Certum Cloud EV CODE Signing certificate
The Certum Cloud EV CODE Signing certificate is the most trusted CODE certificate from the Certum certification authority. Thanks to secure cloud-based key storage, there is no need to have a physical token or smart card with the keys connected to the computer. It offers convenient code signing from anywhere with internet access using the SimplySign applications.
EV Code Signing certificates became especially popular due to their ability to "bypass" the Microsoft SmartScreen filter, which displays warnings when installing unknown applications. However, Microsoft removed this advantage in its 2026 updates, and the certificates no longer guarantee immediate removal of these warnings. EV Code Signing certificates are required for signing kernel-mode drivers and system components for Microsoft Windows. They are intended for hardware developers, system software developers, and organizations that require the highest level of company validation.
- Firma de código basada en la nube
- firma sencilla con SignTool, compatible con ClickOnce
- autoridad de certificación europea de confianza
- we also offer standard Certum Cloud CODE Signing
Signing with Certum EV Code Sign Cloud
File signing is performed on a workstation (PC, Mac) using the installed SimplySign Desktop application, which emulates a card reader with a physical crypto card while securely connecting everything to the certificate stored in the cloud. For the operating system, the Code Signing certificate is installed locally. The connection is established through the SimplySign app on a mobile phone, which generates a dynamic numeric token. It is a standard TOTP application (functionally similar to Google Authenticator, for example). After entering the token into SimplySign Desktop, code signing is enabled for 2 hours. This two-hour window is provided for security reasons. Entering a new activation extends the window for another 2 hours. You can then sign files on the workstation using Microsoft SignTool as usual. The SimplySign app and SimplySign Desktop applications are available free of charge.
If you are interested in Code Signing, we recommend reading our detailed documentation.
The Certum Cloud EV CODE Signing certificate is a popular EV Code SSL certificate.
Explore our other CODE certificate offerings → CODE Signing Certificates.
Please note that EV Code certificates cannot be issued to companies using a virtual office address!
The price includes: obtaining an SSL certificate, basic technical support for the order
Multi-year - The final multi-year price is given in parentheses.
Based on the new standards, CODE certificates are issued with a maximum validity of 460 days. For multi-year CODE certificates, one or more REISSUEs will be required to use the entire period.
Payment - We accept payments by card, PayPal and bank transfer.
For payments in EUR, please switch above to EUR → [ $ | € ].
Features and Benefits of Certum Cloud EV CODE Signing certificates
Application security
A Code Signing Certificate maintains code integrity and prevents your name from being misused to distribute counterfeit software or modify code.
Distribution support
Signed applications help increase download numbers and sales revenue. Increased trust helps expand distribution channels for your software.
Customer confidence
Signed software protects customers from malware and other malicious threats. A digital signature protects and reassures customers that the integrity of the code they have downloaded is ensured and that the program is intact, not damaged, or altered in any way. Increased trust promotes better user perception of the application.
Authenticity
After downloading, the user has the certainty that the code obtained actually comes from you as the software creator. Code Signing Certificates allow customers to identify the author of a digitally signed code and confirm that the program comes from the expected publisher.
Seamless integration
The offered Code Signing certificates can be used for Windows and MacOS operating systems without any problems. All certification authorities work with companies such as Microsoft or Apple and follow their recommendations and policies for issuing certificates according to the CA/Browser Forum.
30 Days Money Back Guarantee
Customer experience is the first and foremost priority for us. The selected SSL certificate is not suitable for your needs? Do you want another one? Or do you just want to cancel the order? We offer 30 Days Money Back Guarantee for all our customers. Check out our Refund Policy to know more.
SSLmentor recommendation
The Certum Extended Validation Cloud CODE certificate is the most trusted certificate from CA Certum for software signing. It is suitable for companies developing for Windows OS, where high trust requirements are required.
More information about Certum Cloud EV CODE Signing
What you should know before you place an order.
Extended Validated CODE certificate
EV Code Signing entails extensive vetting of the applicant
EV certificates are the most trusted certificates, and for this reason, the validation team very carefully and consistently validates certificate applicants.
Validation Requirements and Process
- Online verification of the ADMIN contact (ID document and facial scan).
Validation takes place using Automatic identity verification. - Submission of a business registration document (e.g. full company formation document, official extract, or record from a government registry).
The document must include all information, such as the name and address of the organization, and information about the individuals authorized to represent it. We recommend also providing a DUNS number (if available). - Submission of proof of address (e.g. utility bill such as water, gas, electricity, or a fixed-line telecommunications service bill).
Without valid proof of address, the EV Code certificate cannot be issued. Virtual company addresses are not accepted. - Submission of a signed POA (if the ADMIN contact is not the CEO).
- Any additional communication with the validation team, if required.
More information on CODE certificate verification is available at support.certum.eu: Code Signing - required documents.
Note i: In some cases, the CA will contact the applicant to clarify the location or provide information on the purpose for which the CODE certificate will be used. These inquiries should always be responded to as soon as possible.
Note ii: When applying for a CODE certificate, we recommend that you also check your spam folder, where some emails may end up.
