hero digicert Image

Certificati di firma del codice

OV and EV code signing certificates from Comodo, Sectigo, DigiCert, and GoGetSSL, starting at $219/year. Most orders issue in 1–7 business days and ship with a hardware token, or you can sign via cloud HSM. Backed by a 25-day money-back guarantee.

Icona che mostra una cuffia di supporto con il testo "Support".
Supporto dedicato
Logo GLEIF con testo incorporato "Accreditato GLEIF".
25 giorni di rimborso

OV vs EV Code Signing Certificates

Two validation tiers exist, and the buyer’s choice between them comes down to who signs and what they sign.

OV / IndividualEV
Identity vettingBusiness or individualRegistered organization (no individuals)
SmartScreen behaviorBuilds reputation per file hashBuilds reputation per file hash
Windows kernel-mode driver signingNot eligibleEligible
Starting price (SSL Dragon)$219/yr$287/yr
Best forUser-mode apps, scripts, lower budgetDriver signing, identity assurance, procurement

A note on SmartScreen: a 2024 update to the Microsoft Trusted Root Program changed how reputation accumulates. SmartScreen reputation now builds by file hash and download volume regardless of certificate type. EV no longer grants instant SmartScreen trust. Both OV and EV signed binaries build reputation the same way once they’re in the wild.

Pick OV if you sign user-mode applications and want the lower price tier. Pick EV if you sign Windows kernel-mode drivers, need maximum identity assurance, or have procurement that names EV explicitly.

Hardware Token, Cloud HSM, or Bring Your Own Device

Since June 1, 2023, the CA/Browser Forum requires every publicly-trusted certificate’s private key to be generated and stored on hardware meeting FIPS 140-2 Level 2 or Common Criteria EAL 4+. Downloadable .pfx files are no longer issued. Buyers pick one of three delivery routes:

  1. CA-shipped USB token. The CA mails a pre-loaded FIPS 140-2 Level 2 USB token (typically a YubiKey) to the verified address on the order.
  2. Bring-your-own compliant device. If your team already operates a FIPS 140-2 Level 2 or Common Criteria EAL 4+ HSM or token, the CA issues against an attestation from that device.
  3. Cloud HSM signing service. The private key is generated and held in a CA-managed cloud HSM such as DigiCert KeyLocker, Sectigo cloud signing, or SSL.com eSigner. No physical token to ship, and signing fits cleanly into CI/CD pipelines.

A USB token is simplest for occasional manual signing; cloud signing fits better for automated builds. All three routes share the same Public Key Infrastructure (PKI): the certificate binds your verified identity to a public key, hardware protects the private key, and the resulting digital signature is what Windows verifies.

Setup steps are in our code signing tutorials.

New 460-Day Validity Limit (Effective March 2026)

As of March 1, 2026, publicly-trusted certificates have a maximum validity of 460 days (about 15 months), down from the previous 39-month maximum. The change comes from CA/Browser Forum Ballot CSC-31. Multi-year orders are still sold, but the certificate itself is reissued inside the purchased term rather than spanning it.

What this means at the order level:

  • A single new certificate is capped at ~15 months of validity
  • 2-year and 3-year orders remain available, with reissuance during the term
  • HSM-installed orders may cover the full purchased term but require annual reissuance
  • Certificates issued before March 1, 2026 stay valid until their original expiration

Properly timestamped code stays trusted past the certificate’s expiration, so software you’ve already signed and shipped is unaffected. Only the renewal cadence shifts.

Compare Code Signing Certificates by CA and Price

SSL Dragon stocks options from four Certificate Authorities. Here’s how the OV and EV options line up on starting price, hardware delivery, and issuance time.

CertificateValidationStarting PriceHardware DeliveryIssuance
Comodo Code SigningOV / Individual$219/yrUSB token or HSM1–7 days
Sectigo Code Signing SSLOV / Individual$219/yrUSB token or HSM1–7 days
GoGetSSL Code Signing SSLOV / Individual$289/yrUSB token or HSM1–7 days
DigiCert Code SigningOV$400/yrUSB token, HSM, or KeyLocker cloud1–7 days
Comodo EV Code SigningEV$287/yrUSB token or HSM1–7 days
Sectigo EV Code SigningEV$287/yrUSB token or HSM1–7 days
GoGetSSL Code Signing EV SSLEV$369/yrUSB token or HSM1–7 days
DigiCert EV Code SigningEV$685/yrUSB token, HSM, or KeyLocker cloud1–7 days

Comodo and Sectigo OV both start at $219/year and are the cheapest publicly-trusted options on this page. DigiCert sits at the premium end, $400 for OV and $685 for EV, and is usually chosen by buyers whose contracts or compliance frameworks specifically name DigiCert. GoGetSSL is the value pick at the EV tier at $369/year. All four CAs ship hardware tokens, with DigiCert also offering KeyLocker cloud signing for HSM-free workflows.

Why Free Code Signing Isn’t Realistic

No publicly-trusted Certificate Authority offers free code signing as of 2026.

Two real costs make it unworkable:

  1. The CA must verify the publisher’s identity (organization or individual)
  2. Since June 2023 the private key must live on FIPS-compliant hardware that someone has to pay for

Self-signed certificates can be generated with OpenSSL and cost nothing, but Windows, macOS, and browsers don’t trust them, so they leave the “Unknown Publisher” warning in place. If price is the deciding factor, Comodo Code Signing and Sectigo Code Signing OV (or Individual Validation for solo developers) are the entry-level SKUs at $219/year.

