LICENSEWARE

Entrust licensing

This article is an overview of how Entrust licenses its nShield hardware security modules, public key infrastructure (PKI) and certificate lifecycle software, and identity and access management subscriptions. Deeper articles cover nShield HSM licensing, the Cryptographic Security Platform and PKI as a Service, and the 2024 to 2025 public TLS certificate distrust and the sale of the public certificate business to Sectigo. It is not legal advice.

On This Page

Entrust sells security products whose licensing differs sharply by product line. Its hardware security modules (HSMs), branded nShield, are licensed as hardware with serial-bound activations and client licences. Its Cryptographic Security Platform is software licensed by key with volume add-ons. PKI as a Service is a prepaid subscription, and Entrust Identity as a Service is a per-user-per-month subscription. In January 2025 the company announced the sale of its public certificate business to Sectigo, which removed publicly trusted TLS, S/MIME and related certificates from the Entrust catalogue.[6] A licence manager therefore has to read several documents, published in several places, to establish an Entrust position.

Contract structure

Entrust publishes a Terms and Conditions page that states that its General Terms “may be supplemented and/or superseded by the individual agreements” listed under each product heading, and that the terms do not apply where Entrust has entered into a separate master or supervening agreement with the customer.[5] The page lists product groups including identity and access management, PKI, digital signing, hardware security modules and the Cryptographic Security Platform.[5] For PKI, the page separates hosted services (Entrust Managed PKI, Cryptography as a Service, Managed Root CA, Managed Microsoft PKI, Managed Certificate Hub, PKI as a Service and Verified PKI as a Service) from PKI software, which is “subject to the end user license that must be accepted at the time of download/installation”.[8]

Those agreements are published as downloadable documents rather than HTML pages, and this article does not summarise their clauses (for example any audit or verification clause). The licensing detail that is published as web pages, and is therefore cited here, sits in product documentation: the nShield HSM licensing page, the Customer license section of the Cryptographic Security Platform guide, and the Definitions page of PKI as a Service.[1][2][3] Practitioners should obtain the order form and schedules that apply to their purchase, since the order and any master agreement can override the general documentation.

Product lines and metrics

Product line How it is licensed Unit that matters Detail article 
nShield HSMs (Connect XC, 5c, Solo XC, 5s, Edge) Hardware with perpetual feature activations; support sold separately Client license, feature activation, speed rating Entrust nShield HSM licensing 
nShield software (KeySafe 5, nShield Monitor, option packs) Licences or annual subscriptions per HSM or endpoint Monitor endpoint, nCOP licence, KeySafe 5 Monitoring tier Entrust nShield HSM licensing 
Cryptographic Security Platform Base package plus add-on licence keys Certificate, key or secret, terabyte per year Cryptographic Security Platform and PKI licensing 
PKI as a Service Prepaid subscription assigned to a region Subscription inventory Cryptographic Security Platform and PKI licensing 
Entrust Identity as a Service Subscription per user per month User This article 
Public certificates (to 2025) Sold through Entrust Certificate Services, now Sectigo Certificate Public certificate business and TLS distrust 

nShield in brief

The nShield documentation describes a customer making choices on hardware model, performance level (Base, Mid or High), certification, features and add-ons.[1] HSMs and their software are sold or licensed for internal Customer use, and unless an express licence agreement signed by Entrust says otherwise, a customer may not use them to provide its own managed service for other companies.[1] Network appliance models include a default total of three client licences, and further client licences are perpetual activations applied to an individual HSM.[1] Optional features are enabled by a feature certificate issued by Entrust against the HSM serial number.[10] Software releases follow a Long Term Support and Standard Term Support policy, revised on 2025-07-02, which sets how long a given Security World release receives fixes.[11] The nShield Monitor appliance has its own endpoint-based licences with a cap of 500 endpoints per monitoring software licence.[9]

Cryptographic Security Platform and PKI in brief

The Cryptographic Security Platform licence section describes a base package, “Entrust CSP on Premise Core”, extended by add-on licences for specific capabilities and volumes of keys and secrets, certificates and third-party objects.[2] Volume-based items may not be exceeded, and Entrust may invoice an overage fee in arrears for actual consumption.[2] The licences do not include HSMs.[2] PKI as a Service defines a subscription as “a prepaid inventory of PKI products purchased by the customer”, which becomes an instance when assigned to a region.[3]

