Obtaining OV/EV Code Signing Certificates from Japan — Eligibility for Companies, Sole Proprietors, and Individuals, with 2026 Pricing

Tadashi Shigeoka · Tue, June 30, 2026

In an earlier post, Distributing a Windows Desktop App Safely as a Japanese Company, I walked through choosing a distribution channel, signing with SignTool, and growing SmartScreen reputation. What I did not dig into was the procurement side: which one can you actually obtain, and what does it cost? This is the follow-up. It looks at OV and EV code signing certificates through the lens of whether a Japanese company or a Japan-resident individual can obtain them, based on eligibility and prices as of June 2026.

The first thing to stress: a code signing certificate is not “pick the cheapest and you’re done.” Before price there is a gate, namely whether you are even eligible to obtain one. Two axes decide that. One is the applicant type (a company, a sole proprietor, or an individual with no registered business); the other is geographic availability (whether the CA or service serves Japan at all). Settle those two first, then compare price among the options you can actually obtain.

Two regulatory shifts that changed how to read the price tag

As background to both price and eligibility, here are two recent rule changes common to every CA.

Hardware key storage became mandatory (June 2023)

Under the revised CA/Browser Forum Code Signing Baseline Requirements, since June 2023 both OV and EV certificates must have their private keys generated and stored on hardware certified to FIPS 140-2 Level 2 or Common Criteria EAL 4+ (or equivalent). Holding the private key in an exportable form, meaning the old .pfx (PKCS#12) file delivery, was discontinued.

That change erased the old advantage that “OV is cheap and convenient because it uses a software key.” OV and EV alike now require a physical USB token, a cloud HSM, or your own HSM. As a result, on top of the annual fee, the token cost (re-purchased if lost) and the shipping/customs lead time discussed below now affect both total cost and how hard the certificate is to obtain.

Validity periods got shorter (March 1, 2026)

Under CA/Browser Forum Ballot CSC-31, the maximum validity of a code signing certificate dropped from 39 months to 460 days (about 15 months), effective March 1, 2026. In step with this, DigiCert retired its 2- and 3-year plans, GlobalSign moved to 1-year products only, and SSL.com lowered its maximum day count. Multi-year contracts are still sold, but they assume annual certificate reissuance and re-receipt of a compliant device.

The practical meaning is simple: the per-year discount from multi-year contracts no longer bites as hard, and renewal operations happen more often.

EV no longer bypasses SmartScreen instantly

One more premise before selection. EV certificates used to come with an instant-trust perk: Microsoft SmartScreen would rate your binary positively the moment you signed it. Microsoft removed that behavior years ago. Today, both OV and EV clear the first-run warning only by accumulating download reputation.

In other words, in 2026 there is no rational reason to pay the EV premium solely to avoid SmartScreen warnings. EV remains mandatory only for Windows kernel-mode driver signing (registration in the Windows Hardware Dev Center portal) and for cases with strict identity-vetting or procurement-audit requirements. The detailed behavior is in the earlier post.

Who can obtain one: the applicant barrier

This is the core of this post. Unlike a server certificate, a code signing certificate vets the existence of the issuer (an organization or a person). So eligibility splits sharply by applicant type.

ApplicantEligible?Notes
Japanese companyYesAlmost any CA. Vetted via registry information, third-party database lookup, and a callback to the main phone number
Sole proprietor (with a business registration)Some CAsCAs like Sectigo are flexible if you can show existence. A DUNS number shortens vetting
Individual with no registered businessGenerally not from major CAsSSL.com’s IV leaves room. Otherwise register a business or move to the Microsoft Store

Point by point:

  • Japanese company: the most straightforward to obtain. For both OV and EV, you are vetted via corporate registry information, a third-party database lookup, and a callback to your main phone number. Since any CA will issue, you choose on price and operations rather than eligibility.
  • Sole proprietor: if you can show existence with documents such as a business registration filed with the tax office, some CAs including Sectigo will issue, because it is treated as an application with organizational information.
  • Individual with no registered business: most major CAs decline to issue to a private individual with no organizational information. As below, SSL.com IV (Individual Validation) leaves room, but the realistic workarounds are to register as a sole proprietor, or to move to certificate-free Microsoft Store (MSIX) distribution.

