Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
  1. Home
  2. Code Signing Certificates
Code Signing

Code Signing Certificates

Sign your software with your organization's verified name, so users see the publisher and know the file has not been modified.

  • Organization validated (OV / EV)
  • Hardware key protection
  • Lasting signatures with timestamping
Annual starting price (excl. VAT): OV $100.00 · EV $341.10
Products

Code signing certificate prices

Prices are per year and taken from product data. See the product page for details, delivery method and term options.

Cloud OV

Certum Open Source Code Signing in the Cloud

For Individual Open Source Developers (“Open Source Developer” Prefix) SimplySign Cloud Solution - No Physical Card Required Microsoft Authenticode Compatible 1 Year Validity
$100.00/yr · excl. VAT
View
Cloud OV

Certum Standard Code Signing in the Cloud

Individual & Business Use SimplySign Cloud Solution - No Physical Card Required Microsoft Authenticode & Java Compatible 1-3 Year Term Options (Certificate Up to 459 Days)
$180.00/yr · excl. VAT
View
EV Code Signing
Popular

GoGetSSL EV Code Signing

Type: EV (Extended Validation) Key Storage: USB Token Signature Algorithm: SHA‑256 File Types: EXE, DLL, MSI, OCX, JAR, AIR, XPI, etc.
$341.10/yr · excl. VAT
View
Cloud EV

Certum EV Code Signing in the Cloud

Extended Validation (EV) SimplySign Cloud Solution - No Physical Card Required SmartScreen Reputation Builds Over Time Microsoft Authenticode & Java Compatible
$415.00/yr · excl. VAT
View
OV Code Signing

DigiCert Code Signing SSL

Validation Type: OV (Documents Required) Key: 3072+ bit RSA or ECC Algorithm: SHA-256 Timestamping: Included
$438.24/yr · excl. VAT
View
EV Code Signing

Sectigo EV Code Signing SSL

Certificate Type: Extended Validation (EV) Key Storage: USB Token (FIPS 140-2 Level 2) Signature Algorithm: SHA-256 File Support: .exe, .dll, .cab, .msi, .ocx, .xpi, .xap, .jar, .air etc.
$453.00/yr · excl. VAT
View
EV Code Signing

DigiCert EV Code Signing Certificate

Type: EV (Extended Validation) Signature: SHA-256 Key: 3072+ bit RSA or ECC Delivery: Hardware USB Token
$617.52/yr · excl. VAT
View
Comparison

OV or EV?

Both show your organization name as the verified publisher and provide the same signature strength. The difference lies in the scope of validation and some platform requirements.

OV Code Signing

Organization Validation

The standard choice for independent software developers and organizations.

  • The organization's existence and contact details are validated
  • Validation usually takes 1–3 business days
  • Key on a USB token, HSM or cloud signing service
  • Authenticode, PowerShell, Java and Office VBA signing
From$100.00 / yr
OV products

EV Code Signing

Extended Validation

For driver developers and organizations that want the most thorough validation.

  • Legal, physical and operational existence and the applicant's authority are validated in detail
  • Validation usually takes 1–5 business days
  • Required for a Microsoft Hardware Dev Center (Windows driver signing) account
  • Key on a USB token, HSM or cloud signing service
From$341.10 / yr
EV products
SmartScreen: since 2024 Microsoft no longer grants automatic reputation to EV certificates. Reputation for OV or EV signed software builds through download and usage history; the signature ties that reputation to your publisher identity.
Key security

Your private key is protected in hardware

Under CA/Browser Forum rules, since 1 June 2023 the private key of every code signing certificate is generated and stored in certified hardware. Certificates are not delivered as PFX files.

USB token

The key is generated on a FIPS 140-2 Level 2 certified token shipped to you. Signing is done on a computer with the token plugged in.

Cloud signing

The key is kept in the certificate authority's HSM; no physical device is needed and you can sign from CI/CD pipelines.

Cloud code signing

Your own HSM

If your organization has a suitably certified HSM, the key can be generated there and proven to the certificate authority via attestation.

Use cases

What can you sign?

Windows Authenticode

.exe .dll .msi .cab .cat .ocx

PowerShell

.ps1 .psm1

PowerShell scripts and modules

Java

.jar

Java archives (jarsigner)

Office VBA

Word, Excel and PowerPoint macro projects

macOS and iOS apps are signed with Apple Developer ID certificates and Android apps with the developer's own key; code signing certificates are not used for these platforms. Windows kernel drivers are additionally signed by Microsoft (Hardware Dev Center).
Process

How do ordering and validation work?

1

Choose the certificate

Choose an OV or EV product and term, then complete the order.

2

Organization details

Enter your organization and contact details in your panel; the certificate authority starts validation.

3

Validation

Your organization is matched against official records; a verification call and, if needed, documents are requested.

4

Delivery and signing

The certificate is delivered on a token or via the cloud service; you start signing with timestamps.

FAQ

Frequently asked questions

What does a code signing certificate do?

A digital signature is added to your software. The user's operating system shows who published the file (your verified organization name) and verifies that it has not been modified since signing. For unsigned files the publisher appears as "Unknown".

What is the difference between OV and EV code signing?

In both cases your organization is validated by the certificate authority. EV (Extended Validation) is more thorough: the organization's legal, physical and operational existence and the applicant's authority are reviewed in detail. An EV code signing certificate is required to open a Microsoft Hardware Dev Center account for signing Windows drivers.

Does an EV certificate remove the SmartScreen warning immediately?

No. Since 2024 Microsoft no longer grants automatic SmartScreen reputation to EV certificates. Reputation for OV or EV signed software builds through download and usage history; the signature ties it to your publisher identity and, compared with unsigned files, reduces warnings over time.

Why is the private key kept on a USB token or in the cloud?

Under CA/Browser Forum rules, since 1 June 2023 the private key of all OV and EV code signing certificates must be generated and stored in hardware certified to FIPS 140-2 Level 2 or Common Criteria EAL 4+ (USB token, HSM or cloud signing service). Certificates cannot be delivered as a PFX file.

Which files can I sign?

With Windows Authenticode you can sign .exe, .dll, .msi, .cab, .cat and .ocx files; you can also sign PowerShell scripts (.ps1), Java archives (.jar) and Microsoft Office VBA macros. macOS and iOS apps are signed with Apple Developer ID certificates and Android apps with the developer's own key; code signing certificates are not used for these platforms.

What happens to my signed software when the certificate expires?

If you added a timestamp when signing, the signature stays valid after the certificate expires. Certificate authorities' timestamp servers are free; just add the timestamp URL to your signing command.

How long does validation take?

It depends on how quickly your organization details can be matched with official records. OV validation usually takes 1–3 business days and EV 1–5 business days. Having your company registration and a verifiable company phone number ready speeds things up.

Not sure which certificate is right for you?

Ask our team about product choice, validation documents and delivery method.