as examples.[1]

The customer receives one or more licence keys that enable functionality and volumes of keys and secrets, certificates and third-party objects according to what was purchased.[1] Customers may not alter a licence key or attempt to circumvent the licensing mechanism, and may use only a valid key provided by Entrust with the corresponding component.[1]

Base package: Entrust CSP on Premise Core

The base licensing package includes a number of components, and states which items need separate licences:[1]

Included in the base package Limit or separate licence 
Compliance Manager, 2-node cluster Additional nodes need the add-on “Compliance Manager - 2 Nodes Virtual Appliance Cluster” 
Standard Compliance Pack: assessment, documentation and risk scoring for Discovery scan results and one additional data source Further data sources need the add-on for Standard Assessment, Documentation and Risk Scoring per Vault Cluster; Discovery scan results do not count as a data source 
Discovery (scanning) None stated 
KeySafe 5 (HSM manager) Monitoring is a separate tiered annual subscription 
File Encryption, 10 GB Beyond 10 GB, a licence per terabyte per year (File Encryption Subscription 1TB) 

The 10 GB protected data limit is calculated on the original data size and excludes overhead added by the encryption. Disc Encryption for Virtual Machines needs a separate Vault Cluster licence and virtual machine volume licences.[1]

Add-on licences and how they are consumed

The add-on table groups licences by capability:[1]

  • Compliance Management: Third-party Objects (integration with third-party KMS keys), Compliance Manager nodes (up to a maximum of eight nodes per cluster), and the Standard Compliance Pack. Every Vault Cluster, Certificate Manager and KeySafe 5 instance needs its own Standard Compliance Pack.
  • HSM Management: KeySafe 5 Monitoring in Base, Standard, Mid or Enterprise tiers, “determined by the number of HSMs being monitored and subject to an annual (12-month) subscription”. The nShield documentation likewise states that KeySafe 5 monitoring is an annual subscription requiring a separate activation licence.[7]
  • Certificate Management: Certification Authority, Advanced PKI, Advanced CLM, Timestamping Expansion and Production Certificates. Certificates “require separate licensing” from the Certification Authority licence, and the certificate licence is volume-based, with one licence required for each active certificate. The timestamping authority included in Advanced PKI may be deployed as a three-node cluster limited to 600 timestamps per second; the expansion add-on adds two nodes or up to 600 additional timestamps per second, to a maximum of five nodes per cluster.
  • Keys and Secrets Management: Vault Cluster (each licence covers one 2-node cluster, up to eight nodes), KMIP Keys, Managed Secrets, Cloud Keys (bring your own key, hold your own key and native key management), TDE Databases, Application Keys (including tokenisation and cryptographic REST API) and Virtual Machine Keys.

Active and dormant counting

For the keys-and-secrets subscriptions and for third-party objects, the documentation sets out consumption directly: an active key or secret is “1 full license”; an inactive key or secret that is still managed is “1/10 of a license (dormant Key/Secret)”; a deleted or unmanaged key or secret requires no licence. Third-party objects imported into Compliance Manager inventory follow the same pattern.[1] The dormant fraction makes the lifecycle state of each object, not just its existence, the licence variable. A reconciliation should export objects with their state (active, inactive but managed, deleted or unmanaged), count active objects at one and dormant objects at one tenth, and compare the totals per category with each purchased add-on.

Overage, records and reports

Customers may not exceed the total volume in a purchased licence. If consumption does, “Entrust may invoice Customer an overage fee in arrears for its actual consumption”.[1] The Support and Record-Keeping section expects customers to maintain reasonable records of deployment details, including production instances and whether they are on-premises or in cloud environments, and, on Entrust’s request, to provide a report of consumption of keys and secrets, certificates and third-party objects.[1] That request is the closest the documentation comes to a verification right, and the customer should be able to produce the report from the platform’s inventory.

External dependencies and compliance packs

CSP licences “do not include any Hardware Security Modules (HSM)”, which must be provided, installed and configured separately before the software can operate.[1] The Standard Compliance Packs help review keys, secrets and certificates against industry standards and best practices, but Entrust does not warrant that their use ensures compliance, and the customer remains responsible for validating requirements.[1] The software contains cryptographic components, so the customer’s country may have import and export requirements.[1]

PKI as a Service

PKIaaS is a cloud-hosted PKI service. Its Definitions page states that “a subscription is a prepaid inventory of PKI products purchased by the customer”, and that to use the inventory the subscription must be converted into an instance by assigning it to a region.[2] A region defines a legal boundary for regulatory requirements and jurisdiction and a physical location for cryptographic operations, private-key storage and data-residency enforcement, and the page suggests choosing one by the location of regulated data and users and by legal and disaster-recovery considerations.[2]

The Supervisor interface shows each subscription’s identifier, status (assigned or unassigned), region, URL and inventory.[3] Two inventory counters matter for licensing:[3]

  • Certificates are shown as issued/purchased, where purchased is the largest number of certificates allowed and issued the number already issued. The inventory excludes the certificate-signing certificates issued when a certificate authority is created.
  • Certificate authorities (root or issuing) are shown as active/purchased. After a CA is deleted, PKIaaS takes up to 24 hours to remove it from the total number of active CAs.

A subscription that is unassigned has been purchased but not deployed, so unused inventory can be identified by status. The documents read do not state whether unused inventory expires or can be carried forward; the PKIaaS schedule and the order govern that.

Other hosted PKI services

Managed Certificate Hub, Managed Root CA, Managed Microsoft PKI, Entrust Managed PKI and Cryptography as a Service each have separate terms of use or schedules on the PKI terms page, together with uptime service levels and support schedules where listed.[4] The page also lists professional services (Technical Account Manager, PKIaaS onboarding and Certificate Hub onboarding).[4] The schedules are separate documents and their metrics are not covered here.

Out of scope

This article does not give prices, which Entrust does not publish for these products, and it does not summarise the PDF schedules. Certificate Hub is described only by its listing on the terms page. Publicly trusted TLS certificates, once issued through Entrust Certificate Services, are covered in the separate article on the public certificate business.

References

  1. Customer license (Cryptographic Security Platform 1.4 - PKI Hub 1.5 installation, administration and user guide)Authorized Use, base licensing package, add-on licences, deployment, external dependencies, record-keeping. Undated.Retrieved 2026-10-08.
  2. Definitions (Entrust PKI as a Service)Agreement, Region, Subscription and related definitions. Undated.Retrieved 2026-10-08.
  3. Checking your subscriptions (Entrust PKI as a Service)Inventory display and counting. Undated.Retrieved 2026-10-08.
  4. PKI Terms & ConditionsIndex of PKI hosted-service and software terms. Undated.Retrieved 2026-10-08.
  5. Terms & ConditionsStates precedence of separate master agreements. Undated.Retrieved 2026-10-08.
  6. Entrust Sells Public Certificate Business to Sectigo, Sharpening Focus on Quantum-Ready Cryptographic Data Security SolutionsPress release dated 2025-01-29; states Entrust will continue to provide private and managed PKI, CLM and digital signing.Effective 2025-01-29. Retrieved 2026-10-08.
  7. nShield HSM licensing (nShield Docs)KeySafe 5 monitoring subscription. Undated.Retrieved 2026-10-08.

See also

Catalog Rows Cited

5Metrics1Programs

Esc