What You Can Sign with a Code Signing Certificate

A certificate from any CA SSL Dragon carries can sign:

  • Windows binaries and installers: .exe, .dll, .cab, .ocx, .msi, and .xap files signed via Microsoft Authenticode
  • Windows drivers: user-mode drivers (OV or EV) and kernel-mode drivers (EV only)
  • Java applications: .jar files signed with jarsigner
  • Scripts and macros: PowerShell scripts, VBScript, and Microsoft Office VBA macros
  • Other formats: Adobe AIR packages, Mozilla object files, and Microsoft Silverlight (legacy but still valid)
  • Firmware and IoT software
  • Containers and software packages

The same certificate covers most of the list above; the kernel-mode driver case is the one that forces the EV tier.

Code Signing vs SSL/TLS Certificates

An SSL/TLS certificate encrypts the connection between a browser and a website. A code signing certificate digitally signs software so the operating system can verify who published it and that the file hasn’t changed.

The two aren’t interchangeable: one secures a domain, the other proves the origin of an executable. Both are X.509 certificates issued by a Certificate Authority, which is why they get confused.

Domande frequenti

Cos’è un certificato di firma del codice?

È un certificato X.509 che consente a un publisher di allegare una firma digitale verificabile al software. A differenza di un CSR (che è solo la richiesta d’ordine inviata alla CA), il certificato emesso associa un’identità verificata a una chiave pubblica che i sistemi operativi utilizzano per confermare l’origine di un file.

Copia link

Qual è la differenza tra OV ed EV?

La verifica EV richiede in genere 3-5 giorni lavorativi in piu rispetto a OV, e solo EV e idoneo per la firma dei driver in modalita kernel. Prezzi, controlli di identita e il confronto sul comportamento di SmartScreen si trovano nella sezione OV vs EV qui sopra.

Copia link

Ho bisogno di un token hardware per la firma del codice?

Un hardware token è una delle tre opzioni. I servizi di firma cloud come DigiCert KeyLocker e SSL.com eSigner eliminano completamente il token fisico: la chiave risiede in un HSM gestito dalla CA e la firma avviene tramite API, il che funziona bene per i flussi CI/CD. Consulta la sezione sulla consegna hardware sopra.

Copia link

Per quanto tempo è valido un certificato di firma del codice?

Massimo 460 giorni per emissione secondo le regole attuali. Firma sempre con un’autorita’ di timestamping (tsa.digicert.com di DigiCert o timestamp.sectigo.com di Sectigo) in modo che i binari rimangano attendibili oltre la scadenza. Contesto completo nella sezione Validita’ di 460 Giorni sopra.

Copia link

Posso ottenere un certificato di firma del codice gratuito?

Nessuna CA pubblicamente attendibile le emette. Il ragionamento completo e le alternative a pagamento più economiche si trovano nella sezione Perché la firma del codice gratuita non è realistica qui sopra.

Copia link

Di quale certificato ho bisogno per i driver in modalità kernel di Windows?

Qualsiasi certificato di firma del codice EV. Il portale WHQL di Microsoft e il flusso di firma con attestazione rifiutano categoricamente i certificati non EV.

Copia link

Quanto tempo richiede il rilascio della firma del codice?

Da 1 a 7 giorni lavorativi a seconda della CA e del livello di validazione. EV richiede generalmente più tempo di OV perché il processo di verifica dell’organizzazione è più approfondito, quindi pianifica del tempo extra se hai una scadenza di rilascio ravvicinata.

Copia link

La firma del codice funziona su macOS e Linux?

Sì, per la firma generale di binari cross-platform, inclusi i file .jar e molti formati container. La distribuzione tramite macOS App Store richiede un programma Apple Developer ID separato; la firma su Linux è meno standardizzata ma supportata nella maggior parte dei formati di pacchetto.

Copia link

Non sai di cosa hai bisogno?

Usa la nostra procedura guidata SSL per selezionare le opzioni che fanno al caso tuo e ti aiuteremo a trovare il certificato SSL giusto.

Non sai di cosa hai bisogno?

Interfaccia di configurazione guidata di SSL Dragon con pulsanti e testo didattico

I nostri clienti e le figure chiave

Volvo logo
Netflix logo with a red background, displaying the text Netflix in white.
Koton logo featuring stylized text and a light background.
Dufry logo
Phillips logo
Northrop Grumman Logo
Yale logo
Harvard logo
Oxford Logo
Rockefeller Logo
Goodwill Logo
Sapient Logo
Hawaii Logo
Army Logo
Force Logo
Schneider Logo
Cisco Logo
Cornell Logo

Voto 4.8 su 5 da 1255 clienti

avatar-male-3
Christopher Broderick
June 15, 2022, , united kingdom

Great selection of certificates with a clear definition of properties for each certificate makes it easy to choose the right one.

avatar-male-2
Munro James
October 31, 2020, Victoria, AU

Easier and cheaper than going directly and ordering via the vendor, thank you for the information and the simple shopping experience.

avatar-female-2
Kelly Mark
October 29, 2020, Dublin, IE

Excellent customer service when I ordered the wrong cert! The support team then helped me get the correct cert and refunded me on the incorrect cert I bought! Very fast and a happy customer.

Valutazioni e recensioni reali dei clienti su Shopper Approved. Leggile tutte.