DigiCert Code Signing Certificate: Review 2026
A technically solid certificate with a real use case for kernel-mode driver signing, priced above comparable OV and EV certificates from Sectigo and Certum for the same underlying security properties.
What Is DigiCert Code Signing Certificate?
A digital certificate that attaches a cryptographic signature to executables, installers, scripts, drivers, and Java or Adobe AIR applications, proving the code came from a verified publisher and hasn't been altered since signing. DigiCert issues two tiers: Standard (OV), which verifies organizational registration, and EV, which adds deeper identity checks and requires the private key to live on FIPS-compliant hardware.
Certificate Specifications at a Glance
| Spec | Standard (OV) | EV |
|---|---|---|
| Validation | Organization Validation | Extended Validation |
| Certificate type | Authenticode | Authenticode + EV |
| Max validity | 459 to 460 days (2026 CA/B Forum cap) | Same |
| Warranty | Varies by reseller | Varies by reseller |
| Supported platforms | Windows, macOS, Java, Adobe AIR | Same, plus kernel-mode drivers |
| Key storage | Hardware token or HSM (mandatory since June 2023) | Hardware token or HSM (mandatory) |
| Signature types | SHA-256 Authenticode | SHA-256 Authenticode, EV attestation for Dev Center |
Security Features Reviewed
Identity verification
OV confirms legal business registration. EV adds physical address confirmation, a callback to a publicly listed phone number, and confirmation of the requestor's authority to act for the organization. This is a real, human-verified process, not an automated check.
Digital signature security
Standard SHA-256 Authenticode signing across both tiers. The signature itself is cryptographically identical in strength between OV and EV; what differs is the identity behind it and, for EV, the hardware guarantee on the private key.
Timestamping support
Both tiers support RFC 3161 timestamping. A properly timestamped signature remains valid after the certificate itself expires, since the timestamp proves the code was signed while the certificate was still valid. Skipping this step means your signed software becomes untrusted the day the certificate expires, regardless of when it was actually signed.
Hardware-protected private keys
Since June 2023, CA/Browser Forum rules require both OV and EV code signing keys to be generated and stored on FIPS 140-2 Level 2 hardware, non-exportable by design. This is an industry-wide requirement, not a DigiCert-specific feature, but it is a genuine security property: the private key physically cannot be copied off the token or HSM.
Certificate revocation
Standard CRL and OCSP-based revocation if a key is compromised. Revoking a code signing certificate doesn't retroactively invalidate software signed before the compromise was discovered, provided that software was properly timestamped.
Signing Capabilities and Platform Compatibility
Windows applications
Full Authenticode support via SignTool for .exe, .msi, .dll, and similar binaries. No platform-specific limitation.
Drivers
EV specifically is required to establish a Windows Hardware Dev Center Dashboard account for kernel-mode driver submission. Microsoft's own documentation notes that once that account exists, individual submissions can technically use a standard Authenticode certificate, but establishing the account itself requires EV.
Java applications
Supported via jarsigner, standard across both tiers.
Adobe documents and applications
Adobe AIR application signing is supported. This certificate does not cover Adobe's own Approved Trust List for PDF document signing; that is a separate certificate category with different requirements.
Scripts and executables
PowerShell scripts and similar can be signed the same way as binaries, though OS-level enforcement of script signature checking varies by environment configuration.
Certificate Validation Process
Organization Validation
Confirms the requesting organization is legally registered and in good standing. Typically clears in 1 to 3 business days when registration details are current and publicly verifiable.
Extended Validation
Adds legal, physical, and operational existence checks, plus phone verification of the requestor's authority. Realistically 3 to 5 business days, not counting shipping time for the physical hardware token.
Required business verification
Business registration documents, government-issued photo ID for the requestor, and often a secondary document (utility bill or equivalent) confirming address. EV additionally requires a callback to a number independently verified against a public directory, not one supplied by the applicant.
Certificate Lifecycle Management
Issuance
OV completes once documentation and domain-independent business checks clear. EV additionally waits on physical token shipment before signing can begin.
Renewal
Manual reissuance required within the 459 to 460 day validity window. No code signing certificate on the market currently avoids this under 2026 rules.
Reissue
Generally included at no extra cost within the certificate's term; confirm with your specific reseller since policies vary.
Revocation
Standard CRL/OCSP process if the private key is compromised or the certificate needs to be invalidated early.
Installation and Deployment Experience
Hardware token setup
EV ships as a physical USB token; the signing machine needs the token physically inserted for every signing operation unless routed through KeyLocker's cloud path instead.
Cloud HSM support
DigiCert KeyLocker provides cloud-based signing without a physical token, with per-signature limits on some plans. Check your specific plan before relying on it for high-volume automated builds.
