Are you a developer or IT professional looking to digitally sign your code or software application, but not sure how to get a digital certificate? In this blog post, we will introduce you to some of the top providers where you can purchase these certificates at an affordable cost.
Please note that we are not affiliated with any of these vendors and aim to provide an unbiased overview of your available options.
DigiCert
DigiCert is the leading global provider of digital certificates and a trusted name in the internet security industry. The company was founded in 2003 and is headquartered in Lehi, Utah, USA.
DigiCert has gained notoriety, especially after the acquisition of Symantec’s Website Security and related PKI solutions in 2017, which strengthened its position as a top certification authority worldwide.
As of May 2024, DigiCert offers both standards (OV) and Extended Validation (EV) certificates with the following three service options and prices:
Code Signing – USB Token |
Code Signing – HSM |
Code Signing + Keylock |
---|---|---|
Use your hardware token or they will send you one with your subscription. |
Use your hardware security module (HSM). |
Cloud-based key storage and code signing service. |
$54 / OV Certificate/month | $72 / EV certificate/month |
$44 / OV Certificate/month | $62 / EV certificate/month |
$65 / OV Certificate/month | $83/EV certificate/month |
Annual subscription options are also available
For more details, visit DigiCert’s code token certificate section.
Sectigo (Comodo)
Sectigo, formerly known as Comodo CA, is a leading provider of digital identity solutions, including SSL/TLS certificates, digital signatures and managed PKI solutions. It is one of the largest certificate authorities in the world, helping to secure online transactions and online communications for millions of consumers and businesses.
As of May 2024, Sectigo offers Standard (OV) and Extended Validation (EV) certificates each in the following option:
OV code signing certificate |
EV Code Signing Certificate |
---|---|
Pricing starts at $429 per year. |
Pricing starts at $498 per year. |
Up to 37% off with a multi-year subscription. |
Up to 37% off with a multi-year subscription. |
There are no monthly options available.
For more details, you can check this direct link to Sectigo code token certificate purchase section. At the time this article was written, the Comodo website is still open and you can purchase certificates there. Sectigo chose to keep the old website as a sales platform to make the transition easier for buyers.
GLOBAL
GlobalSign is a highly respected and established provider of digital identity services, known for its wide range of digital certificate solutions and identity verification services. Founded in 1996, GlobalSign is one of the world’s oldest Certificate Authorities (CAs) and has developed a strong reputation for providing secure and reliable digital certificates.
As of May 2024, GlobalSign offers both standards (OV) and Extended Validation (EV) certificates with the following 2 options and prices:
Standard OV code signature |
EV Code Signing Certificate |
||
---|---|---|---|
Application of Token |
Implementation of HSM |
Application of Token |
Implementation of HSM |
– Storing the key on a USB stick or other hardware storage stick. – Token is NOT included. |
– Key storage in customer-provided HSM or Azure Key Vault. |
– Key storage on USB token, provided by GlobalSign. |
– Key storage in customer-provided HSM or Azure Key Vault. |
For more details, you can check this direct link to GlobalSign code signing certificate purchase section.
CONCLUSION
Choosing the right code signing certificate is essential to ensuring the security and trust of your software, whether you choose a cloud-based solution or secure hardware-based services.
Certificate authorities such as DigiCert, Sectigo and GlobalSign offer a variety of code signing options to suit different needs and budgets. While cloud-based services offer flexibility and scalability, on-premises solutions give you complete control. Hardware-based secure services provide robust security for critical applications.
Before deciding, consider your specific requirements, such as the level of trust needed, budget constraints, and ease of implementation. By choosing a reputable CA and the right code signing service, you can ensure that your software is secure and trusted by users and operating systems.