What are the differences between CMC and VMC certificates, including cost and requirements?
Published 28 Jul 2025
Updated 2 Aug 2026
13 min read
Summarize with

Updated on 2 Aug 2026: We refreshed the CMC and VMC comparison with current pricing, validation paths, DMARC requirements, certificate coverage, and renewal planning.
A CMC, or Common Mark Certificate, is usually cheaper and easier to obtain than a VMC because it can validate a logo through at least 12 months of public use instead of requiring an exact registered trademark. Some issuer workflows also accept a modified registered trademark for CMC. A VMC, or Verified Mark Certificate, is stricter because the logo must match a registered trademark or eligible government mark, but it can add Gmail's verified checkmark when the rest of the domain setup qualifies.
Both certificates belong at the end of a BIMI project. Before buying either one, the sending domain needs enforced DMARC, aligned SPF or DKIM for legitimate mail, a BIMI-ready SVG logo, domain control validation, and clean enough authentication reporting that the certificate does not sit unused.
- Cheaper: CMC is normally the cheaper certificate path, although current public pricing is still in the low four figures per year.
- Easier: CMC avoids the trademark filing barrier for a prior-use mark, but it still requires company validation, domain control, and evidence that the logo has been used publicly.
- Stricter: VMC requires an eligible registered mark that matches the submitted logo closely, plus the same organization and domain checks.
- Visibility: VMC can add the Gmail verified checkmark. CMC supports logo display at participating providers but does not create that checkmark.
DigiCert's current public pricing lists annual subscriptions at $1,416 for CMC and $1,752 for VMC. Prices change by region, currency, contract, and renewal terms, so CMC means less expensive than VMC, not a low-cost certificate.
CMC vs VMC at a glance
The cleanest comparison separates what proves rights to the logo, what the mailbox provider shows, and what work must happen before the certificate can help. The certificate itself does not fix authentication. It proves the logo after the domain has met BIMI and DMARC requirements.
|
|
|
|---|---|---|
Logo proof | Prior use or modified registered mark | Registered trademark or government mark |
Trademark | Not required for prior use | Required for normal brand logos |
Gmail check | No | Yes, when accepted |
Typical buyer | No matching trademark | Trademarked brand |
Public sellers |
Practical CMC and VMC comparison
The table hides one practical detail: a CMC is not a casual logo claim. The certificate authority still validates the organization, checks that the applicant controls the domain, and reviews evidence that a prior-use mark has appeared publicly for at least 12 months. A modified registered trademark can follow a separate CMC evidence path, depending on the issuer.

DigiCert Mark Certificates comparison screen with CMC and VMC options.
DigiCert and Sectigo both publicly describe CMC and VMC options. Issuer availability, validation details, and mailbox support can change, so confirm them before building a launch timeline around a specific certificate.
Certificates do not guarantee deliverability
CMC and VMC do not repair SPF, DKIM, or DMARC, and they do not guarantee inbox placement. Their direct function is authenticated logo display. A VMC can also produce Gmail's verified checkmark when Gmail accepts the BIMI setup.
Requirements before either certificate
Neither certificate matters until the domain has enforced DMARC. For BIMI, the policy must be p=quarantine or p=reject with pct=100, not p=none or partial enforcement. Suped's DMARC monitoring workflow shows which sources pass, which fail, and what must be fixed before a BIMI certificate has value.
Check the domain's authentication posture before asking legal or finance to approve a certificate purchase. Suped's domain health checker gives a quick view of DMARC, SPF, and DKIM readiness, while Suped's platform provides ongoing reporting and issue tracking.
Minimum DNS posture before BIMIdns
_dmarc IN TXT "v=DMARC1; p=reject; pct=100; rua=mailto:d@example.com" default._bimi IN TXT "v=BIMI1; l=https://e.co/l.svg; a=https://e.co/c.pem"
If the domain is still at p=none, move through staged enforcement only after legitimate sources pass aligned SPF or DKIM. Suped's Hosted DMARC supports policy staging without repeated DNS edits, especially when several business units send through different systems.
Do not buy the certificate first
A VMC or CMC can sit idle if authentication is not ready. Check these items before starting the certificate order.
- DMARC: The applicable domain is at quarantine or reject with pct=100.
- Mail sources: Legitimate messages pass aligned SPF or DKIM consistently before the logo launch.
- BIMI SVG: The logo file is in SVG Tiny Portable/Secure format and uses HTTPS hosting.