Build pipeline integration
KeyLocker's API-based signing integrates into CI/CD without requiring a token plugged into a build agent, which matters if your builds run on ephemeral cloud infrastructure rather than a fixed physical machine.
Multiple developer workflows
Signing typically routes through a single certificate or token per organization rather than per-developer credentials. Teams need a process for who actually triggers signing, not just who writes code.
Performance in Real-World Signing Scenarios
Desktop software publishing
Standard Authenticode flow; performs identically to any other CA's equivalent certificate for this use case.
Enterprise software releases
KeyLocker's cloud signing scales cleanly across frequent release cycles without physical token bottlenecks.
Driver signing
The only scenario where this certificate's EV tier does something a cheaper alternative structurally cannot: establishing Dev Center account eligibility for kernel-mode submission.
Automated CI/CD pipelines
Works well once KeyLocker is configured; the initial setup is real work, not a drop-in replacement for a locally-plugged-in token workflow.
Advantages and Limitations
Advantages
- Genuine EV identity vetting, not a rubber-stamp process
- KeyLocker's cloud signing removes the physical-token bottleneck from CI/CD pipelines
- RFC 3161 timestamping keeps signatures valid past certificate expiration
- Hardware-backed key storage is non-exportable by design, a real security property
- EV establishes Windows Hardware Dev Center eligibility for kernel-mode driver signing
Limitations
- Organization verification is required. No path exists for an unregistered individual to obtain this certificate directly.
- Hardware-backed key storage is mandatory. Adds real setup time and, for EV, a shipping wait for the physical token.
- Validity is capped at 459 to 460 days. Plan renewal timing now; there is no multi-year, no-touch option under current rules.
- Acquisition cost is higher than budget-tier certificates. The price difference buys identity depth and platform features, not stronger cryptography.
Pricing and Overall Value
Direct from DigiCert runs roughly $500 to $600 per year. Reseller pricing brings single-year cost down to $369 to $438 per year, with multi-year terms around $406 to $416 per year per year. For the OV tier specifically, that is a real premium over Sectigo or Certum's comparable certificates for the same signature strength and validity cap.
The premium buys deeper EV identity verification (where you need it), KeyLocker's cloud signing infrastructure, and driver-signing eligibility, not a technically stronger signature than a cheaper CA provides.
DigiCert Code Signing vs Alternatives
vs Sectigo Code Signing
Sectigo prices lower for comparable OV and EV tiers. As of February 2026, Sectigo's own documentation states OV and EV now require identical hardware key protection, a change that likely reflects a broader CA/B Forum shift rather than a Sectigo-specific one. If that applies to DigiCert too, the OV-versus-EV security gap narrows to identity depth and driver eligibility, not key protection strength, for either CA.
vs GlobalSign Code Signing
Similar price band to DigiCert, with GlobalSign's own separate 1-year term restriction following its 2026 policy changes. Neither is the budget option; pick based on existing infrastructure rather than price.
vs SSL.com Code Signing
Generally priced lower and marketed more directly at smaller publishers and individual developers, a segment this certificate's process and price aren't built around. A stronger value for organizations that don't specifically need DigiCert's platform or brand.
vs Certum Code Signing
Typically the lowest-cost option among established CAs for code signing, and often the more accessible path for individual developers specifically. Worth pricing first if budget is the primary constraint.
| DigiCert | Sectigo | SSL.com | Certum | |
|---|---|---|---|---|
| OV and EV tiers | Both | Both | Both | Both |
| Typical price | $369 to $600/yr | Lower | Lower | Lowest |
| Cloud signing | KeyLocker | Varies | Varies | Not prominent |
| Driver signing (EV) | Yes | Yes | Yes | Yes |
| Individual developer path | No | Limited | Yes | Yes |
Who Should Choose This Certificate
Good fit
- Commercial software vendors needing EV specifically for driver signing via Windows Hardware Dev Center
- ISVs already integrated with DigiCert's platform for other certificate types
- Enterprise publishers with compliance or procurement requirements naming DigiCert
- Organizations distributing signed executables at a volume where KeyLocker's automation genuinely pays off
Look elsewhere
- Individual developers and low-frequency publishers. Sectigo or Certum deliver the same signature validity at a lower price.
- Anyone without a kernel-mode driver signing requirement. OV from any CA covers general application signing adequately.
- Publishers choosing based on EV's SmartScreen bypass advantage. That advantage no longer applies as of 2024.
Frequently Asked Questions
Final Review
This certificate does what a code signing certificate should: verified identity, hardware-protected keys, valid timestamped signatures, and real driver-signing eligibility at the EV tier. It doesn't do any of that more securely than a comparable certificate from Sectigo or Certum at a lower price. Buy it specifically for EV's driver-signing eligibility or KeyLocker's automation fit, not for a security property a cheaper certificate lacks.