Entrust Identity as a Service

Entrust describes its identity as a service (IDaaS) offer as “a complete subscription to Entrust Identity” covering workforce, consumer and citizen use cases.[4] The product page lists three Workforce Bundles. The Standard bundle (multi-factor authentication for remote access applications, single sign-on and Active Directory integration) is shown at USD 2 per user per month; the Plus bundle (adaptive authentication, access control and advanced management with Active Directory and Azure Active Directory) at USD 3.50 per user per month; and the Premium bundle (mobile digital identities, proximity-based login and cross-platform biometrics) is priced on request.[4] The page offers deployment by the customer or as a managed service through a certified managed service provider partner.[4]

The page does not define how a “user” is counted, whether inactive users are billable, or any minimum order. Those points would normally be set in the order and the Identity and Access Management schedule, which is one of the product agreements listed on the Terms and Conditions page.[5] A licence manager reconciling IDaaS should therefore compare the number of enabled users in the administration console with the quantity on the order, and confirm the counting rule in the schedule rather than assume it from the price page.

Public certificates after 2025

Entrust announced on 2025-01-29 that it had sold its public certificate business to Sectigo and stated that terms were not being disclosed.[6] The Entrust TLS Certificate Information Center records that the transition was completed on 2025-09-18, that Public Trust CA services were discontinued in the Entrust Certificate Services portal, and that Sectigo “will honor the terms of your existing Entrust contract”.[7] Entrust states that it will continue to provide private and managed PKI, certificate lifecycle management and digital signing.[6] The detail, including the browser distrust decisions that preceded the sale, is in Entrust public certificate business and TLS distrust.

What a licence manager should check

  • HSM estate. List each HSM by serial number with model, performance tier, client licences and feature activations, because licences are tied to the serial.[1]
  • Features after re-initialisation. Client licences on network HSMs are dynamic and must be re-applied if the HSM is initialised.[10]
  • Software release support. Match each Security World version to its LTS or STS phase before relying on fixes.[11]
  • CSP consumption. Count active and dormant keys, secrets and certificates against purchased volumes, and keep deployment records, since Entrust may ask for a consumption report.[2]
  • Certificates. Identify which certificates were issued by Entrust roots, which by Sectigo, and their expiry dates.[7]
  • Contract documents. Confirm which schedules and any master agreement apply.[5]

Out of scope

This article does not cover Entrust identity-verification (formerly Onfido), issuance hardware and software for cards and passports, digital signing services or the Entrust Instant Financial Issuance products, whose terms are separate schedules on the Terms and Conditions page.[5] It does not state prices other than the published Entrust Identity bundle prices, and it does not reproduce clauses from the PDF agreements.

References

  1. nShield HSM licensing (nShield Docs)Licensing model and permitted uses for nShield HSMs and HSM-related software. Undated.Retrieved 2026-10-08.
  2. Customer license (Cryptographic Security Platform 1.4 - PKI Hub 1.5 guide)Base licensing package and add-on licences for the Cryptographic Security Platform. Undated.Retrieved 2026-10-08.
  3. Definitions (Entrust PKI as a Service)Subscription, Instance and Region definitions. Undated.Retrieved 2026-10-08.
  4. Identity as a Service (IDaaS) Solution ProviderStandard, Plus and Premium Workforce Bundles. Undated.Retrieved 2026-10-08.
  5. Terms & ConditionsIndex of the General Terms and product schedules. Undated.Retrieved 2026-10-08.
  6. Entrust Sells Public Certificate Business to Sectigo, Sharpening Focus on Quantum-Ready Cryptographic Data Security SolutionsPress release dated 2025-01-29.Effective 2025-01-29. Retrieved 2026-10-08.
  7. TLS Certificate Information CenterStates that the transition was completed on 2025-09-18.Effective 2025-09-18. Retrieved 2026-10-08.
  8. PKI Terms & ConditionsIndex of PKI hosted-service and software terms. Undated.Retrieved 2026-10-08.
  9. Licensing (nShield Monitor)Order codes and endpoint caps. Undated.Retrieved 2026-10-08.
  10. Optional features (nShield HSM User Guide)Feature certificates, client licences and speed ratings. Undated.Retrieved 2026-10-08.
  11. nShield Security World Software Release PolicyRevision 1.1 dated 2025-07-02.Effective 2025-07-02. Retrieved 2026-10-08.

See also

Catalog Rows Cited

11Metrics

Esc