EV Code Signing Certificates

Protected by Digital Authentication Services

To prevent tampering or compromise of applications by unauthorized parties, software developers digitally sign their programs with EV code signing certificates. Extended Validation Code Signing certificates offer the highest level of authentication and security available in signing code, resulting in more trust and higher download counts of your signed applications.

Programs signed with an EV Code Signing certificate immediately work with Internet Explorer and Windows® SmartScreen® reputation services. For device driver publishers, an EV Code Signing certificate is REQUIRED as a first step for Windows Kernel Mode Signing (see Windows Kernel Mode Signing Policy for more details).

Why Buy EV Code Signing Certificate?

Highest organizational authentication assurance

Company name, address and organization type displayed in the certificate

Signature and time stamping does not expire once certificate expires

Certificate stored on FIPS hardware token prevents key duplication

Immediate Extended Validation reputation with Microsoft SmartScreen®

2-factor authentication through hardware token and PIN combination

Benefits of EV Code Signing Certificate

EV (Extended Validation) code signing certificates offer a powerful solution for software developers and businesses seeking to enhance user trust and security. These certificates go beyond standard code signing by verifying the publisher’s identity through a rigorous vetting process, resulting in several key benefits:

Enhanced User Trust and Confidence:

  • Prominent EV Badge: A visually distinct EV badge displayed alongside your software instantly verifies your identity and instills trust in users.
  • Reduced Security Warnings: With a recognized EV certificate, users encounter fewer security warnings, leading to a smoother and more confident installation process.
  • Stronger Brand Reputation: Associating your brand with a trusted name like DigiCert strengthens your reputation for security and user safety.

Increased Security and Risk Mitigation:

  • Verified Publisher Identity: DigiCert’s thorough vetting process ensures only legitimate publishers can obtain EV certificates, preventing unauthorized applications from exploiting your signature.
  • Tamper-proof Code: EV certificates provide a digital seal that protects your code from alteration or compromise during transmission or download, shielding users from malware and other threats.
  • Reduced Security Incidents: By deterring attackers and minimizing risks, EV certificates help you avoid costly security incidents and data breaches.

Improved Software Distribution and Sales:

  • Wider Platform Compatibility: EV certificates are recognized by major platforms and operating systems, allowing you to distribute your software more broadly.
  • Increased User Adoption: Users are more likely to trust and install software with an EV certificate, leading to wider adoption and improved sales potential.
  • Faster Installation and Deployment: EV certificates streamline the installation process, resulting in quicker deployment and faster user engagement.

Additional Benefits:

  • Enhanced Code Integrity: EV certificates protect your intellectual property by ensuring your code remains unaltered and preventing unauthorized modifications.
  • Reduced Development Costs: Eliminating the need to build and maintain your own signing infrastructure saves developers time and resources.
  • Improved Efficiency: Streamlined signing processes and automated renewals simplify certificate management and reduce administrative overhead.

Optional Lifetime Validity:

  • Some EV code signing certificates offer lifetime validity for your software, eliminating the need for recurring renewals and ensuring long-term protection.



Frequently Asked Questions about EV Code Signing

Extended Validation (EV) code signing is a specific type of code signing certificate that provides the highest level of security and trust available for software developers. It uses a rigorous validation process to verify the identity and legitimacy of the certificate applicant, ensuring that only authorized individuals or organizations can issue signed code.

When a developer signs their code with an EV certificate, a digital signature is added to the code. This signature acts as a seal of authenticity, verifying that the code has not been tampered with and originates from a trusted source. When users download and install software with an EV signature, they see a prominent EV badge, giving them confidence that the software is safe and legitimate.

The main difference between EV code signing and standard code signing is the level of validation involved. Standard code signing certificates typically require minimal verification of the applicant’s identity, while EV certificates require a rigorous vetting process that includes validating the applicant’s legal and operational existence, conducting financial checks, and verifying their physical address.

The cost of a code signing certificate varies depending on the type of certificate and the issuing authority. EV certificates are typically more expensive than standard code signing certificates due to the additional validation process involved. Prices can range from tens to hundreds of dollars per year, with EV certificates often costing several hundred dollars or more.

The EV code signing validation process involves several steps:

  • Identity Verification: The certificate authority (CA) verifies the identity of the applicant, including their legal name, address, and business information.
  • Financial Review: The CA assesses the applicant’s financial stability to ensure they are a legitimate business.
  • Operational Verification: The CA confirms that the applicant has the necessary resources and infrastructure to securely manage code signing certificates.
  • Physical Address Validation: The CA verifies the applicant’s physical address to ensure it is a real location

A hardware token device (HSM) is a physical device that stores cryptographic keys and performs cryptographic operations, such as signing code. This provides an additional layer of security for EV certificates, as the keys are kept safe within the HSM and cannot be easily accessed by attackers.

EV code signing validation refers to the process of verifying the authenticity and validity of an EV code signing certificate. This involves checking the digital signature on the certificate and confirming that it was issued by a trusted CA. Users can typically validate EV certificates by clicking on the EV badge displayed alongside the software.

Whether EV code signing is worth it depends on your specific needs and budget. If you are a large company or organization that requires the highest level of security and trust for your software, then an EV certificate is likely worth the investment. However, if you are a small developer or hobbyist, a standard code signing certificate may be sufficient.