You have ordered a Sectigo code signing certificate and nothing has arrived. That is normal: the certificate does not exist yet. Sectigo has to establish who you are before it will sign anything with your name in it, and that vetting is the slowest part of the purchase by a wide margin.
This guide covers what Sectigo asks for, in the order it asks, at each of the three routes an order can take: Organization Validation (OV) for a company, the same OV product issued to an individual developer, and Extended Validation (EV). It also covers the two things that most often leave an order sitting untouched for a week, which are almost never the documents people expect.
What Sectigo Actually Verifies
Sectigo publishes its current code signing vetting process in two knowledge base articles, one for OV code signing and one for EV code signing. Both were rewritten in 2026, and both describe the same three-part structure:
- Identity. The publisher named in the certificate is a real legal entity, or a real person, and is active.
- Presence. That publisher can be placed at a physical address and reached through a contact detail that Sectigo found somewhere other than your order form.
- Authorization. The certificate request and the Subscriber Agreement were approved by a person entitled to approve them, confirmed by a callback.
The underlying rules are not Sectigo’s own. They come from the CA/Browser Forum’s Baseline Requirements for Code Signing Certificates, which every publicly trusted CA follows. That is why the shape of the process is the same at DigiCert, and why no vendor can waive a step for you. If you ordered from DigiCert instead, see the sibling guide on passing DigiCert code signing validation.
Which route your order is on
- OV, organization. The certificate carries a company name. Sectigo verifies the company and separately verifies the identity of the person who requested the certificate.
- OV, individual. The certificate carries a person’s name. This is the route SSL Dragon’s order form labels IV. It is not a third product at Sectigo: an individual applicant receives the same non-EV code signing certificate, validated against the rules for individual applicants instead of the rules for organizations.
- EV. Organizations only. Sectigo states plainly that EV code signing certificates cannot be issued to individuals. If you ordered EV as a sole developer with no registered entity, the order cannot be validated as placed and has to be changed.
Why you see the Comodo name in your paperwork
Comodo CA was renamed Sectigo in 2018. The vetting team, the systems and the requirements are the same. You will still meet the old name in a few places: some resellers list the products as Comodo, and some download links still resolve through comodoca.com hostnames. Neither is a sign that anything is wrong with your order. Everywhere else in this guide, Sectigo means both.
Passing Organization Validation (OV)
OV is the standard code signing validation level. The checks below run in parallel rather than strictly in sequence, but the callback is always last, because it confirms everything that came before it.
1. Legal existence of the organization
Sectigo looks your company up in the government registry of the jurisdiction where it was incorporated: a Secretary of State, a companies house, a commercial register, a chamber of commerce. It confirms the legal entity name, the jurisdiction, and that the entity is active and in good standing.
The single most common cause of delay at this step is a name that does not match. Enter the exact legal name as it appears in official records, including the suffix. If you trade under a different name, that name must be a registered DBA or trade name, and it goes in the trade name field rather than replacing the legal name. An unregistered trading name cannot be verified and cannot go in the certificate.
If the registry does not list your company, or lists it with stale details, see what to do when the registry is not enough below.
2. Identity of the person requesting the certificate
Sectigo authenticates the individual who requested the certificate through an automated Video ID session. You receive a link, you present a valid government-issued photo ID to your camera, and the system checks that the document is genuine and that the face in front of the camera is the face on the document. Acceptable documents are the usual set: passport, driver’s license, national ID card, military ID.
This step replaced the old routine of attaching a scan of your ID to a support ticket. Several older Sectigo knowledge base articles still describe that upload flow, so if you land on one, check its update date: the two code signing validation articles linked above were refreshed in 2026 and are the current ones. It is also worth knowing why the requirement exists at all. The Baseline Requirements make identity verification of the certificate requester mandatory whenever the organization was formed less than three years before the request. Sectigo applies the session more broadly than that minimum, so expect it even for a long-established company.
Two practical points. The name on your photo ID has to match the name on the order, so if the order was placed under a colleague’s name, that colleague does the session. And the session is time-limited in practice: complete it when the link arrives rather than a week later, because an incomplete identity check is invisible on the order status and looks exactly like Sectigo being slow.