A DUNS number is the key to overseas CA vetting

When an overseas CA vets the existence of a Japanese business, registration in the DUNS database is the deciding factor. In Japan it is administered through Tokyo Shoko Research; with a registered DUNS number, you can clear the organization check with just an automated voice callback, sharply shortening the vetting period. A new registration takes about 1.5 months on the free standard tier, or about a week on a paid express tier. Whether you are a company or a sole proprietor, pre-registering smooths obtaining a certificate from an overseas CA.

flowchart TD
    A["What is the applicant?"] --> B["Japanese company"]
    A --> C["Sole proprietor"]
    A --> D["Individual, no business"]
    B --> B1["Obtainable from major CAs; choose on price"]
    C --> C1["Obtainable from some CAs like Sectigo"]
    C --> C2["DUNS registration shortens vetting"]
    D --> D1["SSL.com IV leaves room"]
    D --> D2["Register a business or use the Microsoft Store"]

Geographic availability: exclusions and shipping limits

Even past the applicant barrier, geographic limits can leave a service unusable or undeliverable.

Azure Trusted Signing excludes Japan

Microsoft’s own cloud signing service, Azure Trusted Signing (now Artifact Signing), is a bargain at $9.99/month and the strongest option technically. But Public Trust certificates are limited to “organizations in the USA, Canada, the EU, and the UK, plus individual developers in the USA and Canada,” and Japan is on neither list, for companies or individuals. So as of June 2026, neither a Japanese company nor a Japan-resident individual can use Azure Trusted Signing. The cheapest shortcut being geographically blocked is the single biggest reason obtaining from Japan is harder. Microsoft has signaled it will expand the regions, so if Japan is added it can be promoted to the top choice. Check the country list in the FAQ periodically.

The token may not reach Japan

For physical tokens, some CAs will not ship a token outside the region you selected at order time. GlobalSign explicitly states it does not ship tokens outside the region chosen at order time, so you must order in the region matching your company’s location. Buying directly from an overseas CA or reseller, the token may never reach Japan and the purchase stalls. Going through a domestic reseller (in-country shipping) or choosing token-free cloud HSM signing avoids this geographic risk.

Buying directly from an overseas CA also means the identity-vetting callback happens in English and across time zones (9 a.m. in the UK is 6 p.m. in Japan; 9 a.m. in Florida is 11 p.m. in Japan), which raises the bar for a first-time purchase.

Pricing of the options you can obtain

Assuming you meet the eligibility above, here are the prices. First the options easiest to obtain in yen, then the options bought directly in USD. All prices are published values as of June 2026, split into tax-excluded, tax-included, and token cost.

Options obtainable in yen

VendorTypePer year (excl. tax)Per year (incl. tax)Token costEase of obtaining
Sectigo Japan (formerly Comodo Japan)OV55,000 yen60,500 yen16,500 yen (incl.)Cheapest published tier. Accepts sole-proprietor applications
Sectigo Japan (formerly Comodo Japan)EV65,000 yen71,500 yen16,500 yen (incl.)Cheapest tier even for EV. Flexible for sole proprietors
GMO GlobalSignOV60,000 yen66,000 yen16,500 yen (incl.)Domestic CA. Ships the token in-country
GMO GlobalSignEV78,000 yen85,800 yen16,500 yen (incl.)Fits WHDC driver signing
Slogical (DigiCert reseller)OV89,000 yen97,900 yen18,700 yen (incl.)Carries DigiCert in Japan. Supports deferred payment
Slogical (DigiCert reseller)EV138,000 yen151,800 yen18,700 yen (incl.)DigiCert EV with deferred payment
RMS (DigiCert authorized reseller)OV115,200 yen126,720 yen24,090 yen (incl.)Equivalent to DigiCert direct. HSM integration support
RMS (DigiCert authorized reseller)EV171,300 yen188,430 yen24,090 yen (incl.)Enterprise customization
DigiCert Japan (direct)OV115,200 yen126,720 yenQuoteGlobal market leader, industry standard
DigiCert Japan (direct)EV171,300 yen188,430 yenQuoteConsistent behavior across all platforms

