OV Code Signing

Put your organization's name on every binary you distribute. OV Code Signing verifies and displays your verified company name — preventing “Unknown Publisher” warnings and building user trust from the first click.

Key Benefits

Organization name on installer

Your verified company name displayed when users install your software — eliminating “Unknown Publisher” warnings.

Tamper-evident signing

Modification after signing cryptographically breaks the signature, protecting users from altered software.

Trusted on all Windows versions

OV certificates prevent untrusted warning messages on all current and legacy Windows versions.

Unlimited rekeys and reissues

Operational flexibility — rekey or reissue at no extra cost throughout the certificate lifetime.

Who Is It For?

Software companies & ISVs

Distributing applications to end users who need to see a verified organization name on the installer.

Enterprise IT teams

Distributing internal tooling and utilities where a recognized publisher name is required.

Open source organizations

With a legal entity that want their verified organization name on distributed software.

Any organization shipping software

That wants its verified name on every installer screen without the extended EV requirements.

Purchase & Pricing

1. Select Certificate Duration

1 Year
$129.00/yr
2 Years
Save 10%
$116.10/yr
3 Years
Save 15%
$109.65/yr
4 Years
Save 20%
$103.20/yr
5 Years
Save 25%
$96.75/yr

2. Select Key Storage & Delivery (optional)

YubiKey

Physical Token
+ $279.00
YubiKey Quantity $279 each
Delivery Queue

Standard

3–5 business days after validation (Continental US)

Express + $329.00

1 day after validation

Bring Your own Cloud HSM

Self-managed infrastructure
+ Starting at $500.00

SSL.com must attest your key to your chosen provider before issuing the certificate. This fee is a one-time charge per order.

AWS CloudHSM
Attestation Fee
$1,500
Google Cloud HSM
Attestation Fee
$1,500
Azure Dedicated HSM
Attestation Fee
$500.00

What is attestation? Before issuing your certificate, SSL.com verifies that your private key was generated and is stored inside your cloud HSM — not exportable to software. This one-time attestation fee covers the verification process with your chosen provider.

Looking for a simpler option? SSL.com eSigner for Code provides cloud-based signing with no HSM to provision, no attestation fee, and a lower total cost for most teams.

Bring your own on-premises HSM

SSL performs an attestation ceremony for your compliant on-premises HSM.
+ Custom Pricing

Please contact sales.


3. Validation Speed (optional)

Choose how quickly your organization or identity is validated before your certificate is issued.

Standard

3–5 day validation · 2–3 day US shipping Validation completed after all agreements, entity info submitted, and a successful callback to a listed phone number. International shipping tracked; delivery subject to customs. Included

Expedited

2 business day validation · overnight US delivery 2 business days priority validation from first complete submission and callback. Token shipped overnight in continental US. +$599.00

How It Works

1 — Purchase

Select OV duration and complete your order.

2 — Organization validation

SSL.com validates your organization using business registration documentation.

3 — Certificate issued

Certificate issued with your verified organization name. Install on a FIPS token or enroll in eSigner for cloud signing.

4 — Sign your code

Users see your organization's name on the installer screen.

5 — Timestamp

Timestamp at signing to extend signature validity beyond certificate expiry.

Compliance & Standards

CA/B Forum Code Signing BR

Issued under CA/B Forum Code Signing Baseline Requirements.

WebTrust for Code Signing BR

SSL.com audited annually by BDO under WebTrust for Code Signing Baseline Requirements.

Microsoft Authenticode

Trusted on all Windows versions — prevents untrusted publisher warnings.

Frequently Asked Questions

OV signs with your organization's name and is trusted on Windows, but does not provide instant SmartScreen reputation. EV provides immediate SmartScreen reputation and is required for kernel-mode drivers.

Each certificate is issued to the organization but should be used by a single authorized signer. For multiple signers, each needs their own certificate or use a shared eSigner account.

No — if you timestamp at signing time, the signature remains valid indefinitely even after the certificate expires.

Yes — eligible for 30-day unconditional refunds per SSL.com's refund policy.

Ready to get OV Code Signing?

Put your verified organization name on every installer — trusted on all Windows versions from day one.

Related Products

IV Code Signing

Individual developer — personal name on installer, no business entity required.

EV Code Signing

Instant SmartScreen reputation, kernel-mode drivers — for registered organizations.

eSigner for Code

Cloud HSM signing for CI/CD pipelines — no hardware token required. Works with OV certificates.

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details