3. Physical address
Sectigo confirms that your organization is physically at the address on the order, using third-party public data sources or government sources. Older Sectigo and Comodo documentation called this step Locality Presence and described it as a check on the city and state rather than the street. Current Sectigo documentation calls it physical address verification and checks the address where the business actually operates.
Use the address the business really works from, and make sure it matches the registry entry. If the address cannot be confirmed independently, Sectigo will ask for supporting documentation rather than fail the order outright, and the everyday documents in the evidence list below are normally enough for an address on their own.
4. A contact detail Sectigo can verify
This is the step the old version of this process described as telephone verification, and it is the step that has changed most. The requirement is no longer specifically a listed phone number. Sectigo needs a working business phone number and/or email address that appears in a reliable third-party public data source or a government source, under the same organization name.
The Baseline Requirements call this a Reliable Method of Communication and define it as a postal or courier delivery address, telephone number or email address verified using a source other than the applicant representative. The word doing the work is other. A number typed into your own order form proves nothing, however genuine it is. Neither does an address on your own website.
So the practical question is not “do I have a phone number”, it is “where can Sectigo find my phone number or email address without asking me”. If the answer is nowhere, fix that before the callback stage: get the number listed in the government registry entry, in a business directory, or in a credit report, or be ready to submit documentation from such a source showing the contact details under your company name. That documentation route is available and is the standard remedy when the listing does not exist.
5. The Subscriber Agreement
Every code signing order requires a signed Subscriber Agreement. Sectigo will not issue without it, and an unsigned or half-completed agreement blocks the order silently, which makes it a common reason an order looks stuck.
The signer does not have to be the person who administers the order, but must be authorized to commit the organization. Two errors account for most rejections here: entering the organization’s name in a field that asks for an individual’s name, and omitting the signer’s job title. Put a real person’s full name where a person is asked for, and give a title such as IT Manager or Software Development Lead.
6. Callback authentication
The callback confirms that a human with authority actually intended this order. It is the last step, and unlike the old process it is not necessarily a phone call from a person. Sectigo currently uses three methods, chosen according to the situation:
- Automated telephone callback. An email goes to the order’s administrative contact with a link that triggers an automated call to your verified business number. The call reads out a verification code, and you enter that code to complete the step.
- Automated email callback. A verification link is sent to a verified business email address. Clicking it completes the step.
- Manual callback. A validation specialist calls or emails directly. This is used when the automated methods are unavailable or when Sectigo wants a closer look.
All three run only against contact details that were independently verified in step 4. Sectigo does not call or email a number or address that you supplied and it could not confirm elsewhere, which is why an unverifiable contact detail does not merely delay the callback, it prevents it.
If the automated callback fails but the contact details are correct, contact Sectigo support through chat and ask for a manual callback. If the contact details themselves are wrong or unverifiable, upload documentation from a third-party data source or government registry showing valid contact details under your organization name.
One old piece of advice still holds. The verified number often reaches a switchboard rather than your desk. Have your extension ready, make sure reception knows to transfer the call, and do not let it go to voicemail.
Passing Validation as an Individual Developer
If the certificate will carry your own name rather than a company’s, Sectigo verifies you instead of an organization. There is no company registry to check, so identity carries the whole weight and the evidence bar for a single document is correspondingly higher.
Photo ID and the video session
Sectigo runs the same Video ID session described in step 2 above. Underneath it, the Baseline Requirements ask for two separate things, which is useful to know because it explains what Sectigo is looking at:
- Identity. A legible copy of at least one currently valid government-issued photo ID that discernibly shows your face, inspected for signs of alteration. Your address must also be established, from that ID or from one of the other sources described in the next section. A second route exists that skips the ID copy entirely: digitally signing the certificate request with a qualified personal certificate issued under a recognised assurance standard, which almost no applicant has to hand.
- Authenticity of the request. Proof that the person holding the ID is the person asking for the certificate. Four forms are accepted: a photo of you holding the ID with both your face and the document’s details legible, a live in-person or web camera check by an employee or contractor of the CA, an executed Declaration of Identity carrying a biometric identifier such as a fingerprint or a handwritten signature, or the qualified digital signature just described.
