Skip to main content
    Code Signing

    EV vs OV Code Signing: Which One Do You Actually Need?

    EV vs OV code signing in 2026: EV no longer skips SmartScreen, so most publishers need only standard OV. When EV is still required, and what both now cost.

    MS
    My-SSL Security Team
    ·
    12 min read
    ·Published July 16, 2026·Last updated July 16, 2026

    The short answer

    For most software publishers in 2026, standard OV code signing is the right choice. EV no longer skips Microsoft SmartScreen warnings — that instant-reputation behaviour was removed in 2024 — so OV and EV now build reputation the same slow way, through download history. Choose EV only when you genuinely need it: to register for Windows kernel-mode driver submission through Microsoft's Hardware Dev Center, or when an enterprise customer's procurement rules demand it. Both tiers verify a registered organization, both require the private key on FIPS 140-2 Level 2 hardware (a rule in force since June 1, 2023), and both are capped at 460 days of validity for certificates issued on or after March 1, 2026.

    If you already know you're buying and just want to see the tiers side by side, the OV and EV code signing certificates pages lay out validation, key delivery, and price for each. If you're still deciding, the rest of this guide walks through exactly when each one earns its cost.

    OV vs EV code signing: what actually differs

    OV and EV are the two validation levels for publicly trusted code signing certificates, and they share far more than they differ. Both prove your software came from a verified, registered organization, both bind that identity to a tamper-evident signature, and since June 2023 both keep their private key on certified hardware. The differences come down to how deeply the CA vets you, and a handful of platform rules.

    OV — Organization Validation, usually marketed as "standard" code signing — confirms your organization is real and legally registered, then issues. EV — Extended Validation — layers on stricter checks (enterprise identifiers, operational-existence and phone verification, sometimes a signed authorization), so it takes longer to issue. A few CAs also store EV keys on FIPS 140-2 Level 3 hardware rather than Level 2. Neither is issued to anonymous individuals anymore; the old "individual" code signing certificate is gone.

    OV versus EV code signing comparison panelA side-by-side panel comparing OV (standard) and EV code signing across identity vetting, key hardware, SmartScreen behaviour, driver eligibility and issuance speed. The SmartScreen row is highlighted to show both tiers now build reputation the same way.OV (Standard)EV (Extended)Verifies an organizationYesYes, stricterPrivate key on FIPS hardwareLevel 2+Level 2+ (some L3)SmartScreen reputationEarned over timeEarned over timeRegister for driver signingNoYesIssuance speedFasterSlower
    The one row that used to decide the purchase — SmartScreen — is now identical for both tiers, which is exactly why the old "always buy EV" advice no longer holds.

    Read that panel top to bottom and one thing stands out: the row publishers used to buy EV for — SmartScreen — now reads the same in both columns. That single change reshaped the whole decision, so it's worth understanding precisely.

    Does EV still skip SmartScreen? No — and here's what changed

    EV code signing no longer grants instant Microsoft SmartScreen reputation. For years an EV-signed installer sailed past the "Windows protected your PC" screen on its very first download while OV software had to earn trust slowly. Microsoft removed that shortcut in 2024. As of its current developer documentation, a fresh EV-signed download can still trip SmartScreen until it accumulates a download history — exactly like OV.

    Why the change? Malware operators had turned EV into a commodity — buying certificates through shell companies or stealing them specifically to inherit that instant trust. The shortcut had become a liability, so Microsoft moved to reputation earned through real-world download telemetry for every certificate, regardless of tier. Microsoft doesn't publish the download threshold, and it varies.

    SmartScreen reputation over time for OV and EV signingA schematic line chart. Both OV and EV signed software follow the same upward reputation curve as downloads accumulate, crossing the "warnings stop" line at the same point. A gold marker shows reputation dropping to zero at certificate renewal.ReputationDownloads over time →Warnings stopOV = EV: same climbRenewal resets to zero
    Reputation is tied to one certificate, so a renewal or CA switch drops you back to the bottom of the same curve — plan overlaps around your renewal, whichever tier you buy.

    There's a footgun hiding in that curve. Reputation attaches to one specific certificate, so when you renew, rekey, or switch CA, the replacement starts from zero and warnings can reappear right after a renewal. Teams that ship continuously dual-sign during the overlap window so the new certificate banks reputation before the old one lapses. This bites harder now that certificates renew roughly yearly — we cover the mechanics in our SmartScreen publisher reputation guide. The bottom line: if your only reason to pay for EV was to dodge SmartScreen, that reason is gone.

    When you genuinely need EV code signing

    EV is still the required choice in two clear situations, and a defensible one in a third. Reach for it on purpose, not as a default. The old catch-all justification is gone, but these cases are real, and in them OV simply won't do the job.

