The short answer
For most software publishers in 2026, standard OV code signing is the right choice. EV no longer skips Microsoft SmartScreen warnings — that instant-reputation behaviour was removed in 2024 — so OV and EV now build reputation the same slow way, through download history. Choose EV only when you genuinely need it: to register for Windows kernel-mode driver submission through Microsoft's Hardware Dev Center, or when an enterprise customer's procurement rules demand it. Both tiers verify a registered organization, both require the private key on FIPS 140-2 Level 2 hardware (a rule in force since June 1, 2023), and both are capped at 460 days of validity for certificates issued on or after March 1, 2026.
If you already know you're buying and just want to see the tiers side by side, the OV and EV code signing certificates pages lay out validation, key delivery, and price for each. If you're still deciding, the rest of this guide walks through exactly when each one earns its cost.
On this page
OV vs EV code signing: what actually differs
OV and EV are the two validation levels for publicly trusted code signing certificates, and they share far more than they differ. Both prove your software came from a verified, registered organization, both bind that identity to a tamper-evident signature, and since June 2023 both keep their private key on certified hardware. The differences come down to how deeply the CA vets you, and a handful of platform rules.
OV — Organization Validation, usually marketed as "standard" code signing — confirms your organization is real and legally registered, then issues. EV — Extended Validation — layers on stricter checks (enterprise identifiers, operational-existence and phone verification, sometimes a signed authorization), so it takes longer to issue. A few CAs also store EV keys on FIPS 140-2 Level 3 hardware rather than Level 2. Neither is issued to anonymous individuals anymore; the old "individual" code signing certificate is gone.
Read that panel top to bottom and one thing stands out: the row publishers used to buy EV for — SmartScreen — now reads the same in both columns. That single change reshaped the whole decision, so it's worth understanding precisely.
Does EV still skip SmartScreen? No — and here's what changed
EV code signing no longer grants instant Microsoft SmartScreen reputation. For years an EV-signed installer sailed past the "Windows protected your PC" screen on its very first download while OV software had to earn trust slowly. Microsoft removed that shortcut in 2024. As of its current developer documentation, a fresh EV-signed download can still trip SmartScreen until it accumulates a download history — exactly like OV.
Why the change? Malware operators had turned EV into a commodity — buying certificates through shell companies or stealing them specifically to inherit that instant trust. The shortcut had become a liability, so Microsoft moved to reputation earned through real-world download telemetry for every certificate, regardless of tier. Microsoft doesn't publish the download threshold, and it varies.
There's a footgun hiding in that curve. Reputation attaches to one specific certificate, so when you renew, rekey, or switch CA, the replacement starts from zero and warnings can reappear right after a renewal. Teams that ship continuously dual-sign during the overlap window so the new certificate banks reputation before the old one lapses. This bites harder now that certificates renew roughly yearly — we cover the mechanics in our SmartScreen publisher reputation guide. The bottom line: if your only reason to pay for EV was to dodge SmartScreen, that reason is gone.
When you genuinely need EV code signing
EV is still the required choice in two clear situations, and a defensible one in a third. Reach for it on purpose, not as a default. The old catch-all justification is gone, but these cases are real, and in them OV simply won't do the job.
- Windows kernel-mode drivers. To submit drivers, you need an EV certificate to open the Microsoft Hardware Dev Center (Partner Center) account in the first place. The driver itself is then signed through Microsoft's attestation process, not directly with your certificate. As of April 2026, Microsoft enforces Windows Hardware Compatibility Program checks for new kernel drivers and has removed trust for the legacy cross-signed driver path — so this route is now the only supported one. Our guide to signing a Windows driver walks the full submission flow.
- Enterprise procurement that names EV. Some large customers' security policies still specify "EV code signing" by name. When a contract or vendor questionnaire requires it, EV is simply a checkbox you have to tick, independent of the technical merits.
- A deliberate trust signal (weaker than it used to be). EV's stricter vetting can still matter to a security-conscious audience or an internal policy that values the highest assurance level. Just don't expect it to change the end user's install experience the way it once did.
