Major tech companies are enforcing a new 460-day maximum validity period for code signing certificates in 2026, down from previous multi-year lifespans. This change, driven by the CA/Browser Forum, aims to reduce supply chain attack windows by forcing regular key rotation and verification. Microsoft, Google, and Apple are hardcoding these policies into their platforms, blocking non-compliant software. Organizations must transition from file-based keys to FIPS-compliant hardware (HSMs or USB tokens), audit existing certificates, automate signing workflows, and update CI/CD pipelines to avoid distribution disruptions.
Table of contents
The Evolution of Trust: A Look Back at Code Signing ChangesThe 2026 Standard: The New 460-Day Validity RuleHow Tech Giants Are Enforcing These New PoliciesThe “Why” Behind the Crackdown: Supply Chain SecurityAction Plan: How Developers Can Prepare for 2026Conclusion697 Impressions