Obtaining OV/EV Code Signing Certificates from Japan — Eligibility for Companies, Sole Proprietors, and Individuals, with 2026 Pricing
In an earlier post, Distributing a Windows Desktop App Safely as a Japanese Company, I walked through choosing a distribution channel, signing with SignTool, and growing SmartScreen reputation. What I did not dig into was the procurement side: which one can you actually obtain, and what does it cost? This is the follow-up. It looks at OV and EV code signing certificates through the lens of whether a Japanese company or a Japan-resident individual can obtain them, based on eligibility and prices as of June 2026.
The first thing to stress: a code signing certificate is not “pick the cheapest and you’re done.” Before price there is a gate, namely whether you are even eligible to obtain one. Two axes decide that. One is the applicant type (a company, a sole proprietor, or an individual with no registered business); the other is geographic availability (whether the CA or service serves Japan at all). Settle those two first, then compare price among the options you can actually obtain.
Two regulatory shifts that changed how to read the price tag
As background to both price and eligibility, here are two recent rule changes common to every CA.
Hardware key storage became mandatory (June 2023)
Under the revised CA/Browser Forum Code Signing Baseline Requirements, since June 2023 both OV and EV certificates must have their private keys generated and stored on hardware certified to FIPS 140-2 Level 2 or Common Criteria EAL 4+ (or equivalent). Holding the private key in an exportable form, meaning the old .pfx (PKCS#12) file delivery, was discontinued.
That change erased the old advantage that “OV is cheap and convenient because it uses a software key.” OV and EV alike now require a physical USB token, a cloud HSM, or your own HSM. As a result, on top of the annual fee, the token cost (re-purchased if lost) and the shipping/customs lead time discussed below now affect both total cost and how hard the certificate is to obtain.
Validity periods got shorter (March 1, 2026)
Under CA/Browser Forum Ballot CSC-31, the maximum validity of a code signing certificate dropped from 39 months to 460 days (about 15 months), effective March 1, 2026. In step with this, DigiCert retired its 2- and 3-year plans, GlobalSign moved to 1-year products only, and SSL.com lowered its maximum day count. Multi-year contracts are still sold, but they assume annual certificate reissuance and re-receipt of a compliant device.
The practical meaning is simple: the per-year discount from multi-year contracts no longer bites as hard, and renewal operations happen more often.
EV no longer bypasses SmartScreen instantly
One more premise before selection. EV certificates used to come with an instant-trust perk: Microsoft SmartScreen would rate your binary positively the moment you signed it. Microsoft removed that behavior years ago. Today, both OV and EV clear the first-run warning only by accumulating download reputation.
In other words, in 2026 there is no rational reason to pay the EV premium solely to avoid SmartScreen warnings. EV remains mandatory only for Windows kernel-mode driver signing (registration in the Windows Hardware Dev Center portal) and for cases with strict identity-vetting or procurement-audit requirements. The detailed behavior is in the earlier post.
Who can obtain one: the applicant barrier
This is the core of this post. Unlike a server certificate, a code signing certificate vets the existence of the issuer (an organization or a person). So eligibility splits sharply by applicant type.
| Applicant | Eligible? | Notes |
|---|---|---|
| Japanese company | Yes | Almost any CA. Vetted via registry information, third-party database lookup, and a callback to the main phone number |
| Sole proprietor (with a business registration) | Some CAs | CAs like Sectigo are flexible if you can show existence. A DUNS number shortens vetting |
| Individual with no registered business | Generally not from major CAs | SSL.com’s IV leaves room. Otherwise register a business or move to the Microsoft Store |
Point by point:
- Japanese company: the most straightforward to obtain. For both OV and EV, you are vetted via corporate registry information, a third-party database lookup, and a callback to your main phone number. Since any CA will issue, you choose on price and operations rather than eligibility.
- Sole proprietor: if you can show existence with documents such as a business registration filed with the tax office, some CAs including Sectigo will issue, because it is treated as an application with organizational information.
- Individual with no registered business: most major CAs decline to issue to a private individual with no organizational information. As below, SSL.com IV (Individual Validation) leaves room, but the realistic workarounds are to register as a sole proprietor, or to move to certificate-free Microsoft Store (MSIX) distribution.