Lining up the major SKUs obtainable in yen, the gap between the cheapest tier (Sectigo Japan) and the high end (DigiCert direct/RMS) is two to three times. Any of them is obtainable by a Japanese company; the one with the widest door, down to sole proprietors, is Sectigo Japan.

xychart-beta
    title "Annual price comparison (JPY, tax-excluded)"
    x-axis ["Sectigo OV", "Sectigo EV", "GMO OV", "GMO EV", "DigiCert OV", "DigiCert EV"]
    y-axis "JPY" 0 --> 180000
    bar [55000, 65000, 60000, 78000, 115200, 171300]

For context, JPRS (known for selling SSL/TLS certificates) does not offer code signing certificates, and Cybertrust has discontinued some of its brands. Where to obtain Windows Authenticode code signing effectively converges on the three lineages above (Sectigo, GMO GlobalSign, DigiCert).

Options bought directly in USD

These are bought directly in USD from CAs that publish no JPY price. Apply the exchange rate (roughly 150 to 160 yen per dollar) and the apparent cheapness shrinks.

VendorTypePublished priceEase of obtaining / notes
DigiCert (official)OV$696/yr (own token/HSM), $840/yr (USB token)KeyLocker variant adds about $300
DigiCert (official)EV$972/yr (own token/HSM), $1,116/yr (USB token)KeyLocker variant adds about $300
GlobalSign (US)OV$434/yr1 year only. Tokens not shipped outside the ordered region
GlobalSign (US)EV$550/yr1 year only
Sectigo (official)OV/EVFrom about $536/yr on a 5-year purchaseFree FIPS-compliant token shipped annually
SSL.com (official)OV/EVOV $129/yr, EV $349/yr (much less on 5-year)Issues IV (for individuals). Token-free via eSigner

In USD, SSL.com looks cheap, but on top of the headline price the YubiKey cost (+$379), eSigner charges, and Cloud HSM attestation fee ($500–1,500) are separate line items, and token shipping guidance is US-centric. Keep the headline price and the total cost to obtain separate. On the other hand, SSL.com is one of the few options where even an individual with no registered business can obtain IV (Individual Validation) code signing, and signing through the fully cloud eSigner sidesteps the token-shipping problem. For an individual developer who can tolerate USD payment and an English-language process, it is a realistic path to obtaining a certificate.

Cloud signing service pricing and eligibility

If you want to sign automatically on every CI/CD build, physically inserting a token is impractical, so a cloud HSM signing service becomes the option. Its pricing is separate from the certificate, so treat it on its own, with availability to Japanese organizations noted alongside.

ServicePriceAvailable to Japanese organizationsForm
Azure Trusted Signing (Artifact Signing)Basic $9.99/mo (5,000 signings), Premium $99.99/mo (100,000 signings), $0.005/signing overNo (Japan excluded)Fully managed, FIPS 140-2 Level 3 HSM, short-lived 72-hour certificates renewed daily
SSL.com eSigner (IV/OV/EV)Tier 1 $15/mo (240 signings) to Tier 4 $187.50/mo (12,000 signings); ~25% off annuallyYes (individuals via IV)Cloud HSM, automated via CodeSignTool
DigiCert KeyLockerService fee at certificate purchase (1,000 signings per certificate)Yes (via CertCentral)Cloud HSM (FIPS 140-2 Level 3), CI/CD integration
DigiCert Software Trust ManagerQuote (enterprise)YesPolicy control, audit logs, SBOM, RBAC

To repeat, the cheapest option, Azure Trusted Signing, excludes Japan. If you want to keep automated signing fully in the cloud from Japan, the realistic answers today are SSL.com eSigner or DigiCert KeyLocker. Neither needs a physically inserted token, so they also dissolve the shipping/customs geographic risk.

Which is cheaper, a physical token or cloud HSM

The certificate fee itself is roughly the same either way, so the difference is in operating cost. A physical token requires human effort on every signing (finding the token, inserting it, entering the PIN, updating the SafeNet client). A cloud HSM costs a monthly base fee and an initial setup cost, but in exchange the per-signing human effort is essentially zero.