- Ownership: The applicant can prove legal organization details and domain control.
Suped does not issue CMC or VMC certificates. Suped helps prepare the domain, detect authentication gaps, alert teams when failures increase, and guide fixes for SPF, DKIM, DMARC, hosted SPF, and MTA-STS before the certificate is added to DNS.
?
What's your domain score?
Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.
After the initial check, monitor live reports for at least one normal sending cycle. This avoids passing a static DNS check while a forgotten invoicing, recruiting, support, or marketing platform still sends unauthenticated mail.
How certificate validation differs
The main difference between CMC and VMC is the evidence behind the mark. Both require identity validation and domain control. VMC asks for a registered mark that matches the logo. CMC accepts a prior-use mark, or a qualifying modified registered trademark under some issuer rules.
VMC validation
- Mark proof: A registered trademark, service mark, or eligible government mark.
- Logo match: The submitted SVG must match the official mark record closely.
- Document load: Trademark record, organization validation, and domain control evidence.
- Gmail result: Logo display plus the verified checkmark when Gmail accepts the setup.
CMC validation
- Mark proof: A prior-use mark or a qualifying modified registered trademark.
- Logo match: A prior-use logo must be visible on a controlled domain and match the submitted SVG.
- Document load: Organization validation, domain control, and evidence of 12 months of use for a prior-use mark.
- Inbox result: Logo display at participating providers that accept CMC, without Gmail's verified checkmark.
CMC is useful for companies with a real brand but no finished trademark registration. It is not a shortcut around identity checks. The certificate authority still needs to confirm that the company exists, that the applicant can be reached through a reliable channel, and that the applicant controls the domain.

Decision flow for choosing VMC when a logo is trademarked or CMC when it has prior use.
The strict logo match matters more than many teams expect. If the trademark is a word mark but the BIMI logo is a stylized icon, or if the registered mark contains words removed from the email version, the VMC path can slow down. For a prior-use CMC, the question becomes whether the same logo has enough visible history in normal business use.
Cost and commercial process
CMC has a lower public retail price, but the gap is not large enough to make price the only decision. The bigger saving can be time when a business does not already have a registered trademark. Filing or correcting a trademark can cost more than the annual certificate difference and can add months before a VMC order is ready.
Current public annual pricing
DigiCert public pricing for CMC and VMC annual subscriptions.
CMC
1,416 USDVMC
1,752 USDThe visible certificate price is one line item. A project also includes legal review, brand file preparation, DNS work, certificate renewals, and authentication cleanup. If the trademark already exists and matches the logo, VMC can justify the extra certificate cost when Gmail's checkmark is required. If the trademark is missing, CMC is usually the practical starting point.
- Certificate fee: Expect an annual paid certificate, commonly in the low four figures at public retail prices.
- Trademark cost: VMC can require legal filing work if the brand has no matching registration.
- Design cost: Both paths need a compliant SVG logo, which often needs design cleanup.
- DNS cost: The domain must publish correct DMARC and BIMI records with stable HTTPS locations.
- Renewal cost: Mark certificates normally renew annually, so assign a clear internal owner.
Price is not the only filter
If the brand requires Gmail's verified checkmark, choose VMC and budget for trademark validation. If the brand needs BIMI logo display without trademark filing, choose CMC and confirm that the target mailbox providers accept it.
The commercial process normally follows a certificate authority workflow: select CMC or VMC, submit organization details, validate domain control, provide the logo files, complete identity checks, and publish the final BIMI DNS record with the certificate URL. Issuer-hosted logo and certificate files can reduce the chance of a broken URL later.
How many certificates and renewals to plan for
Certificate cost scales with the number of unique logos and base domains, not the number of mailboxes or recipients. DigiCert's current guidance calls for one certificate per unique logo and one certificate per unique base domain. Confirm the exact coverage with the issuer before ordering because certificate packaging and supported configurations can change.
- Unique logos: A parent brand, sub-brand, or seasonal logo can require separate certificate coverage.
- Base domains: Separate organizational domains can increase the certificate count even when they use the same logo.
- Selectors: BIMI selectors can publish different logos, but each logo still needs matching certificate coverage where a certificate is required.
- Validity: Mark certificates have a maximum validity period of 397 days, while retail subscriptions commonly renew every 12 months.
Assign renewal ownership before launch. A changed logo, legal organization name, domain set, or certificate file location can trigger replacement work before the normal renewal date. Keep the PEM URL stable and monitor it so an expired or unreachable certificate does not remove the BIMI result.
