Comodo EV Code Signing Certificate: Review 2026
A genuine, high-assurance EV certificate, still the only path to Windows kernel-mode driver signing eligibility, but not the instant SmartScreen trust shortcut it used to be. Several reseller pages selling this exact certificate haven't caught up to that change.
The Claim Multiple Resellers Still Get Wrong
At least two resellers selling this exact certificate still market it as providing "instant trust" with Microsoft SmartScreen and claim it "instantly establishes image and reputation." That description stopped being accurate in March 2024.
What changed in March 2024
What EV still does that OV structurally cannot: establish Windows Hardware Developer Center Dashboard eligibility for kernel-mode driver submission. That specific capability is unchanged. Don't buy EV specifically for an instant SmartScreen bypass; that claim is outdated regardless of how many reseller pages still repeat it.
What It Actually Costs
Reseller 1-year pricing runs from $279.99 to roughly $353/yr. Multi-year pricing is only available via "Install on Existing HSM" (since February 15, 2026 for Token + Shipping changes), and requires reissuing roughly every year during the subscription period.
Is an EV Code Signing Certificate Still Worth Buying in 2026?
What changed after Microsoft's SmartScreen policy updates
As of March 2024, EV certificates no longer instantly clear SmartScreen warnings on first release. Both EV and standard (OV) signed software now build reputation over time based on download volume and behavior, not certificate tier alone.
Who actually needs EV instead of standard code signing
Publishers submitting kernel-mode drivers to Microsoft's Hardware Developer Center Dashboard, since that specific submission path requires an EV certificate. Beyond that one structural requirement, EV's practical advantage over standard OV code signing for general application distribution is narrower than it used to be.
Situations where EV is non-negotiable
Kernel-mode driver signing for Windows 10 (build 1607+) and later. This is the one place EV isn't optional: Microsoft requires it to access the Hardware Dev Center Dashboard at all, regardless of which CA you choose.
How Difficult Is the EV Validation Process?
Business verification requirements
Deeper than OV: confirmation of legal and operational existence through third-party sources, plus company address and organization type displayed in the certificate itself.
Hardware token and private key protection
Required since May/June 2023 industry-wide: the private key must be generated and stored on FIPS 140-2 Level 2 or Common Criteria EAL4+ compliant hardware. At least one reseller's page for this exact certificate still describes the key as remaining "on a server," which reflects outdated, pre-2023 policy, not the current mandate.
Typical issuance timeline
Up to 5 business days per at least one source, longer than OV, reflecting the deeper identity checks.
Common reasons applications get delayed
Standard EV bottlenecks: outdated business registration records and difficulty completing the required third-party identity confirmation quickly.
Does Comodo EV Fit Modern Software Delivery Pipelines?
Signing Windows applications
Standard Authenticode signing across the usual formats (.exe, .dll, .msi, .cab, .ocx, .xpi, .xap), no unusual friction relative to any other CA's EV certificate.
Driver signing and Microsoft requirements
The certificate's clearest structural advantage: required for kernel-mode driver submission to the Windows Hardware Dev Center Dashboard.
Using EV certificates in CI/CD pipelines
A real, specific limitation worth knowing before you set up automation: at least one current source states directly that a USB-token-based certificate cannot be accessed over Remote Desktop. Signing requires the token physically connected to the machine running the build. For automated pipelines (GitHub Actions, Azure DevOps, Jenkins), the HSM installation option supports remote and cloud-based signing instead. Confirm HSM compatibility with your specific environment before ordering.
Working around hardware token limitations
Choosing HSM delivery over a physical USB token from the outset avoids the RDP limitation entirely for teams building genuinely automated, remote pipelines.
Does EV Actually Improve Software Trust Today?
Verified Publisher experience
Genuine: the verified organization name, address, and type appear in the certificate and are checkable by users who look.
What users see during installation
The verified publisher name instead of "Unknown Publisher," the same practical outcome OV eventually achieves too, once it builds enough download reputation.
SmartScreen reputation reality
This is where marketing and Microsoft's actual current behavior diverge sharply across the reseller ecosystem. Multiple resellers selling this exact certificate still advertise "instant trust with Microsoft SmartScreen." The more recent, specifically-dated source (March 2024) is the one consistent with Microsoft's actual documented policy change. Both descriptions cannot be accurate simultaneously. Don't buy EV specifically for an instant SmartScreen bypass.
Timestamping and long-term signature validation
Standard RFC 3161 timestamping keeps signatures valid after the certificate itself expires; use it on every signature.
