Sign your software with your organization's verified name, so users see the publisher and know the file has not been modified.
Prices are per year and taken from product data. See the product page for details, delivery method and term options.
Cloud OV
Cloud OV
EV Code Signing
Cloud EVBoth show your organization name as the verified publisher and provide the same signature strength. The difference lies in the scope of validation and some platform requirements.
The standard choice for independent software developers and organizations.
For driver developers and organizations that want the most thorough validation.
Under CA/Browser Forum rules, since 1 June 2023 the private key of every code signing certificate is generated and stored in certified hardware. Certificates are not delivered as PFX files.
The key is generated on a FIPS 140-2 Level 2 certified token shipped to you. Signing is done on a computer with the token plugged in.
The key is kept in the certificate authority's HSM; no physical device is needed and you can sign from CI/CD pipelines.
Cloud code signingIf your organization has a suitably certified HSM, the key can be generated there and proven to the certificate authority via attestation.
.exe .dll .msi .cab .cat .ocx
.ps1 .psm1
PowerShell scripts and modules
.jar
Java archives (jarsigner)
Word, Excel and PowerPoint macro projects
Choose an OV or EV product and term, then complete the order.
Enter your organization and contact details in your panel; the certificate authority starts validation.
Your organization is matched against official records; a verification call and, if needed, documents are requested.
The certificate is delivered on a token or via the cloud service; you start signing with timestamps.
A digital signature is added to your software. The user's operating system shows who published the file (your verified organization name) and verifies that it has not been modified since signing. For unsigned files the publisher appears as "Unknown".
In both cases your organization is validated by the certificate authority. EV (Extended Validation) is more thorough: the organization's legal, physical and operational existence and the applicant's authority are reviewed in detail. An EV code signing certificate is required to open a Microsoft Hardware Dev Center account for signing Windows drivers.
No. Since 2024 Microsoft no longer grants automatic SmartScreen reputation to EV certificates. Reputation for OV or EV signed software builds through download and usage history; the signature ties it to your publisher identity and, compared with unsigned files, reduces warnings over time.
Under CA/Browser Forum rules, since 1 June 2023 the private key of all OV and EV code signing certificates must be generated and stored in hardware certified to FIPS 140-2 Level 2 or Common Criteria EAL 4+ (USB token, HSM or cloud signing service). Certificates cannot be delivered as a PFX file.
With Windows Authenticode you can sign .exe, .dll, .msi, .cab, .cat and .ocx files; you can also sign PowerShell scripts (.ps1), Java archives (.jar) and Microsoft Office VBA macros. macOS and iOS apps are signed with Apple Developer ID certificates and Android apps with the developer's own key; code signing certificates are not used for these platforms.
If you added a timestamp when signing, the signature stays valid after the certificate expires. Certificate authorities' timestamp servers are free; just add the timestamp URL to your signing command.
It depends on how quickly your organization details can be matched with official records. OV validation usually takes 1–3 business days and EV 1–5 business days. Having your company registration and a verifiable company phone number ready speeds things up.
Ask our team about product choice, validation documents and delivery method.