When standard OV code signing is the right call
For the ordinary job of shipping trusted Windows software, standard OV code signing is now the sensible default. It verifies your organization, produces a valid Authenticode signature, replaces the "Unknown Publisher" label with your real name, and builds SmartScreen reputation on the same curve as EV — for less money and with faster issuance.
OV fits the large majority of publishers: desktop apps and installers (EXE, MSI), PowerShell scripts, Java archives, and most CI/CD signing pipelines. The one caveat is your key-storage model, which matters more than the OV-versus-EV label once you're automating. A single USB token is painful to share across build agents, so pipelines usually move to a cloud signing service or HSM — a trade-off we break down in cloud code signing vs USB tokens. If you're distributing software for macOS, note that neither OV nor EV applies — that's Apple's separate Developer ID and notarization system.
Price, validity, and the 2026 changes that affect both
Two industry-wide rules now apply equally to OV and EV, so they don't tilt the decision — but they change how you plan and budget. Both stem from CA/Browser Forum baseline requirements, and both are worth pricing in before you buy either tier.
Hardware keys, since June 1, 2023. Every publicly trusted code signing certificate — OV and EV — must generate and hold its private key on hardware certified to at least FIPS 140-2 Level 2 or Common Criteria EAL 4+, with the key non-exportable. The software-only PFX file you could copy onto a build server is dead for public code signing. In practice you provision via a CA-shipped USB token, your own compliant HSM, or a cloud signing service.
460-day validity, from March 1, 2026. Under ballot CSC-31 (adopted November 2025), certificates issued on or after March 1, 2026 max out at 460 days — about 15 months — down from the old 39-month ceiling. Some CAs began enforcing a 459-day cap a few days earlier. Buyers used to three-year certificates now face roughly annual renewals, so multi-year plans (a price lock with periodic reissues) and renewal planning around the 460-day limit matter more than they did.
On price, EV costs more than OV — the deeper validation and, with some CAs, higher-grade key hardware carry a premium. Because that premium no longer buys instant SmartScreen reputation, it's only worth paying when you actually need EV. Prices move, so confirm current figures with your CA or reseller rather than trusting a number in an old blog post.
Where My-SSL fits
| You ship ordinary Windows apps or installers and want warnings to fade fastest for the least cost | Standard (OV) code signing |
| You sign kernel-mode drivers, or a customer's policy names EV by contract | EV code signing |
| You're automating signing across build agents and need the key reachable in CI | Code signing in CI/CD |
How to choose in under a minute
Boil the whole decision down to two questions. Do you sign Windows kernel-mode drivers, or does an enterprise policy require EV by name? If yes to either, buy EV. If no to both, standard OV code signing is the right choice — it does everything ordinary software distribution needs, for less money and a faster turnaround.
Whichever tier you land on, two habits matter more than the choice itself: always timestamp your signatures so already-shipped builds keep verifying after the certificate expires, and plan a renewal overlap so your reputation curve doesn't reset to zero at the worst moment. Get those right and OV and EV both do their job.
FAQ
Ready to pick a tier?
My-SSL issues both standard (OV) and EV code signing certificates through Certum, a publicly trusted certificate authority, with the hardware key delivery the current rules require. Compare the tiers, key options, and validity on the code signing certificates page and match the certificate to how you actually build and ship.
Related reading
- Code signing certificates explained — the full primer on what these certificates do and what changed.
- Windows SmartScreen publisher reputation — how reputation is scored and how to make the warning go away.
- Code signing certificate validity: the 460-day limit — planning renewals under the 2026 change.
Sources worth checking directly
- Microsoft Learn — Code signing options for Windows app developers (SmartScreen reputation for OV and EV)
- Microsoft Learn — Driver Code Signing Requirements (EV needed to register for driver submission; WHCP)
- CA/Browser Forum — Baseline Requirements for Code Signing (hardware key rule and CSC-31 460-day validity)