Code signing certificate — from 293,90 € a year

Sign your app, installer or driver: Windows stops scaring users with «Unknown publisher»

Buy a code signing certificate for 293,90 €
Code signing: your company name instead of «Unknown publisher»

A code signing certificate attaches a digital signature with your verified company name to an application, installer, script or driver. Users see the publisher name instead of the red Windows warning, antivirus engines are less suspicious of a new file, and any tampering after signing breaks the signature. Price — from €293.90 a year. Organisation validation takes 1–5 business days. Since 1 June 2023 industry rules require the signing key to live on a hardware token or in a cloud HSM — that applies to standard certificates too, not only EV. The catalogue holds six products from Sectigo, Comodo and DigiCert, in standard and EV versions.

Code signing certificates

Six products from three authorities: standard organisation validation and extended (EV)

Certificate Validation and issuance What it secures Warranty Price
Comodo Code Signing
Sectigo
One domain and its www 293.90
per year
Order
Sectigo Code Signing
Sectigo
One domain and its www 293.90
per year
Order
Comodo EV Code Signing
Sectigo
One domain and its www 384.90
per year
Order
Sectigo EV Code Signing
Sectigo
One domain and its www 384.90
per year
Order
DigiCert Code Signing
DigiCert
One domain and its www 402.90
per year
Order
DigiCert EV Code Signing
DigiCert
One domain and its www 563.90
per year
Order

The hardware token and its delivery are quoted separately — industry rules require one unless you already have a compliant device or a cloud HSM.

What a signature gives you

Three things the user and the system can check

1

Publisher name

Windows shows your verified company name at launch instead of «Unknown publisher».

2

File integrity

Any edit breaks the signature, so a tampered installer is told apart from yours.

3

SmartScreen reputation

Signed files build reputation with Microsoft's filter; an EV certificate grants it from day one.

How it works

From order to a signed file

1

Order and organisation validation

The authority confirms the company through a registry and an independent phone source. Usually 1–5 business days.

2

Key on a secure device

Industry rules keep the key on a hardware token (FIPS 140-2 Level 2 or higher) or in the authority's cloud HSM. The token is shipped to you, or you use your own.

3

Signing

You sign with the usual tools: signtool on Windows, jarsigner for Java, your build tooling for installers.

4

Verification by the user

Windows shows the publisher name in the User Account Control prompt, and Explorer adds a «Digital Signatures» tab to the file.

Standard or EV: which to take

Standard or EV: which to take

The difference is not the strength of the signature but the validation — and how Windows treats the file.

  • Standard (OV) — from €293.90 a year. Fits applications, installers, PowerShell scripts and Office add-ins. SmartScreen reputation builds up with downloads.
  • EV — from €384.90 a year. Extended company validation and SmartScreen reputation from the first day. Required for Windows kernel-mode drivers: without it a driver cannot be attested through the Microsoft Hardware Dev Center.

Not sure which one fits your case — write to us and we will work it out before you pay.

Ask support

Frequently asked questions

Tokens, timing, drivers and signing in CI

Without a signature Windows and SmartScreen warn about an «Unknown publisher», and some corporate policies block the file outright. With one, the user sees your company name.

Yes. Since 1 June 2023 CA/Browser Forum rules require the signing key to sit on a token certified to FIPS 140-2 Level 2 or higher, or in the authority's cloud HSM. This applies to standard certificates, not only EV.

Validation is stricter and SmartScreen reputation is there from the start, without accumulating downloads. For Windows kernel-mode drivers EV is mandatory.

Usually 1–5 business days: the authority verifies the organisation through a registry and an independent contact source, then issues the certificate to the device.

Yes, but a kernel-mode driver needs an EV certificate and attestation through the Microsoft Hardware Dev Center — the certificate alone does not sign the kernel.

No. macOS applications are signed with an Apple Developer ID certificate, issued by Apple only.

Through the authority's cloud signing or a network HSM: a physical token cannot be plugged into a build server. Tell us about your pipeline and we will pick an option.

If the signature carries a timestamp, the files stay trusted after expiry. New files can no longer be signed — you need a renewed certificate.