Skip to main content
    Code Signing

    Code Signing Certificate Price: What OV and EV Cost in 2026

    Code signing certificate prices in 2026: OV runs about $215–400/year, EV about $280–690/year across CAs. What drives the cost and how to avoid overpaying.

    MS
    My-SSL Security Team
    ·
    12 min read
    ·Published July 20, 2026·Last updated July 20, 2026

    The short answer

    As of July 2026, a standard (OV) code signing certificate costs roughly $215–$400 per year across the major certificate authorities, and an EV code signing certificate roughly $280–$690 per year. My-SSL's Certum-issued options sit below that range at $99/year for standard and $299/year for EV. Two things move the price: the validation level — EV adds legal, operational, and physical checks — and the hardware the private key must live on, which has been mandatory since June 2023. The certificate fee alone isn't the whole cost: budget for the token or a cloud signing subscription too.

    If you already know your validation level and just want current figures, the code signing certificate options list the standard and EV prices side by side. If you're still weighing which level you need, keep reading — the price gap only makes sense once you see what each tier actually verifies.

    Code signing prices at a glance

    Standard OV code signing generally runs about $215–$400 per year and EV about $280–$690 per year across publicly trusted CAs, as of July 2026. Those are certificate figures for a one-year term; longer terms lower the per-year rate, and whether a hardware token is bundled shifts the total. The table sets the ranges next to My-SSL's own Certum prices, and the panel underneath shows where the EV premium goes.

    TypeTypical market (per year)My-SSLBest for
    Standard (OV)~$215–$400$99Most app and script publishers
    EV~$280–$690$299Driver submission, procurement rules
    Standard OV versus EV code signing price positioningTwo comparison columns. Standard OV code signing sits at roughly 215 to 400 dollars a year and proves a registered organization. EV code signing sits higher, roughly 280 to 690 dollars a year, adding legal, operational, and physical verification and stronger key storage. The EV column, shown in gold, is where the extra cost goes.Where the money goes: standard OV vs EVStandard (OV)~$215–400/yrmarket range across CAsVerifies a registered organizationKey on a compliant token or HSMEarns SmartScreen over timeFits most app publishersMy-SSL: $99/yrEV~$280–690/yrmarket range across CAsEverything OV does, plus:Legal + operational + physical checksHigher-assurance key storageNeeded for driver submissionMy-SSL: $299/yr
    Both certificates sign your code identically. The EV premium buys deeper identity vetting and stricter key storage — worth it only when you actually need those, which most publishers don't.

    The ranges are wide because the CA brand matters as much as the tier: a big-name authority charges a premium over a Certum- or Sectigo-issued certificate that clears Windows identically. Before you assume the cheaper one is worse, it's worth understanding exactly what you're paying for.

    What actually drives the price

    Code signing pricing comes down to four levers: the validation level (OV or EV), the certificate authority's brand, the length of the term, and how the mandatory hardware requirement is met. Every code signing key must now be generated and stored on hardware — a USB token, an on-premise HSM, or a cloud signing service — so the "certificate" and the "key protection" are really two line items, whether or not a vendor prices them together.

    • Validation level. EV requires more human vetting than OV, so it costs more to issue. That's the single biggest swing between two certificates from the same CA.
    • CA brand. The same OV validation from a premium brand can cost two to three times what a Certum- or Sectigo-issued certificate does. The trust outcome in Windows is the same.
    • Term length. Multi-year plans lower the per-year rate. Since the 460-day validity cap, they're delivered as reissues rather than one long certificate — more on that below.
    • Hardware delivery. A shipped USB token, a token you already own, or a cloud signing subscription each carry different costs and lead times.

    The details of OV versus EV pricing follow, but the decision itself is covered end to end in our EV vs OV code signing guide — worth a read if the price difference is the only thing pushing you toward one or the other.

    Standard (OV): what you pay and get

    A standard (OV) code signing certificate runs about $215–$400 per year at the major CAs, and less from value-focused resellers — My-SSL lists its Certum-issued standard certificate at $99/year. For that price the CA confirms your organization is a real, registered legal entity and issues a certificate that stamps your verified company name onto anything you sign. It signs executables, installers, scripts, and drivers' user-mode components exactly as an EV certificate would.

    For the large majority of software publishers, OV is the right spend. The one thing it doesn't do is grant instant Windows SmartScreen reputation — but neither does EV anymore, so that's no longer a reason to pay up. Reputation now builds through download telemetry regardless of tier, which we cover in the SmartScreen publisher reputation guide.

    EV code signing: why it costs more

    EV code signing runs about $280–$690 per year across the major CAs, with My-SSL's EV option at $299/year. The premium over OV pays for two things: deeper identity vetting and stricter key storage. On top of the OV organization check, EV verifies your company's legal, operational, and physical existence and confirms the requester's authority — more human review, which the CA prices in. EV keys must also sit on higher-assurance hardware.