The web camera route is the second option in that list, which is why Sectigo can run the whole check remotely and why the older selfie-with-ID routine is no longer the default. If you are asked for a photo of yourself holding your ID, that is the first option and it is equally valid, not a sign that something went wrong.
When your ID does not show the right address
A passport with no address, or a license showing an address you moved away from, is the usual complication. Older Sectigo guidance sent everyone in that position down a face-to-face notarization route. That route still exists in the current Baseline Requirements, as an executed Declaration of Identity, but it is no longer the only answer and it is no longer the first thing to try.
Two lighter options come first. Your address can be established from a qualified independent information source or a government information source rather than from the ID itself, or through an access code that Sectigo physically mails to your address, which proves you receive post there.
If Sectigo does route you to a Declaration of Identity, it is a specific document, not a generic affidavit. It records the identity of the person performing the verification, your signature, a unique identifying number from your identification document, the date of verification, and the signature of the Verifying Person. That Verifying Person can be a notary, an attorney, a Latin notary, an accountant, someone a government agency has authorized to verify identities, or an agent of the CA. Sectigo then confirms the declaration directly with that person, normally by telephone, using contact details it verified independently.
Alongside the declaration you will usually be asked for a financial document in your name, such as a bank or mortgage statement, and a non-financial document in your name showing an address, such as a recent utility bill, a landline telephone bill, a lease statement or a tax bill. Mobile phone bills are typically not accepted.
Sectigo publishes this paperwork as the Face to Face Verification Form, which carries the Personal Statement Declaration you fill in along with the section the verifier completes. The copy in its knowledge base has not been revised for several years, so ask Sectigo validation support for the current version when you reach this point rather than reusing a copy found online. The forms are revised, and an out-of-date form is rejected on sight.
Passing Extended Validation (EV)
EV covers everything OV covers, then adds proof that the business is genuinely trading, a formal split of the approval into named roles, and a second pair of eyes over the whole file. Since August 2024 the EV rules live inside the Code Signing Baseline Requirements themselves rather than in a separate EV guidelines document, so there is one rulebook to check rather than two.
1. Legal existence and the name in the certificate
Same registry check as OV, applied more strictly to the name. An EV code signing certificate must carry the legal name. If you have a verified trade name, it appears alongside the legal name in the format Trade Name (Legal Name), not instead of it. Putting a trade name in the company name field is one of the most common EV rejections.
2. Operational existence
This is the EV-only step, and it is widely misdescribed, including in the previous version of this guide. You do not have to have been in business for three years. Three years is one of four acceptable ways to satisfy the requirement, not the requirement itself.
The Baseline Requirements ask the CA to verify that the applicant has the ability to engage in business, by any one of the following:
- Records of an incorporating or registration agency show the company, or its parent, subsidiary or affiliate, has existed for at least three years.
- The company is listed in a current qualified independent information source or qualified government tax information source. A business credit report from a provider such as Dun and Bradstreet is the usual example.
- The company holds an active demand deposit account, in other words an ordinary business current or checking account, at a regulated financial institution, evidenced by authenticated documentation received directly from that institution.
- A verified professional letter states that the company holds such an account.
A company incorporated last year with a business bank account and a bank confirmation letter therefore qualifies. In its own customer-facing wording Sectigo does not mention a three-year rule at all; it asks for confirmation that the organization is actively conducting business and is active and in good standing.
3. Physical address, with a stricter exclusion list
EV verifies the physical address where business operations actually take place. The exclusions are broader than most applicants expect, and Sectigo lists them explicitly: PO boxes, virtual offices, mail forwarding addresses and registered agent addresses are not accepted.
That last one catches small software companies regularly, because the registered agent’s address is often the only address in the public registry. If that describes you, expect to supply separate documentation for the operating address, and expect the registry entry alone not to be enough.
4. Contact verification
Identical in substance to the OV step above, and applied at least as strictly. Details that exist only on your own order form cannot be used.
