Code Signing Certificate
Code Signing Product
Standard Code Signing
Certum Standard Code Signing certificate.
Identifies the software publisher and helps protect signed files from modification.
Designed for common software signing workflows.
Sectigo Code Signing
Sectigo Code Signing certificate.
Identifies the software publisher and helps protect signed files from modification.
Supports common software formats including Windows, Java, Office, Adobe AIR, and more.
Sectigo EV Code Signing
Sectigo EV Code Signing certificate.
Identifies the software publisher and helps protect signed files from modification.
Uses stronger Extended Validation and includes USB token delivery.
What Code Signing Does ​
Publisher identity
Code signing helps users confirm that software comes from a trusted publisher.
File integrity
A valid signature helps prove that the software has not been changed after signing.
Better installation experience
Signed software can reduce unknown publisher warnings and helps build reputation with Microsoft SmartScreen over time.
Validation Process ​
Standard validation
Standard code signing verifies the software publisher before issuance. Company orders may require company registration and contact verification. Individual developer orders verify personal identity instead.
Extended validation
EV Code Signing is designed for businesses and requires deeper company verification through official records or trusted third-party sources.
Possible follow-up
You may be asked to provide documents, complete identity verification, or confirm the request by phone or email.
Certificate Details ​
- Certificate Brand
- Certum / Sectigo
- Certificate Type
- Standard Code Signing / Sectigo Code Signing / Sectigo EV Code Signing
- Best For
- Software publishers, developers, and application vendors
- Validation
- Standard Code Signing validation or Extended Validation, depending on the product
- Key Storage
- Certum normally uses SimplySign. Sectigo Standard requires compliant hardware key storage. Sectigo EV is delivered with a USB token after validation.
- Physical Token
- Certum normally does not require a USB token or card reader. Sectigo Standard normally requires a compliant token or HSM. Sectigo EV includes USB token delivery after validation.
- Certificate Standard
- X.509 v3
- Key Algorithm
- RSA 3072-bit minimum
- Certificate Validity
- Starting February 27, 2026, a single code signing certificate may be valid for up to 459 days. Multi-year products may require certificate reissue during the service term.
- Monthly Signing Limit
- Up to 5,000 signatures per month
- Compatibility
- Microsoft Windows, Java, Linux/Unix tools, macOS tools, and common software formats such as .exe, .msi, .dll, .jar, and .war
- Requirements
- SimplySign mobile app, SimplySign desktop app, SimplySign cloud account, and internet access
FAQ ​
Do I need to verify company information?
If the certificate is ordered under a company name, the certificate authority may verify company registration, address, and contact information before issuance. If you apply as an individual developer, company information is not required; your personal identity will be verified instead.
Do I need a USB token or smart card reader?
For Certum, a physical USB token or smart card reader is normally not required. Sectigo Standard Code Signing normally requires a dedicated security token or HSM. Sectigo EV Code Signing includes USB token delivery after validation.
Will this remove unknown publisher warnings?
A code signing certificate identifies the software publisher and can help reduce unknown publisher warnings. Microsoft SmartScreen reputation may still need to build over time.
Can I sign software from different operating systems?
Yes. The certificate can be used with supported signing tools on Windows, Linux/Unix, and macOS environments.
What happens with multi-year service terms?
The service term may be longer than a single certificate validity period. When required by industry rules, a new certificate may need to be reissued during the active service term.