Where SSL.com Has the Advantage
Cloud-based signing without managing USB tokens
SSL.com's eSigner platform is built specifically around cloud signing from the ground up, a genuinely different starting design than a token-first CA offering cloud signing as an add-on option.
eSigner for distributed development teams
Useful if your signers are spread across locations without a shared physical token to pass around.
Better fit for automated release pipelines
If your entire release process runs on ephemeral cloud infrastructure with no persistent build machine, a cloud-native signing platform avoids the RDP/token limitation by design, not as a workaround.
When we'd recommend SSL.com instead
Teams starting fresh with no existing token or HSM infrastructure, prioritizing a simple, cloud-first setup over price.
Where Comodo EV Still Makes More Sense
Organizations with traditional signing infrastructure
If you already have a token or HSM-based workflow, there's limited reason to switch CAs purely for a cloud-signing feature you may not need.
Teams that already use hardware tokens
The physical-token workflow isn't a drawback if it's already how your team operates.
Budget-conscious enterprise software vendors
Pricing here runs roughly $279 to $353 per year across the resellers checked, generally below DigiCert's equivalent EV tier.
Comodo EV Code Signing vs Other Enterprise Certificates
vs SSL.com EV Code Signing
SSL.com's real differentiator is cloud-first signing infrastructure; Comodo's is more traditional token/HSM delivery. Comparable price bands; choose based on your actual pipeline architecture.
vs DigiCert EV Code Signing
DigiCert prices meaningfully higher for comparable validation depth; the difference is platform (DigiCert's KeyLocker) and brand recognition, not certificate mechanics.
vs Sectigo EV Code Signing
These aren't two separate options to choose between. Comodo CA rebranded to Sectigo in November 2018; this certificate is issued by Sectigo under the legacy Comodo product name, with an identical validation process, root trust chain, and technical specification to the Sectigo-branded listing. If a reseller sells both names, confirm they're not simply reselling the same certificate under two labels before treating it as a real comparison.
| Comodo EV | SSL.com EV | DigiCert EV | Sectigo EV | |
|---|---|---|---|---|
| Validation | EV | EV | EV | EV (same CA) |
| SmartScreen bypass | No (removed March 2024) | No | No | No |
| Driver signing eligible | Yes | Yes | Yes | Yes |
| Cloud signing | Token/HSM (RDP limitation) | eSigner cloud-first | KeyLocker | Token/HSM |
| Price range | $279 to $353/yr | Competitive | Higher ($352 to $498) | Same (identical CA) |
What We Liked, What We Didn't, and Who Should Buy It
Biggest strengths
- Genuine, structurally necessary path to kernel-mode driver signing eligibility via Dev Center Dashboard
- Competitive pricing relative to DigiCert for identical validation depth
- Broad platform and file-format compatibility (.exe, .dll, .msi, .cab and more)
- Free RFC 3161 timestamping keeps signatures valid past certificate expiration
Biggest weaknesses
- Multiple resellers selling this exact certificate still market an "instant SmartScreen trust" claim that stopped being accurate in March 2024
- At least one reseller also still describes outdated pre-2023 key storage policy; OV and EV both require hardware now
- USB token cannot be used over Remote Desktop; HSM delivery is required for automated/remote pipelines
- "Comodo vs Sectigo" framing at some resellers obscures that these are the same CA infrastructure
Best fit organizations
- Driver publishers needing Dev Center Dashboard eligibility
- Organizations with existing token/HSM infrastructure not looking to switch platforms
- Budget-conscious publishers below DigiCert's price threshold
Consider an alternative
- Teams building entirely around ephemeral cloud CI/CD; SSL.com's eSigner integrates more naturally
- Anyone specifically buying EV for a SmartScreen advantage; that advantage no longer exists
- Fully distributed teams needing RDP-accessible signing; use HSM delivery, not USB token
Frequently Asked Questions
Final Verdict
A structurally sound EV code signing certificate, still the only route to kernel-mode driver signing eligibility, priced competitively against DigiCert. Its biggest problem isn't the certificate: it's that the reseller ecosystem selling it hasn't caught up. Multiple pages still market an "instant SmartScreen trust" claim that stopped being accurate in March 2024, and at least one still describes key-storage policy that predates the 2023 hardware mandate.
Buy this for driver-signing eligibility or existing token infrastructure. If you're building a fully automated cloud pipeline, plan for HSM delivery from the start rather than discovering the RDP limitation after the USB token arrives.