How long it takes to get the Certum Cloud EV CODE Signing certificate
The certification authority performs thorough verification of the company and the applicant
Issuance time for EV CODE certificate: 5+ business days
Company verification is carried out in accordance with the strict rules of the CA/Browser Forum. Correct and sufficient documentation must be provided and the CA validation process must be completed.
Renewing your certificate
You need to renew Certum Cloud EV CODE Signing certificate before it expires
We recommend to start renewing an expiring SSL certificate approx. 30 days before it expires. Renewing a CODE certificate is practically like applying for a new one and is therefore no faster. If you need to continue signing on an expiring certificate, definitely don't leave renewal to the last minute.
You can renew your Certum Cloud EV CODE Signing certificate with us without any problem even if you originally ordered it from another supplier. We always have better prices than the certification authority!
Microsoft SmartScreen
The security guard in the Windows ecosystem
In the spring of 2024, company Microsoft announced a plan to evaluate EV Code certificates in the same way as regular Code certificates. This means that EV Code certificates will no longer automatically "skip" the SmartScreen filter, but will have to build a reputation under Microsoft's control. These changes have been showing up after the updates since April 2026.
Note: In security updates in 2026, Microsoft is gradually removing the EV code benefit, and the certificates no longer guarantee immediate removal of SmartScreen warnings! In some versions of the Windows operating system, EV Code certificates still work and automatically "skip" SmartScreen. We recommend that those interested in signing EV Code order a certificate for a maximum of 1 year.
For more information see What is Windows SmartScreen?
Time Stamping Server
Time Stamp Server & Stamping Protocols for Code Signing
RFC3161 compliant Time Stamp Authority (TSA) server: http://time.certum.pl
FAQ
Frequently Asked Questions
How much do the SimplySign mobile app and SimplySign Desktop cost?
Both apps are free to download.
What is the difference between SimplySign App and SimplySign Desktop?
The SimplySign mobile app is used to generate one-time authentication codes (TOTP) required to authorize access in SimplySign Desktop. SimplySign Desktop establishes a secure connection to the cloud service where your code signing certificate and private key are securely stored.
Can I keep the certificate connected all the time?
No, it is not possible. SimplySign Desktop maintains an active secure session for up to two hours. If you need more time, you can sign out and sign in again at any time to start a new two-hour session.
How many times can I use a CODE certificate?
Each certificate can be used for up to 5,000 signatures per month. If this limit is exceeded, the certification authority may contact you and temporarily suspend the certificate until the next monthly period.
Are there any additional costs?
No. The price you pay includes the entire validity period of the certificate. There are no additional fees payable to the certification authority.
Can I obtain an EV Code Signing certificate if my company uses a virtual office?
No. The certification authority requires proof of a physical business address during the validation process. Companies that operate solely from a virtual office cannot obtain an EV Code Signing certificate.
We don't have a utility bill.
Proof of your company's business address is a mandatory part of the validation process. If you cannot provide a utility bill, the certification authority may review your application individually and request alternative documents. However, approval is not guaranteed, and the certificate may not be issued if the address cannot be verified to the CA's satisfaction.
Why must the applicant for a CODE certificate be verified?
The certification authority (CA) must verify the identity of every applicant before issuing a code signing certificate. This verification follows industry requirements defined by the CA/Browser Forum as well as the CA's own security policies. Any improperly issued certificate could undermine the trust placed in the certification authority, which is why every application is reviewed carefully.
This process ensures digital trust. It is not just a "paper certificate" from a short course, but a globally recognized security standard. To avoid delays, please provide all requested documents and follow the validation team's instructions.
How long does the verification process take and when can I start signing?
Document review and identity verification typically take 2–4 business days once the certification authority receives all required documents. Please note that there is no guaranteed processing time (ETA), as each order is carefully reviewed through several validation steps.
The time it takes to complete the process depends on the speed of the applicant's response, the quality of the documents provided, and the workload of the certification authority, which must thoroughly verify everything. Once the certificate is issued, you can immediately start signing.
Can I use the certificate on multiple computers?
Yes. SimplySign Desktop can be installed on multiple computers. After signing in and completing two-factor authentication, you can use the same cloud certificate on any authorized device.
Do I need a USB token?
No. The private key is securely stored in Certum's cloud infrastructure, so no USB token or hardware security key is required.
Can I get or export a PFX file?
Exporting the certificate as a PFX file is no longer supported due to current CA/Browser Forum requirements and modern security standards.
Can I move my certificate to Azure Key Vault or Google Cloud HSM?
No. The private key remains securely stored within the Certum cloud infrastructure and cannot be exported or transferred to third-party HSM services such as Azure Key Vault or Google Cloud HSM.
Can I use the certificate in GitHub Actions or other CI/CD pipelines?
Not at the moment. Certum plans to introduce CI/CD support in the future, but no release date has been announced.
What happens if I replace my computer?
Simply install SimplySign Desktop on the new computer and sign in again. Since the certificate is stored securely in the cloud, it is not tied to a specific computer.
What if I lose my phone or get a new one?
If you lose your mobile phone or replace it with a new device, you will need to regain access to your SimplySign account. You can submit a request from your order details in the Control Panel. Once your request has been reviewed, we will send you a new SimplySign activation link.