5. The three EV roles and the Subscriber Agreement
Older guidance described a single Organizational Contact who handled everything. The Baseline Requirements split the job into named roles, three of which apply to every EV code signing order, and they require the CA to verify the name, title and authority of each. One person may hold more than one role, but the roles have to be filled and named:
- Certificate Requester. The person who submits the request. May be an employee, an authorized agent, or a third party acting for you.
- Certificate Approver. The person who approves the request and may authorize others to submit requests.
- Contract Signer. The person with authority to sign the Subscriber Agreement on the organization’s behalf.
Sectigo’s own advice on this step is to include the job title of the signer, approver and requester, and to make sure a person’s name goes in every field that asks for a person. If a signer’s authority cannot be confirmed from the registry, it can be established from a verified professional letter, a properly certified corporate resolution, or independent confirmation from someone else at the company.
Enrollment paperwork is provided by Sectigo once the order is open, so do not go looking for the forms in advance. Older orders used a separate EV certificate request form alongside the agreement; Sectigo’s current documentation names only the Subscriber Agreement, and describes reviewing and accepting it rather than a print-and-scan exchange. If you are sent a document that does ask for a handwritten signature, print it, sign it by hand, scan it and upload it through the ticket, because a typed or digitally applied signature on such a form is rejected.
6. Callback
For EV, Sectigo describes the callback as a manual verification call performed by one of its specialists, or an email sent only to contact details obtained from trusted independent sources. In practice EV is less likely than OV to be closed out by an automated call, so plan on speaking to someone.
7. Second review
EV has one step with no OV equivalent, and it is the one that explains why EV takes longer even when your paperwork is perfect. Every document used to verify the organization is reviewed a second time by a different, expert validation specialist. Sectigo calls this the second approval, and the Baseline Requirements are what force it: no one person may single-handedly validate and authorize an EV code signing certificate. Nothing is required from you, but it is real time on the clock after you think you have finished.
When the Government Registry Is Not Enough
Plenty of legitimate companies are not fully documented online. The registry may be offline, may not publish addresses, may be years out of date, or may not exist in a usable form in your jurisdiction. The Baseline Requirements anticipate this and allow the same alternative evidence at every step where a registry lookup would normally do the job, so you can read this section once and apply it wherever you get stuck.
- Official registration documents. Articles of incorporation, a chartered license, or a DBA statement issued by your local government. These prove legal existence and normally carry the address as well.
- A reliable data source. A periodically updated third-party database that the CA accepts. A full business credit report from Dun and Bradstreet is the usual one, and it can support identity, address, contact details and operational existence at the same time, which is why it is worth obtaining if several checks are failing at once. If Sectigo tells you your listing has no phone number on it, ask the provider to add the number to the directory listing and to the report, then resubmit.
- An attestation or professional letter. A letter from an accountant, lawyer, government official or comparable third party confirming the facts in question. This is what older documentation calls a legal opinion letter or a professional opinion letter (POL). It is the slowest and usually the most expensive route, and in some jurisdictions it is the only one that works. Sectigo publishes sample legal opinion letters your professional can work from. Copies of the three samples, for an accountant, for a private organization and for a government organization, are also mirrored here as Word documents: accountant, private organization, legal opinion, private organization and government organization. They are drafted for EV orders; confirm the current wording with Sectigo before your professional signs anything.
- A bank confirmation letter. Accepted for EV operational existence, as authenticated documentation of an active business account received directly from a regulated financial institution.
- Everyday documents, for address only. A utility bill, bank statement, credit card statement or government tax document can establish an address, but never the organization’s identity.
One caution about the professional letter route. A letter is only as good as the professional behind it: Sectigo verifies the person’s professional standing directly with the body that licenses them, so a signature from someone whose registration cannot be confirmed sets you back rather than forward.
The Hardware Step That Runs Alongside Validation
Since June 1, 2023 a code signing private key has to be generated and held in hardware certified to at least FIPS 140-2 Level 2 or Common Criteria EAL 4+. This is not part of identity vetting, but the CA has to satisfy itself about it before issuing, so it runs on the same clock as everything above and it can stall an order that has otherwise passed.
Which version applies depends on the delivery method you chose at checkout:
- Token and shipping. Sectigo generates the key inside a token it ships to you. The hardware requirement is satisfied by the CA, and there is nothing for you to prove. Nearly all orders take this route.