A DUNS number is the key to overseas CA vetting
When an overseas CA vets the existence of a Japanese business, registration in the DUNS database is the deciding factor. In Japan it is administered through Tokyo Shoko Research; with a registered DUNS number, you can clear the organization check with just an automated voice callback, sharply shortening the vetting period. A new registration takes about 1.5 months on the free standard tier, or about a week on a paid express tier. Whether you are a company or a sole proprietor, pre-registering smooths obtaining a certificate from an overseas CA.
flowchart TD
A["What is the applicant?"] --> B["Japanese company"]
A --> C["Sole proprietor"]
A --> D["Individual, no business"]
B --> B1["Obtainable from major CAs; choose on price"]
C --> C1["Obtainable from some CAs like Sectigo"]
C --> C2["DUNS registration shortens vetting"]
D --> D1["SSL.com IV leaves room"]
D --> D2["Register a business or use the Microsoft Store"]
Geographic availability: exclusions and shipping limits
Even past the applicant barrier, geographic limits can leave a service unusable or undeliverable.
Azure Trusted Signing excludes Japan
Microsoft’s own cloud signing service, Azure Trusted Signing (now Artifact Signing), is a bargain at $9.99/month and the strongest option technically. But Public Trust certificates are limited to “organizations in the USA, Canada, the EU, and the UK, plus individual developers in the USA and Canada,” and Japan is on neither list, for companies or individuals. So as of June 2026, neither a Japanese company nor a Japan-resident individual can use Azure Trusted Signing. The cheapest shortcut being geographically blocked is the single biggest reason obtaining from Japan is harder. Microsoft has signaled it will expand the regions, so if Japan is added it can be promoted to the top choice. Check the country list in the FAQ periodically.
The token may not reach Japan
For physical tokens, some CAs will not ship a token outside the region you selected at order time. GlobalSign explicitly states it does not ship tokens outside the region chosen at order time, so you must order in the region matching your company’s location. Buying directly from an overseas CA or reseller, the token may never reach Japan and the purchase stalls. Going through a domestic reseller (in-country shipping) or choosing token-free cloud HSM signing avoids this geographic risk.
Buying directly from an overseas CA also means the identity-vetting callback happens in English and across time zones (9 a.m. in the UK is 6 p.m. in Japan; 9 a.m. in Florida is 11 p.m. in Japan), which raises the bar for a first-time purchase.
Pricing of the options you can obtain
Assuming you meet the eligibility above, here are the prices. First the options easiest to obtain in yen, then the options bought directly in USD. All prices are published values as of June 2026, split into tax-excluded, tax-included, and token cost.
Options obtainable in yen
| Vendor | Type | Per year (excl. tax) | Per year (incl. tax) | Token cost | Ease of obtaining |
|---|---|---|---|---|---|
| Sectigo Japan (formerly Comodo Japan) | OV | 55,000 yen | 60,500 yen | 16,500 yen (incl.) | Cheapest published tier. Accepts sole-proprietor applications |
| Sectigo Japan (formerly Comodo Japan) | EV | 65,000 yen | 71,500 yen | 16,500 yen (incl.) | Cheapest tier even for EV. Flexible for sole proprietors |
| GMO GlobalSign | OV | 60,000 yen | 66,000 yen | 16,500 yen (incl.) | Domestic CA. Ships the token in-country |
| GMO GlobalSign | EV | 78,000 yen | 85,800 yen | 16,500 yen (incl.) | Fits WHDC driver signing |
| Slogical (DigiCert reseller) | OV | 89,000 yen | 97,900 yen | 18,700 yen (incl.) | Carries DigiCert in Japan. Supports deferred payment |
| Slogical (DigiCert reseller) | EV | 138,000 yen | 151,800 yen | 18,700 yen (incl.) | DigiCert EV with deferred payment |
| RMS (DigiCert authorized reseller) | OV | 115,200 yen | 126,720 yen | 24,090 yen (incl.) | Equivalent to DigiCert direct. HSM integration support |
| RMS (DigiCert authorized reseller) | EV | 171,300 yen | 188,430 yen | 24,090 yen (incl.) | Enterprise customization |
| DigiCert Japan (direct) | OV | 115,200 yen | 126,720 yen | Quote | Global market leader, industry standard |
| DigiCert Japan (direct) | EV | 171,300 yen | 188,430 yen | Quote | Consistent behavior across all platforms |
Lining up the major SKUs obtainable in yen, the gap between the cheapest tier (Sectigo Japan) and the high end (DigiCert direct/RMS) is two to three times. Any of them is obtainable by a Japanese company; the one with the widest door, down to sole proprietors, is Sectigo Japan.
xychart-beta
title "Annual price comparison (JPY, tax-excluded)"
x-axis ["Sectigo OV", "Sectigo EV", "GMO OV", "GMO EV", "DigiCert OV", "DigiCert EV"]
y-axis "JPY" 0 --> 180000
bar [55000, 65000, 60000, 78000, 115200, 171300]
For context, JPRS (known for selling SSL/TLS certificates) does not offer code signing certificates, and Cybertrust has discontinued some of its brands. Where to obtain Windows Authenticode code signing effectively converges on the three lineages above (Sectigo, GMO GlobalSign, DigiCert).