Which certificate should you choose
Choose VMC when the logo already has an eligible trademark, the company wants Gmail's verified checkmark, and the budget can handle the higher annual certificate cost. Choose CMC when the logo has qualifying public history but no matching trademark, or when an issuer accepts the logo as a modified registered trademark.
- Use VMC: The logo has a current trademark record that matches the file intended for inbox display.
- Use CMC: The logo has at least 12 months of qualifying public use, or the issuer accepts it as a modified registered trademark.
- Wait: DMARC is still at p=none, pct is below 100, legitimate mail fails alignment, or the logo is not BIMI-ready.
- Recheck: The brand uses multiple base domains, selectors, sub-brands, or regional marks that need separate certificate planning.
Suped turns DMARC aggregate reports into a practical fix list for certificate readiness. Its workflow covers policy monitoring, SPF flattening, hosted SPF, hosted MTA-STS, blocklist (blacklist) monitoring, real-time alerts, and multi-tenant reporting when BIMI work involves legal, marketing, IT, and security owners.
Suped DMARC dashboard showing email volume, authentication health, and source breakdown
The dashboard answers the pre-certificate questions: which sources send mail, which pass authentication, and whether the domain is ready for enforcement. For focused record validation during setup, Suped's DMARC checker provides a quick check before production DNS changes.
Common implementation mistakes
Most failed BIMI launches are sequencing failures, not certificate failures. Teams order the certificate before DMARC reaches full enforcement, use a logo outside the required SVG profile, publish an unreachable certificate URL, or authenticate a different domain from the visible From domain.
BIMI record with certificate URLdns
default._bimi IN TXT "v=BIMI1; l=https://e.co/l.svg; a=https://e.co/c.pem"
That record is small, but every value behind it matters. The logo URL must stay live, the certificate URL must be reachable over HTTPS, and the certificate must match the organization and mark validated by the certificate authority.
Mistakes that delay launch
- Policy gap: The domain has p=none or pct below 100, so it does not meet Gmail's BIMI enforcement requirements.
- Logo gap: The SVG is a normal web SVG, not the restricted BIMI-safe profile.
- Mark gap: The submitted mark does not match the trademark record or public-use evidence.
- Owner gap: No one owns annual renewal, DNS hosting, and certificate file availability.
If the team is still deciding whether a certificate is required, separate that decision by asking whether a VMC is required for the target providers and what users should see.
Views from the trenches
Best practices
Confirm DMARC enforcement before the certificate order, not during final BIMI launch.
Gather legal entity, logo, domain, and contact proof before opening the CA order.
Treat CMC availability and pricing as issuer-specific until the quote is in writing.
Common pitfalls
Teams assume CMC means low effort, then fail the prior-use evidence review at CA validation.
A trademarked word mark is used for VMC, but the submitted logo is materially different.
Certificate renewal ownership is unclear, so BIMI breaks after the first term ends.
Expert tips
Choose VMC for Gmail checkmark goals, and CMC for real brands without trademark records.
Check historical logo use early because CMC depends on evidence, not preference.
Ask the issuer how it handles hosting, renewal, and certificate replacement before purchase.
Expert from Email Geeks says CMC is quicker and cheaper when trademark paperwork is not already available, but provider support must be checked before relying on it.
2024-09-25 - Email Geeks
Marketer from Email Geeks says CMC ordering became easier once public checkout pages appeared, although regional prices and page behavior still needed careful review.
2024-10-02 - Email Geeks
The practical answer
CMC is the easier and usually cheaper certificate when a brand has qualifying public logo use but no matching registered trademark. VMC is the stricter and usually more expensive certificate when a brand has an eligible registered mark and wants Gmail's verified checkmark.
The practical order is simple: enforce DMARC at pct=100, fix SPF and DKIM alignment, prepare the BIMI SVG, decide whether the mark evidence points to CMC or VMC, and then buy the certificate. If cost is the blocker, compare the annual certificate gap with the cost and delay of trademark work. If visibility is the blocker, check the VMC certificate cost path before assuming CMC gives the same inbox result.
- Pick CMC: No matching trademark exists, the mark has at least 12 months of public use, and logo-only display is enough.
- Pick VMC: A matching eligible trademark exists, Gmail's checkmark matters, and the organization can complete stricter validation.
- Pick neither yet: DMARC is not fully enforced, authentication reporting is messy, or the logo is not ready.