    • Windows kernel-mode drivers. To submit drivers, you need an EV certificate to open the Microsoft Hardware Dev Center (Partner Center) account in the first place. The driver itself is then signed through Microsoft's attestation process, not directly with your certificate. As of April 2026, Microsoft enforces Windows Hardware Compatibility Program checks for new kernel drivers and has removed trust for the legacy cross-signed driver path — so this route is now the only supported one. Our guide to signing a Windows driver walks the full submission flow.
    • Enterprise procurement that names EV. Some large customers' security policies still specify "EV code signing" by name. When a contract or vendor questionnaire requires it, EV is simply a checkbox you have to tick, independent of the technical merits.
    • A deliberate trust signal (weaker than it used to be). EV's stricter vetting can still matter to a security-conscious audience or an internal policy that values the highest assurance level. Just don't expect it to change the end user's install experience the way it once did.

    When standard OV code signing is the right call

    For the ordinary job of shipping trusted Windows software, standard OV code signing is now the sensible default. It verifies your organization, produces a valid Authenticode signature, replaces the "Unknown Publisher" label with your real name, and builds SmartScreen reputation on the same curve as EV — for less money and with faster issuance.

    OV fits the large majority of publishers: desktop apps and installers (EXE, MSI), PowerShell scripts, Java archives, and most CI/CD signing pipelines. The one caveat is your key-storage model, which matters more than the OV-versus-EV label once you're automating. A single USB token is painful to share across build agents, so pipelines usually move to a cloud signing service or HSM — a trade-off we break down in cloud code signing vs USB tokens. If you're distributing software for macOS, note that neither OV nor EV applies — that's Apple's separate Developer ID and notarization system.

    Price, validity, and the 2026 changes that affect both

    Two industry-wide rules now apply equally to OV and EV, so they don't tilt the decision — but they change how you plan and budget. Both stem from CA/Browser Forum baseline requirements, and both are worth pricing in before you buy either tier.

    Hardware keys, since June 1, 2023. Every publicly trusted code signing certificate — OV and EV — must generate and hold its private key on hardware certified to at least FIPS 140-2 Level 2 or Common Criteria EAL 4+, with the key non-exportable. The software-only PFX file you could copy onto a build server is dead for public code signing. In practice you provision via a CA-shipped USB token, your own compliant HSM, or a cloud signing service.

    460-day validity, from March 1, 2026. Under ballot CSC-31 (adopted November 2025), certificates issued on or after March 1, 2026 max out at 460 days — about 15 months — down from the old 39-month ceiling. Some CAs began enforcing a 459-day cap a few days earlier. Buyers used to three-year certificates now face roughly annual renewals, so multi-year plans (a price lock with periodic reissues) and renewal planning around the 460-day limit matter more than they did.

    On price, EV costs more than OV — the deeper validation and, with some CAs, higher-grade key hardware carry a premium. Because that premium no longer buys instant SmartScreen reputation, it's only worth paying when you actually need EV. Prices move, so confirm current figures with your CA or reseller rather than trusting a number in an old blog post.

    Where My-SSL fits

    You ship ordinary Windows apps or installers and want warnings to fade fastest for the least costStandard (OV) code signing
    You sign kernel-mode drivers, or a customer's policy names EV by contractEV code signing
    You're automating signing across build agents and need the key reachable in CICode signing in CI/CD

    How to choose in under a minute

    Boil the whole decision down to two questions. Do you sign Windows kernel-mode drivers, or does an enterprise policy require EV by name? If yes to either, buy EV. If no to both, standard OV code signing is the right choice — it does everything ordinary software distribution needs, for less money and a faster turnaround.

    Decision tree for choosing EV or OV code signingA decision tree. If you sign Windows kernel-mode drivers, choose EV. If an enterprise procurement policy requires EV, choose EV. Otherwise standard OV code signing is the right choice for ordinary applications and installers.Signing Windows kernel-modedrivers?YesNoEnterprise policyexplicitly requires EV?YesNoChoose EVthe specific-need caseChoose OVthe default for most apps
    Two yes/no questions settle it: EV is the exception you reach for on purpose, not the safe default it used to be.

    Whichever tier you land on, two habits matter more than the choice itself: always timestamp your signatures so already-shipped builds keep verifying after the certificate expires, and plan a renewal overlap so your reputation curve doesn't reset to zero at the worst moment. Get those right and OV and EV both do their job.

    FAQ

    Ready to pick a tier?

    My-SSL issues both standard (OV) and EV code signing certificates through Certum, a publicly trusted certificate authority, with the hardware key delivery the current rules require. Compare the tiers, key options, and validity on the code signing certificates page and match the certificate to how you actually build and ship.

    Related reading

    Sources worth checking directly

    • Microsoft Learn — Code signing options for Windows app developers (SmartScreen reputation for OV and EV)
    • Microsoft Learn — Driver Code Signing Requirements (EV needed to register for driver submission; WHCP)
    • CA/Browser Forum — Baseline Requirements for Code Signing (hardware key rule and CSC-31 460-day validity)