Protect your applications and software releases with authentic publisher validation.
$441,18 – $676,47Price range: $441,18 through $676,47
Two validation tiers exist, and the choice comes down to who signs and what types of software you distribute.
The standard tier for software publishing. Vets the legal existence of registered companies or verified individual developers. Eliminates 'Unknown Publisher' security blocks for Windows user-mode applications, Java JARs, scripts, and macros.
Deepest organizational verification under CA/B Forum EV guidelines. Only registered organizations qualify. EV is mandatory for signing Windows kernel-mode drivers and Microsoft WHQL portal attestation submissions.
Following Microsoft Trusted Root Program updates, reputation now accumulates by file hash and download volume across both OV and EV tiers. EV no longer grants instant bypass—both tiers build trust seamlessly in the wild.
Under CA/B Forum regulations, private keys must reside on hardware meeting FIPS 140-2 Level 2 or Common Criteria EAL 4+.
The Certificate Authority mails a pre-loaded FIPS 140-2 Level 2 USB crypto token (typically a YubiKey) directly to your verified business address. Ideal for occasional manual signing.
Private keys reside in secure, CA-managed cloud HSMs (such as DigiCert KeyLocker or Sectigo Cloud Signing). Zero physical tokens to lose, seamless API access, and perfect for automated CI/CD pipelines.
If your team already operates an on-premise FIPS 140-2 Level 2 or Common Criteria EAL 4+ HSM, the CA issues against cryptographic attestation directly from your device.
A single certificate secures binaries, packages, drivers, and macros across all major developer environments:
.exe, .dll, .cab, .ocx, .msi, and .xap files signed with Microsoft Authenticode for complete OS verification.
User-mode drivers (OV or EV) and kernel-mode drivers (EV required for Microsoft WHQL portal attestation).
.jar files signed with jarsigner, Android application packages, and cross-platform runtime bundles.
PowerShell scripts, VBScript, Microsoft Office VBA macros, IoT firmware updates, and container packages.
What software developers need to know about the current validity guidelines:
Under CA/Browser Forum Ballot CSC-31, publicly trusted code signing certificates have a maximum validity of 460 days (~15 months). Multi-year orders remain available on Renewal SSL, locking in lower rates while certificates are reissued during the purchased subscription.
Always include an RFC 3161 compliant timestamp server when signing (tsa.digicert.com or timestamp.sectigo.com). Timestamping proves your binary was signed while the certificate was valid, ensuring Windows continues to trust your software long after certificate expiration.
Common questions about this certificate type, validation standards, and deployment.
It is an X.509 digital certificate that allows software developers and organizations to attach a cryptographic signature to executables, scripts, and drivers. It verifies publisher identity and ensures code has not been altered or corrupted since it was signed.
OV (Organization Validation) confirms the publisher’s registered business identity (or individual identity) and is ideal for user-mode software, scripts, and plugins. EV (Extended Validation) undergoes strict organizational vetting, is required by Microsoft for Windows kernel-mode drivers and WHQL submissions, and satisfies enterprise procurement requirements.
Yes. Since June 1, 2023, CA/B Forum guidelines mandate that private keys reside on FIPS 140-2 Level 2 or Common Criteria EAL 4+ hardware. You can receive a pre-configured USB token from the CA, use your own compliant HSM, or use a CA-managed cloud HSM signing service like DigiCert KeyLocker.
Maximum 460 days per issuance under CA/B Forum Ballot CSC-31. When signing, always use a timestamp authority (TSA) so your binaries remain permanently trusted even after the certificate expires.
No publicly trusted Certificate Authority issues free code signing certificates. The costs of mandatory identity vetting and certified FIPS cryptographic hardware prevent free issuance. Self-signed certificates trigger severe OS security blocks.
Any EV (Extended Validation) code signing certificate. Microsoft’s WHQL portal and Windows hardware attestation signing flow reject non-EV certificates outright.
Yes, for general cross-platform binaries, Java archives (.jar), and container packages. Note that macOS App Store distribution requires an Apple Developer ID certificate, but Linux and generic application packages accept standard CA-signed certificates.
The premier marketplace for seamless SSL certificate issuance, renewal, and website trust management worldwide.
Global Certificate Distribution Hub
Support: support@renewalssl.com
Knowledge Base & Guides
CSR Generator Guide
Contact Support Team
Client Portal Login
View Shopping Cart
Quick Checkout
© 2026 RenewalSSL.com. All rights reserved.
Next-gen PKI platform. Manage digital trust at enterprise scale.
Automate the full certificate lifecycle. Stay secure and compliant.
Simplify certificate lifecycle management across your entire network.
Automate the full certificate lifecycle. Stay secure and compliant.
Protect software supply chains. Ensure secure code delivery.
Digitally sign and validate documents. Preserve integrity and origin.