Let N be the number of signings per year, h the manual time per signing, w the team’s hourly cost, F the cloud HSM annual base fee, and I the initial setup cost. The break-even where the two are equal can be written as:

Physical token / yr = token cost + N × h × w
Cloud HSM / yr      = F + I + N × t   (t ≈ 0)
 
Break-even N* ≈ (F + I − token cost) / (h × w)

Plug in 2026 market values: token cost 18,700 yen, manual time h = 0.25 hour (15 min), hourly cost w = 4,000 yen, cloud annual base fee F = about 9,000 yen (Azure Key Vault HSM key), initial setup I = about 40,000 yen (CI/CD configuration and signing verification, 10 hours):

N* ≈ (9,000 + 40,000 − 18,700) / (0.25 × 4,000)
   = 30,300 / 1,000
   ≈ 31 signings/year

So if your organization builds and signs more than 31 times a year, cloud HSM signing wins on total cost. As a rule of thumb, if you release more than about three times a month, leaning into automation is cheaper. Conversely, if you sign infrequently and hand-signing suffices, a physical token is simpler and cheaper (you never recoup the first-year setup cost).

flowchart TD
    A["Estimate signings per year"] --> B{"More than 31 per year?"}
    B -->|Yes| C["Cloud HSM signing"]
    B -->|No| D["Physical token"]
    C --> C1["SSL.com eSigner / DigiCert KeyLocker"]
    C --> C2["Auto-sign in CI/CD, avoid shipping & customs"]
    D --> D1["Domestic reseller ships the token in-country"]
    D --> D2["Hand-sign with SignTool"]

Recommendations by applicant

Pulling it together by who is obtaining the certificate.

ApplicantRecommendationWhy
Japanese company (ordinary user-mode app)Choose OV on price; cheapest tier is Sectigo JapanEasy to obtain with a wide price gap. OV is enough without driver signing
Japan-resident sole proprietorSectigo Japan OVHas a sole-proprietor application path. Pre-register a DUNS number to shorten vetting
Individual developer with no businessSSL.com IV, or register a business / Microsoft StoreMajor CAs generally do not issue to individuals. IV, or certificate-free Store distribution, is realistic
Signing kernel-mode driversEV (DigiCert or GMO GlobalSign)EV is mandatory. Supports WHDC portal registration

A criterion that flips the decision: if Microsoft adds Japan to the Azure Trusted Signing regions, both companies and individuals could use it at $9.99/month and the eligibility problem dissolves at once, promoting it to the top choice. And remember that with EV’s instant SmartScreen trust gone, OV is enough unless you need driver signing, so there is little reason to pay the EV premium.

Caveats

Both eligibility and price move, so reconfirming on each vendor’s official page before ordering is mandatory.

  • A CA’s policy toward sole proprietors and individuals can change. Confirm eligibility for an individual with no business directly with each CA before applying
  • Overseas reseller prices (SignMyCode, SSL2BUY, and the like) swing with exchange rates and promotions. The USD prices here are 2025–2026 reference values
  • The official direct USD prices for DigiCert, Sectigo, and GlobalSign mix quote-based and estimated figures. RMS’s JPY prices are reference list prices; the actual price is by separate quote
  • This research could not confirm any domestic reseller offering SSL.com certificates in yen. If you obtain one, buying directly from SSL.com (in USD) is the realistic path
  • A weak yen shrinks the apparent USD discount. SSL.com EV at $349 is roughly 52,000 to 56,000 yen (at 150–160 yen per dollar), not far from the cheapest JPY tier, Sectigo Japan EV at 65,000 yen
  • Token and shipping costs are generally one-time (reusable on renewal), but overseas shipping and customs can add a lead time of days to weeks

Conclusion

A code signing certificate starts with confirming you can obtain one, before comparing price. Three takeaways for 2026: a Japanese company can obtain one from almost any CA and choose on price and operations (cheapest tier: Sectigo Japan). An individual with no business is generally not issued one by major CAs, so route around it with SSL.com IV, registering as a sole proprietor, or certificate-free Microsoft Store distribution. And Microsoft’s own cheap Azure Trusted Signing excludes Japan geographically, so traditional CAs are the realistic answer for now.

Channel selection and the SignTool signing procedure are covered in the earlier post. Pair them with this eligibility and price comparison to judge, along the shortest path, who obtains which certificate and how.

References