Entrust is one of the most established names in enterprise PKI, and Entrust Certificate Services is a solid management portal for Entrust-issued certificates. TigerTrust adds the CLM layer above it — CA-agnostic, cloud-native, and Kubernetes-native.
Entrust has decades of PKI credibility and a strong CA business. Their management portal is capable but scoped to Entrust — most enterprises need one CLM across every issuer.
Entrust is a top-tier public CA. Certificate Services is its management portal, not a general-purpose CLM. Here is where the two overlap and where the delivery differs.
| Capability | TigerTrust | Entrust Certificate Services |
|---|---|---|
Entrust CA issuance & renewal Entrust is authoritative for Entrust-issued certs | ||
Multi-CA orchestration | ||
Certificate discovery (network, cloud, K8s) | ||
Kubernetes cert-manager integration | ||
ACME protocol / Let's Encrypt | ||
Cloud-native SaaS delivery | ||
GraphQL API | ||
Terraform provider | ||
HSM integration & FIPS 140-2 support Entrust has particularly strong HSM heritage via nShield | ||
Public CA trust anchors Entrust operates its own WebTrust-audited public trust anchors |
You do not have to leave Entrust to modernise the platform. Most teams keep Entrust as a preferred CA and add TigerTrust as the CLM.
Add Entrust as an issuer in TigerTrust using your existing Certificate Services API credentials. Current inventory imports automatically.
Bring in DigiCert, Sectigo, private CAs, ADCS, Let's Encrypt — whatever else is in the estate. Policy routes each request to the right CA.
Point discovery at your clouds, Kubernetes clusters, and network ranges. Every certificate appears in one inventory, regardless of issuer.
Enable ACME endpoints, cert-manager issuers, Terraform, and webhook renewals. Entrust keeps issuing; TigerTrust handles the rest.
No. Entrust stays as an issuer for the certificates you rely on them for — high-assurance TLS, code signing, EV, and workloads with strict trust requirements. TigerTrust sits above Certificate Services as the CLM plane.
Yes. TigerTrust integrates with Entrust nShield HSMs (and other PKCS#11-compatible HSMs) for key storage. Your existing HSM investment remains authoritative.
TigerTrust uses the Entrust Certificate Services API to enroll, retrieve, and revoke Entrust-issued certificates. Your CS account structure, validation model, and contract stay intact.
TigerTrust can be deployed on-premise, including air-gapped environments, and can front an on-prem Entrust PKI as one of the upstream issuers. You do not have to choose between cloud and on-prem.
Platform pricing is separate from Entrust certificate costs. You keep your Entrust contract; TigerTrust adds a platform fee for the CLM layer. Ask us for a side-by-side against your current line items.
“Entrust and our nShield estate were non-negotiable. We wanted a modern CLM plane above them — one that treats DevOps like a first-class citizen.”
Keep Entrust for high-assurance issuance. Add the CAs and DevOps integrations Entrust Certificate Services does not natively orchestrate.
The other high-assurance commercial CA teams often evaluate alongside Entrust.
The third commercial-CA portal customers weigh a real CLM against.
The managed PKI product that pairs with Entrust CS or replaces on-prem PKI outright.
The buyer journey for regulated estates modernising the CLM plane without touching the CA.