Options bought directly in USD
These are bought directly in USD from CAs that publish no JPY price. Apply the exchange rate (roughly 150 to 160 yen per dollar) and the apparent cheapness shrinks.
| Vendor | Type | Published price | Ease of obtaining / notes |
|---|---|---|---|
| DigiCert (official) | OV | $696/yr (own token/HSM), $840/yr (USB token) | KeyLocker variant adds about $300 |
| DigiCert (official) | EV | $972/yr (own token/HSM), $1,116/yr (USB token) | KeyLocker variant adds about $300 |
| GlobalSign (US) | OV | $434/yr | 1 year only. Tokens not shipped outside the ordered region |
| GlobalSign (US) | EV | $550/yr | 1 year only |
| Sectigo (official) | OV/EV | From about $536/yr on a 5-year purchase | Free FIPS-compliant token shipped annually |
| SSL.com (official) | OV/EV | OV $129/yr, EV $349/yr (much less on 5-year) | Issues IV (for individuals). Token-free via eSigner |
In USD, SSL.com looks cheap, but on top of the headline price the YubiKey cost (+$379), eSigner charges, and Cloud HSM attestation fee ($500–1,500) are separate line items, and token shipping guidance is US-centric. Keep the headline price and the total cost to obtain separate. On the other hand, SSL.com is one of the few options where even an individual with no registered business can obtain IV (Individual Validation) code signing, and signing through the fully cloud eSigner sidesteps the token-shipping problem. For an individual developer who can tolerate USD payment and an English-language process, it is a realistic path to obtaining a certificate.
Cloud signing service pricing and eligibility
If you want to sign automatically on every CI/CD build, physically inserting a token is impractical, so a cloud HSM signing service becomes the option. Its pricing is separate from the certificate, so treat it on its own, with availability to Japanese organizations noted alongside.
| Service | Price | Available to Japanese organizations | Form |
|---|---|---|---|
| Azure Trusted Signing (Artifact Signing) | Basic $9.99/mo (5,000 signings), Premium $99.99/mo (100,000 signings), $0.005/signing over | No (Japan excluded) | Fully managed, FIPS 140-2 Level 3 HSM, short-lived 72-hour certificates renewed daily |
| SSL.com eSigner (IV/OV/EV) | Tier 1 $15/mo (240 signings) to Tier 4 $187.50/mo (12,000 signings); ~25% off annually | Yes (individuals via IV) | Cloud HSM, automated via CodeSignTool |
| DigiCert KeyLocker | Service fee at certificate purchase (1,000 signings per certificate) | Yes (via CertCentral) | Cloud HSM (FIPS 140-2 Level 3), CI/CD integration |
| DigiCert Software Trust Manager | Quote (enterprise) | Yes | Policy control, audit logs, SBOM, RBAC |
To repeat, the cheapest option, Azure Trusted Signing, excludes Japan. If you want to keep automated signing fully in the cloud from Japan, the realistic answers today are SSL.com eSigner or DigiCert KeyLocker. Neither needs a physically inserted token, so they also dissolve the shipping/customs geographic risk.
Which is cheaper, a physical token or cloud HSM
The certificate fee itself is roughly the same either way, so the difference is in operating cost. A physical token requires human effort on every signing (finding the token, inserting it, entering the PIN, updating the SafeNet client). A cloud HSM costs a monthly base fee and an initial setup cost, but in exchange the per-signing human effort is essentially zero.
