Comodo EV Code Signing Review 2026
Issued by Sectigo under the legacy Comodo brand. Sits at the top of the code signing line, priced roughly $60 to $100 above the OV tier. Since the 2023 hardware key mandate closed the biggest technical gap between EV and OV, here is what still justifies the premium.
What EV Adds Over Standard Code Signing
Before June 2023, EV Code Signing carried one enormous practical advantage over OV: a mandatory hardware-stored private key, while OV certificates typically shipped as server-installable software keys. The CA/Browser Forum closed that gap by requiring hardware key storage for every code signing certificate regardless of tier.
What EV still adds is a deeper identity check, confirming the organization's physical operating address and the specific authority of the person requesting the certificate, beyond the registration check OV performs. It also remains the only tier Microsoft accepts for one specific, non-negotiable use case: signing Windows kernel-mode drivers.
Who Can Actually Buy This Certificate
This is worth stating plainly since it rules out an entire category of buyers immediately: EV Code Signing is issued to registered business entities only. No exceptions exist.
Who can and cannot get EV Code Signing
How Business Verification Works
EV verification runs deeper than OV across the same general structure, adding physical address confirmation and authorization checks that OV does not perform. Resellers generally quote 5 to 7 business days from order to signed file, longer than the 1 to 3 day window typical of OV Code Signing.
Legal Existence Verification
Confirms business registration against government or third-party registries, typically including a D-U-N-S number. This step confirms the organization is a real, legally registered entity, the same check OV performs as its primary step.
Physical Address Verification
Confirms the business operates at its stated address through independent verification sources. This step is specific to EV and has no equivalent in OV Code Signing validation.
Authorization and Telephone Verification
Confirms the requestor is specifically authorized to obtain the certificate on the organization's behalf. This named-individual authorization check is another EV-specific step that OV does not perform at the same depth.
Hardware Token Provisioning
A FIPS 140-2 Level 2 compliant USB token is shipped, or the certificate is installed on an existing HSM. Teams with existing HSM infrastructure skip physical shipping entirely and receive the certificate directly.
Certificate Specifications
Kernel Driver Signing: The One Thing Only EV Does
Microsoft requires all kernel-mode drivers targeting Windows 10 build 1607 and later to be submitted through the Windows Hardware Developer Center Dashboard for Microsoft co-signing.
Why OV cannot substitute here
The Windows Hardware Developer Center Dashboard grants access only to accounts holding a valid EV Code Signing certificate. This is a hard requirement, not a recommendation, and it has no OV workaround regardless of how the certificate is configured or what documentation the developer provides.
Any developer building kernel-mode drivers, filter drivers, or similarly low-level Windows components needs EV for this reason alone, independent of any other feature comparison between the tiers. If kernel driver signing is the use case, the decision is already made.
What It Actually Costs
The spread here is narrower than on most SSL products in the Comodo line, since EV Code Signing validation and hardware requirements are largely standardized across resellers at this tier. The main variable is whether additional support through validation and installation is bundled in.
Key Changes for 2026
Code signing certificates moved onto a shorter validity cycle ahead of the broader SSL/TLS industry. Effective February 15, 2026, the CA/Browser Forum capped maximum validity for all newly issued or reissued code signing certificates at one year.
Annual Reissuance Under the 459-Day Cap
A multi-year plan still bills up front and locks in pricing, but the certificate itself reissues annually onto the same hardware token or HSM throughout the subscription term. Because EV already required more paperwork than OV, the annual reissuance cycle affects EV holders more directly in practice, since revalidating requestor authorization and business details happens more often than it did under the older multi-year validity window.
Renew Before Expiry to Avoid Kernel Driver Signing Gaps
For kernel driver developers specifically, a gap in EV certificate coverage means a gap in Hardware Developer Center Dashboard access. Renewing before the current certificate lapses, rather than after, avoids that disruption. Email reminders typically arrive 30 days before reissuance comes due.
Where It Wins and Loses
Where It Wins
- The only certificate type Microsoft accepts for Windows kernel-mode driver signing and Dashboard access
- Deeper verification of physical address and requestor authorization than OV provides
- Free timestamping keeps signatures valid indefinitely past certificate expiration
- Builds Microsoft SmartScreen reputation faster than OV, even though neither tier bypasses it instantly
Where It Loses
- Individuals and unregistered businesses cannot obtain this certificate under any circumstances
- Issuance takes 5 to 7 business days, longer than OV's typical 1 to 3 day window
- No longer provides an instant SmartScreen warning bypass since March 2024
- Costs $60 to $100 more per year than OV for capabilities most non-driver developers will never use
- Same annual reissuance burden as OV under the 2026 validity cap, despite heavier original vetting
EV vs. OV Code Signing: What Justifies the Premium in 2026
With the 2023 hardware key mandate applying equally to both tiers, the decision comes down to three factors: eligibility, kernel driver access, and SmartScreen reputation speed — not private key security.
EV Code Signing — this page
OV Code Signing
Ideal Use Cases
Kernel-Mode Driver Developers
This is not optional for this use case. Windows Hardware Developer Center Dashboard access requires EV, with no OV substitute available at any price.
Large Enterprises Prioritizing Fast Reputation
Organizations distributing software at high volume benefit from EV's faster SmartScreen reputation buildup relative to OV, reducing the window where download warnings appear.
Businesses Needing Documented Requestor Authorization
Companies where an audit trail confirming exactly who was authorized to obtain the certificate matters for internal compliance or governance requirements.
Individual Developers and Sole Proprietors
EV Code Signing cannot be issued to individuals under any circumstances. OV Code Signing is the only available path for this group and works for all non-kernel signing use cases.
Budget-Conscious Small Software Publishers
OV Code Signing delivers verified publisher identity and the same hardware key protection at a meaningfully lower price for anyone not building kernel drivers.
Anyone Expecting Instant SmartScreen Trust
That instant bypass ended in March 2024. Both tiers now build reputation over time based on signing volume and user behavior. Set that expectation correctly before purchasing either tier.
Frequently Asked Questions
Ready to Compare Code Signing Certificates?
Comodo EV Code Signing is a requirement for kernel-mode driver developers, and a premium most other developers can skip in favour of OV. Compare both tiers directly to see which one matches your signing needs.
