Code Signing Certificate Validity Is Shortening (459/460 Days)
-
The industry is reducing the maximum validity period for publicly trusted Code Signing certificates. Beginning March 1, 2026, the Code Signing Baseline Requirements set a maximum validity of 460 days per issued certificate. Some Certificate Authorities will enforce earlier:
- DigiCert starting Feb 24, 2026
- Sectigo starting Feb 23, 2026
- This change affects both new orders and renewals/reissues issued after the enforcement dates.
-
-
!
What’s changing
- Maximum certificate validity - 459 days
- Multi-year issuance is going away.
Historically, Code Signing certificates could be issued for up to ~39 months. After enforcement, CAs will stop offering 2- and 3-year validity selections for a single issued certificate.
-
DigiCert
Pending 2–3 year requests submitted before Feb 24 still must be issued before Feb 24 to keep the longer validity; otherwise they will be issued at 459 days.
No multi-year option available for orders issued after February 24. More details
-
Sectigo
Enforcement starts Feb 23, 2026: max validity 459 days. Multi-year Code Signing remains as a term, but requires reissuance during the term.
Multi-year delivery shifts to remote provisioning (customer-generated keys) and the multi-year Sectigo- provisioned (token-based) option is discontinued. More details
-
*
Will existing Code Signing certificates be affected?
No. Certificates issued before the enforcement date remain valid until they expire (unless revoked). The new maximum validity applies to certificates issued /reissued after the enforcement date(s).
-