Let N be the number of signings per year, h the manual time per signing, w the team’s hourly cost, F the cloud HSM annual base fee, and I the initial setup cost. The break-even where the two are equal can be written as:
Physical token / yr = token cost + N × h × w
Cloud HSM / yr = F + I + N × t (t ≈ 0)
Break-even N* ≈ (F + I − token cost) / (h × w)Plug in 2026 market values: token cost 18,700 yen, manual time h = 0.25 hour (15 min), hourly cost w = 4,000 yen, cloud annual base fee F = about 9,000 yen (Azure Key Vault HSM key), initial setup I = about 40,000 yen (CI/CD configuration and signing verification, 10 hours):
N* ≈ (9,000 + 40,000 − 18,700) / (0.25 × 4,000)
= 30,300 / 1,000
≈ 31 signings/yearSo if your organization builds and signs more than 31 times a year, cloud HSM signing wins on total cost. As a rule of thumb, if you release more than about three times a month, leaning into automation is cheaper. Conversely, if you sign infrequently and hand-signing suffices, a physical token is simpler and cheaper (you never recoup the first-year setup cost).
flowchart TD
A["Estimate signings per year"] --> B{"More than 31 per year?"}
B -->|Yes| C["Cloud HSM signing"]
B -->|No| D["Physical token"]
C --> C1["SSL.com eSigner / DigiCert KeyLocker"]
C --> C2["Auto-sign in CI/CD, avoid shipping & customs"]
D --> D1["Domestic reseller ships the token in-country"]
D --> D2["Hand-sign with SignTool"]
Recommendations by applicant
Pulling it together by who is obtaining the certificate.
| Applicant | Recommendation | Why |
|---|---|---|
| Japanese company (ordinary user-mode app) | Choose OV on price; cheapest tier is Sectigo Japan | Easy to obtain with a wide price gap. OV is enough without driver signing |
| Japan-resident sole proprietor | Sectigo Japan OV | Has a sole-proprietor application path. Pre-register a DUNS number to shorten vetting |
| Individual developer with no business | SSL.com IV, or register a business / Microsoft Store | Major CAs generally do not issue to individuals. IV, or certificate-free Store distribution, is realistic |
| Signing kernel-mode drivers | EV (DigiCert or GMO GlobalSign) | EV is mandatory. Supports WHDC portal registration |
A criterion that flips the decision: if Microsoft adds Japan to the Azure Trusted Signing regions, both companies and individuals could use it at $9.99/month and the eligibility problem dissolves at once, promoting it to the top choice. And remember that with EV’s instant SmartScreen trust gone, OV is enough unless you need driver signing, so there is little reason to pay the EV premium.
Caveats
Both eligibility and price move, so reconfirming on each vendor’s official page before ordering is mandatory.
- A CA’s policy toward sole proprietors and individuals can change. Confirm eligibility for an individual with no business directly with each CA before applying
- Overseas reseller prices (SignMyCode, SSL2BUY, and the like) swing with exchange rates and promotions. The USD prices here are 2025–2026 reference values
- The official direct USD prices for DigiCert, Sectigo, and GlobalSign mix quote-based and estimated figures. RMS’s JPY prices are reference list prices; the actual price is by separate quote
- This research could not confirm any domestic reseller offering SSL.com certificates in yen. If you obtain one, buying directly from SSL.com (in USD) is the realistic path
- A weak yen shrinks the apparent USD discount. SSL.com EV at $349 is roughly 52,000 to 56,000 yen (at 150–160 yen per dollar), not far from the cheapest JPY tier, Sectigo Japan EV at 65,000 yen
- Token and shipping costs are generally one-time (reusable on renewal), but overseas shipping and customs can add a lead time of days to weeks
Conclusion
A code signing certificate starts with confirming you can obtain one, before comparing price. Three takeaways for 2026: a Japanese company can obtain one from almost any CA and choose on price and operations (cheapest tier: Sectigo Japan). An individual with no business is generally not issued one by major CAs, so route around it with SSL.com IV, registering as a sole proprietor, or certificate-free Microsoft Store distribution. And Microsoft’s own cheap Azure Trusted Signing excludes Japan geographically, so traditional CAs are the realistic answer for now.
Channel selection and the SignTool signing procedure are covered in the earlier post. Pair them with this eligibility and price comparison to judge, along the shortest path, who obtains which certificate and how.
References
- CA/Browser Forum: Code Signing Working Group
- Microsoft: SmartScreen reputation-based protection
- Microsoft: Azure Trusted Signing
- Microsoft: Windows Hardware Dev Center
- GMO GlobalSign: Code Signing Certificates
- DigiCert: Code Signing Certificates
- DigiCert: KeyLocker
- Sectigo: Code Signing
- SSL.com: Code Signing Certificates
- Tokyo Shoko Research: DUNS number
- Earlier post: Distributing a Windows Desktop App Safely as a Japanese Company