- Install on existing HSM or token. You generate the key on your own device and must prove it was created there and cannot be exported. The standard proof is key attestation: the certificate request is counter-signed so that a manufacturer certificate vouches for how the key was made. Other routes exist in the rules, including an IT audit or a configuration report from a cloud key protection subscription, but attestation is what a normal order uses.
If you took the second route, produce the attestation material with your CSR rather than after the fact, because an attestation that does not match the submitted CSR is rejected and the order waits. The two sibling guides walk through the process end to end for the common devices: generating a CSR and attestation on a YubiKey 5 FIPS and generating a CSR on a Luna Network Attached HSM. The full comparison of the two delivery methods, including shipping fees and which devices qualify, is in code signing certificate delivery methods.
Submitting Documents and Tracking the Order
Two channels matter, and they do different things.
Your order confirmation email. It contains a link to track validation progress and see the actions still outstanding on your order. Sectigo’s own guidance says outstanding customer actions are the most common reason an order appears stuck, so check this before concluding that the CA has gone quiet. Sectigo also runs an Order Status Checker from its support page.
The support ticket form. Use Sectigo’s support ticket page to send documents and to chase. The form was redesigned, so ignore older instructions that mention a case type dropdown. The current fields are:
- A Subject line and a description of the request.
- Support Topic, where you choose Validation Support. The other choices are Billing, Sales and Technical Support.
- Request Reason, which only populates after you have picked a topic. Choose the entry matching your certificate type.
- Your contact and order details, including the Order Number. Take that number from your SSL Dragon order, not from anything Sectigo sent you, and include it every time. A ticket without it cannot be matched to your order.
Sectigo commits to a response within 24 hours. Keep the reference you are given and quote it on every follow-up, so the thread stays attached to one case instead of spawning several.
What Arrives After Approval
Once validation clears, the certificate is provisioned onto hardware rather than emailed to you.
- If you chose the shipped token, Sectigo installs the certificate on it and sends it by a tracked service. The order administrator receives an email with the tracking number and the token password. Keep that email: the password is not recoverable from the device, and a token that locks after repeated failed attempts cannot be unlocked by the subscriber. The EV token setup guide linked below explains why.
- If you chose your own hardware, the issued certificate is made available to download and you import it onto the device that generated the key.
Check the shipping address on the order before validation completes rather than after. Changing it once the token is in transit is not straightforward, and a token that goes missing has to be revoked and reissued, which can mean revalidating.
From there, the setup guides take over: setting up an EV code signing token, installing the certificate on a YubiKey, and signing an EXE file.
How long the certificate lasts now
Worth knowing before you start, because it changes how often you repeat this process. Under CA/Browser Forum ballot CSC-31, a code signing certificate issued on or after March 1, 2026 may have a validity period of no more than 460 days, roughly fifteen months. The previous ceiling was 39 months. Sectigo moved before the deadline and issues one day inside the limit, at 459 days, from February 23, 2026. Multi-year plans are still sold, but each certificate inside the plan is capped at that term and is reissued along the way. Validation data can be reused within the limits the rules allow, so a reissue is normally lighter than a first order, but it is not automatic.
What Slows a Sectigo Validation Down
Sectigo publishes no service level for code signing validation. SSL Dragon’s product pages quote one to seven business days, with a well-documented OV or individual order usually closer to one to three, and EV sitting at the top of the range. Almost everything that pushes an order past that comes from this list:
- The legal name is not exactly the registry name. An abbreviation, a missing suffix, an unregistered trading name.
- The contact details exist nowhere but your order. The commonest hard stop, because it blocks the callback rather than merely delaying it.
- A new or personal email address or phone number. Recently created details have no independent record yet, so they cannot be verified.
- The address is a registered agent, a virtual office or a mail drop. Fatal for EV, and a problem for OV if the operating address cannot be confirmed.
- The Subscriber Agreement is unsigned, or has a company name where a person’s name belongs.
- The Video ID session was never completed. Nothing else can finish until it is.
- The ID name does not match the order name. The person on the order does the session, not a colleague.
