24/7 Validation Support · Certificates issued in minutes
0
APPLICATION & SOFTWARE INTEGRITY

Code Signing Certificates

OV and EV code signing certificates from Sectigo, Comodo, DigiCert, and GoGetSSL. Protect your software against tampering, remove harsh 'Unknown Publisher' security warnings, and build instant reputation with Microsoft SmartScreen. Hardware token and cloud HSM options available with full 25-day money-back guarantee.

FIPS 140-2 HARDWARE & CLOUD HSM

Complies fully with CA/B Forum requirements. Private keys are securely delivered on pre-configured USB tokens (YubiKey) or hosted in CA-managed cloud HSMs (DigiCert KeyLocker) for seamless CI/CD automation.

UNIVERSAL BINARY SUPPORT

Digitally sign Microsoft Authenticode Windows binaries (.exe, .dll, .msi), kernel-mode drivers (EV), Java JAR archives, PowerShell scripts, and cross-platform installation packages.

PRODUCT CATALOG

Code Signing Certificates

Protect your applications and software releases with authentic publisher validation.

Single Domain

Organization Validation

Sectigo Code Signing Certificates

Price range: $441,18 through $676,47

VALIDATION TIERS

OV vs EV Code Signing Certificates

Two validation tiers exist, and the choice comes down to who signs and what types of software you distribute.

STANDARD TIER

Organization / Individual Validation (OV/IV)

The standard tier for software publishing. Vets the legal existence of registered companies or verified individual developers. Eliminates 'Unknown Publisher' security blocks for Windows user-mode applications, Java JARs, scripts, and macros.

• Best for: User-mode apps, scripts, dev tools • Driver signing: User-mode only • Identity: Business or verified individual • Delivery: USB Token or Cloud HSM • Starting price: From $219/yr
ENTERPRISE TIER

Extended Validation (EV)

Deepest organizational verification under CA/B Forum EV guidelines. Only registered organizations qualify. EV is mandatory for signing Windows kernel-mode drivers and Microsoft WHQL portal attestation submissions.

• Best for: Windows drivers, enterprise software • Driver signing: Full kernel-mode & WHQL eligible • Identity: Registered organization only • Delivery: FIPS USB Token or KeyLocker • Starting price: From $287/yr
REPUTATION MECHANICS

Microsoft SmartScreen Behavior

Following Microsoft Trusted Root Program updates, reputation now accumulates by file hash and download volume across both OV and EV tiers. EV no longer grants instant bypass—both tiers build trust seamlessly in the wild.

• Trust Model: Builds reputation per file hash • Threshold: Fast reputation on download volume • Warning: Prevents 'Windows Protected Your PC' • Timestamping: Retains trust past expiration • Requirement: FIPS 140-2 Level 2 Hardware
KEY STORAGE STANDARDS

Hardware Token, Cloud HSM, or Bring Your Own Device

Under CA/B Forum regulations, private keys must reside on hardware meeting FIPS 140-2 Level 2 or Common Criteria EAL 4+.

CA-Shipped USB Token

The Certificate Authority mails a pre-loaded FIPS 140-2 Level 2 USB crypto token (typically a YubiKey) directly to your verified business address. Ideal for occasional manual signing.

Cloud HSM (KeyLocker)

Private keys reside in secure, CA-managed cloud HSMs (such as DigiCert KeyLocker or Sectigo Cloud Signing). Zero physical tokens to lose, seamless API access, and perfect for automated CI/CD pipelines.

Bring Your Own Device (BYOD)

If your team already operates an on-premise FIPS 140-2 Level 2 or Common Criteria EAL 4+ HSM, the CA issues against cryptographic attestation directly from your device.

SUPPORTED FORMATS

What You Can Sign with a Code Signing Certificate

A single certificate secures binaries, packages, drivers, and macros across all major developer environments:

Windows Binaries & Installers

.exe, .dll, .cab, .ocx, .msi, and .xap files signed with Microsoft Authenticode for complete OS verification.

Windows Hardware Drivers

User-mode drivers (OV or EV) and kernel-mode drivers (EV required for Microsoft WHQL portal attestation).

Java Applications & Mobile

.jar files signed with jarsigner, Android application packages, and cross-platform runtime bundles.

Scripts, Macros & Firmware

PowerShell scripts, VBScript, Microsoft Office VBA macros, IoT firmware updates, and container packages.

BALLOT CSC-31 TIMELINE

New 460-Day Validity Limit & Crucial Timestamping

What software developers need to know about the current validity guidelines:

460-DAY MAXIMUM LIFESPAN

Maximum 460 Days per Certificate

Under CA/Browser Forum Ballot CSC-31, publicly trusted code signing certificates have a maximum validity of 460 days (~15 months). Multi-year orders remain available on Renewal SSL, locking in lower rates while certificates are reissued during the purchased subscription.

• Lifespan Cap: 460 days (~15 months) • Multi-year terms: 2-year and 3-year options • Reissuance: Free and unlimited within subscription • Unaffected code: Existing signed binaries remain valid
RFC 3161 TIMESTAMPING

Why Timestamping is Crucial

Always include an RFC 3161 compliant timestamp server when signing (tsa.digicert.com or timestamp.sectigo.com). Timestamping proves your binary was signed while the certificate was valid, ensuring Windows continues to trust your software long after certificate expiration.

• Signature Longevity: Trusted indefinitely post-expiration • Free inclusion: TSA services included with all certificates • Seamless integration: Supported natively in SignTool • Zero maintenance: No need to re-sign legacy binaries
FAQ

Frequently Asked Questions

Common questions about this certificate type, validation standards, and deployment.

It is an X.509 digital certificate that allows software developers and organizations to attach a cryptographic signature to executables, scripts, and drivers. It verifies publisher identity and ensures code has not been altered or corrupted since it was signed.

OV (Organization Validation) confirms the publisher’s registered business identity (or individual identity) and is ideal for user-mode software, scripts, and plugins. EV (Extended Validation) undergoes strict organizational vetting, is required by Microsoft for Windows kernel-mode drivers and WHQL submissions, and satisfies enterprise procurement requirements.

Yes. Since June 1, 2023, CA/B Forum guidelines mandate that private keys reside on FIPS 140-2 Level 2 or Common Criteria EAL 4+ hardware. You can receive a pre-configured USB token from the CA, use your own compliant HSM, or use a CA-managed cloud HSM signing service like DigiCert KeyLocker.

Maximum 460 days per issuance under CA/B Forum Ballot CSC-31. When signing, always use a timestamp authority (TSA) so your binaries remain permanently trusted even after the certificate expires.

No publicly trusted Certificate Authority issues free code signing certificates. The costs of mandatory identity vetting and certified FIPS cryptographic hardware prevent free issuance. Self-signed certificates trigger severe OS security blocks.

Any EV (Extended Validation) code signing certificate. Microsoft’s WHQL portal and Windows hardware attestation signing flow reject non-EV certificates outright.

Yes, for general cross-platform binaries, Java archives (.jar), and container packages. Note that macOS App Store distribution requires an Apple Developer ID certificate, but Linux and generic application packages accept standard CA-signed certificates.

0