    Because the historical SmartScreen advantage is gone, EV is now worth the extra money in a narrower set of cases: registering to submit Windows kernel-mode drivers through the Microsoft Hardware Program, or meeting an enterprise customer's procurement requirement that specifically names EV. If one of those is you, EV is a genuine requirement rather than a nice-to-have. If neither is, the extra spend buys vetting you don't need.

    The costs beyond the certificate

    The certificate fee is one slice of what you actually pay. Since June 1, 2023, every publicly trusted code signing key must be generated and held on hardware that meets a defined assurance bar — so a compliant token or a cloud signing service is part of the real cost, not an optional extra. Some CAs fold the token into the certificate price; others bill it separately or expect you to supply one. A quote that looks cheap can lose that edge once the hardware line is added.

    The true cost of code signing beyond the certificate feeA horizontal bar split into three parts. The first part is the annual certificate fee. The second part, highlighted in gold, is the mandatory hardware token or cloud signing subscription. The third part is one-off validation and setup time. Together they make up the real first-year cost, not the certificate price alone.What you actually pay in year oneCertificate (annual)the sticker priceToken or cloud signingmandatory since June 2023Setup timeone-off= real first-year costSome CAs bundle the token into the price; others bill it separately.Cloud signing swaps the hardware purchase for a subscription — often the better fit for CI/CD.
    Compare quotes on the full stack, not the certificate line alone. A cheaper certificate with a separately billed token can end up costing more than a pricier all-in bundle.

    Cloud signing changes the shape of the cost rather than removing it: instead of buying and shipping a token, you pay a subscription for signing capacity, which is usually the better fit for CI/CD pipelines and remote teams. If you're weighing hardware against cloud, our cloud signing vs USB token comparison lays out the trade-offs on delivery time, team sharing, and pipeline fit.

    How the 460-day limit changes multi-year pricing

    You can still buy a two- or three-year code signing plan, but since March 1, 2026 no single publicly trusted certificate can be valid longer than 460 days — about 15 months — under CA/Browser Forum ballot CSC-31. That doesn't remove multi-year purchasing; it changes how it's delivered. A three-year plan is now a price lock: you pay once at today's rate, and the CA reissues the certificate roughly every 15 months for the length of the term.

    How a multi-year code signing plan is delivered after CSC-31Two timeline lanes over a three-year term. The old model was a single certificate valid for the whole term. The new model, for certificates issued on or after March 1 2026, delivers the same paid term as a series of reissues no longer than 460 days each. The reissue points, marked in gold, are where you re-key and re-sign.A "3-year" plan under the 460-day capBeforeOne certificate, valid up to ~39 monthsNow≤460 daysreissue ≤460 daysreissue ≤460 daysbuy oncesame paid term — price lockedterm ends
    Paying for three years still fixes your rate — you just collect the certificate in ~15-month installments and re-sign at each reissue. Budget the rate once; budget the re-key work three times.

    The money upside is real — you fix your rate against future increases and handle one transaction instead of three. The operational cost is that you still re-key and re-sign at each reissue, since the hardware requirement means there's no exportable key to simply carry forward. Plan the renewals so a reissue never leaves you unable to sign. The full mechanics are in our guide to the 460-day validity change.

    Is cheap code signing safe?

    A low price is not, by itself, a warning sign. A code signing certificate is trusted because the issuing CA's root is in the Microsoft Trusted Root Program and because the key lives on compliant hardware — not because of what you paid. A genuine, publicly trusted OV certificate at the bottom of the market signs your code exactly as a premium one does, and Windows treats both identically. Much of the price difference is brand, not security.

    What should make you pause is an offer that quietly drops the hardware requirement, promises to remove SmartScreen warnings outright, or comes from a "CA" you can't confirm is in the trusted root program. A software-only PFX sold as publicly trusted code signing is a red flag on its own — that model ended in June 2023. Verify the CA and the key-storage method, and a low price is simply a low price.

    How to buy without overpaying

    Buying well is mostly about matching the tier to your actual need and comparing quotes on the full stack rather than the certificate line. Pick OV unless a driver submission or a procurement rule forces EV. Compare the all-in cost — certificate plus token or cloud subscription — across providers. And decide up front whether a multi-year price lock is worth the reissue admin. Do that and you rarely overpay.

    Here's where My-SSL's options map to common situations:

    Your situationWhere to look
    You need a trusted certificate to stop the "unknown publisher" warningStandard code signing ($99/yr)
    You're deciding between OV and EV on priceEV vs OV code signing
    You want every product's price on one pageFull pricing list

    FAQ

    See the current code signing prices

    My-SSL issues standard and EV code signing certificates through Certum, a publicly trusted certificate authority, with the private key held on compliant hardware as the rules require. The code signing certificates page shows the standard and EV prices together, so you can match the tier to what you're signing before you buy.

    Related reading

    Sources worth checking directly

    • CA/Browser Forum — Ballot CSC-31 (460-day maximum validity, effective March 1, 2026)
    • CA/Browser Forum — Baseline Requirements for Code Signing (hardware key mandate since June 2023)
    • Microsoft Learn — Code signing options for Windows app developers (SmartScreen reputation for OV and EV)