- The verification call went to voicemail. The step does not close until someone answers, so every missed attempt adds days.
- The attestation does not match the CSR, on orders using your own hardware.
None of these need a decision from Sectigo. They need one from you, which is why checking the outstanding actions on your order is nearly always more productive than opening another ticket asking for an update.
Frequently Asked Questions
Sectigo itself does not publish a timeframe. SSL Dragon quotes one to seven business days, and a well-documented OV or individual order that you respond to promptly usually clears in one to three. EV sits at the top of the range, because it adds operational existence checks, verification of three approval roles, and a second review of the whole file by a different validation specialist. Delays past that range are almost always caused by an action still outstanding on your side rather than by a queue at Sectigo.
Because a number you supplied proves only that you can answer a phone. The callback exists to confirm that the person approving the order really represents the organization, so it must run against a contact detail found independently, in a government registry or a reliable third-party data source. If yours is not listed anywhere, get it listed, or submit documentation from such a source showing the number or email address under your company name.
No. Three years in the registry is one of four accepted ways to prove operational existence. The others are a listing in a qualified independent or government tax information source such as a business credit report, authenticated documentation of an active business bank account received directly from a regulated financial institution, or a verified professional letter confirming that account. A company incorporated last year with a business bank account and a bank confirmation letter can pass EV.
No. Sectigo issues EV code signing certificates only to verified organizations: registered businesses, private organizations, international organizations and government entities. An individual applicant receives the standard non-EV code signing certificate, validated against the individual identity rules rather than the organization rules. That is the product SSL Dragon’s order form labels IV.
Usually not. Sectigo’s current documented method is an automated Video ID session with a government-issued photo ID, and web camera verification is an accepted form of proof under the Baseline Requirements. The notarized route still exists as an executed Declaration of Identity, and the Verifying Person can be a notary, attorney, Latin notary, accountant or another authorized person, but it is now a fallback used mainly when your address cannot be established any other way.
There is none. Comodo CA was renamed Sectigo in 2018, and the vetting team, systems and requirements are the same. Products are still sold under the Comodo brand in places, and some Sectigo download links still resolve through comodoca.com hostnames, which is expected and not a sign of a problem.
Not any more. EV code signing certificates used to bypass the Microsoft Defender SmartScreen warning on first download, and Microsoft removed that behavior in 2024. An EV-signed file now builds SmartScreen reputation the same way an OV-signed one does, through download volume and publisher history. EV still requires stricter vetting, is required for Windows kernel-mode driver signing, and is sometimes required by enterprise procurement, but it does not buy instant trust. Microsoft documents the current position in its code signing options for Windows app developers.
It adds a step. Identity vetting is unchanged, but the CA also has to satisfy itself that your private key was generated inside compliant hardware and cannot be exported, which it normally does by verifying a key attestation submitted with your CSR. If the attestation is missing, malformed or does not match the CSR, the order waits even though the identity checks have passed. If you have no reason to run your own hardware, the shipped token removes this step entirely.
Partly. CAs may reuse previously verified data within the reuse periods the Baseline Requirements set, so a renewal is usually lighter than a first order, but expect to confirm the request again through a callback and to redo anything whose reuse window has expired. The windows differ by level: data supporting a standard code signing certificate may be reused for up to 825 days, while every EV data point, from legal existence to the verified contact method, expires after 398 days. This matters more than it used to: since March 1, 2026 a code signing certificate is capped at 460 days, so the cycle now comes round roughly every fifteen months instead of every three years.
Through Sectigo’s support ticket page. Choose Validation Support as the Support Topic, then pick the matching Request Reason, and include your order number from SSL Dragon. Before you do, open the tracking link in your order confirmation email and check which actions are actually outstanding, since that list is what the validation team is waiting on.
For the rest of the process, from generating the request to signing your first file, see the code signing tutorials and the guide to generating a CSR for a code signing certificate.
Risparmia il 10% sui certificati SSL ordinando oggi stesso da SSL Dragon!
Emissione rapida, crittografia avanzata, affidabilità del browser al 99,99%, assistenza dedicata e garanzia di rimborso entro 25 giorni. Codice coupon: SAVE10

