Code signing certificate — from 293,90 € a year
Sign your app, installer or driver: Windows stops scaring users with «Unknown publisher»
Buy a code signing certificate for 293,90 €
A code signing certificate attaches a digital signature with your verified company name to an application, installer, script or driver. Users see the publisher name instead of the red Windows warning, antivirus engines are less suspicious of a new file, and any tampering after signing breaks the signature. Price — from €293.90 a year. Organisation validation takes 1–5 business days. Since 1 June 2023 industry rules require the signing key to live on a hardware token or in a cloud HSM — that applies to standard certificates too, not only EV. The catalogue holds six products from Sectigo, Comodo and DigiCert, in standard and EV versions.
Code signing certificates
Six products from three authorities: standard organisation validation and extended (EV)
| Certificate | Validation and issuance | What it secures | Warranty | Price | |
|---|---|---|---|---|---|
| Comodo Code Signing Sectigo |
— | One domain and its www | — |
€293.90
per year | Order |
| Sectigo Code Signing Sectigo |
— | One domain and its www | — |
€293.90
per year | Order |
| Comodo EV Code Signing Sectigo |
— | One domain and its www | — |
€384.90
per year | Order |
| Sectigo EV Code Signing Sectigo |
— | One domain and its www | — |
€384.90
per year | Order |
| DigiCert Code Signing DigiCert |
— | One domain and its www | — |
€402.90
per year | Order |
| DigiCert EV Code Signing DigiCert |
— | One domain and its www | — |
€563.90
per year | Order |
The hardware token and its delivery are quoted separately — industry rules require one unless you already have a compliant device or a cloud HSM.
What a signature gives you
Three things the user and the system can check
Publisher name
Windows shows your verified company name at launch instead of «Unknown publisher».
File integrity
Any edit breaks the signature, so a tampered installer is told apart from yours.
SmartScreen reputation
Signed files build reputation with Microsoft's filter; an EV certificate grants it from day one.
How it works
From order to a signed file
Order and organisation validation
The authority confirms the company through a registry and an independent phone source. Usually 1–5 business days.
Key on a secure device
Industry rules keep the key on a hardware token (FIPS 140-2 Level 2 or higher) or in the authority's cloud HSM. The token is shipped to you, or you use your own.
Signing
You sign with the usual tools: signtool on Windows, jarsigner for Java, your build tooling for installers.
Verification by the user
Windows shows the publisher name in the User Account Control prompt, and Explorer adds a «Digital Signatures» tab to the file.
Standard or EV: which to take
The difference is not the strength of the signature but the validation — and how Windows treats the file.
- Standard (OV) — from €293.90 a year. Fits applications, installers, PowerShell scripts and Office add-ins. SmartScreen reputation builds up with downloads.
- EV — from €384.90 a year. Extended company validation and SmartScreen reputation from the first day. Required for Windows kernel-mode drivers: without it a driver cannot be attested through the Microsoft Hardware Dev Center.
Not sure which one fits your case — write to us and we will work it out before you pay.
Ask supportFrequently asked questions
Tokens, timing, drivers and signing in CI
Without a signature Windows and SmartScreen warn about an «Unknown publisher», and some corporate policies block the file outright. With one, the user sees your company name.
Yes. Since 1 June 2023 CA/Browser Forum rules require the signing key to sit on a token certified to FIPS 140-2 Level 2 or higher, or in the authority's cloud HSM. This applies to standard certificates, not only EV.
Validation is stricter and SmartScreen reputation is there from the start, without accumulating downloads. For Windows kernel-mode drivers EV is mandatory.
Usually 1–5 business days: the authority verifies the organisation through a registry and an independent contact source, then issues the certificate to the device.
Yes, but a kernel-mode driver needs an EV certificate and attestation through the Microsoft Hardware Dev Center — the certificate alone does not sign the kernel.
No. macOS applications are signed with an Apple Developer ID certificate, issued by Apple only.
Through the authority's cloud signing or a network HSM: a physical token cannot be plugged into a build server. Tell us about your pipeline and we will pick an option.
If the signature carries a timestamp, the files stay trusted after expiry. New files can no longer be signed — you need a renewed certificate.