Preparing the Windows ecosystem for next-generation code signing
🚨 The Signal: Microsoft is updating Windows code signing to use stronger cryptography (RSA-3072, SHA-384, post-quantum) by 2027. This enhances software supply chain security and requires organisations to update their code-signing certificates and processes.
The Impact
Software developers, publishers, and IT/security administrators are affected, facing a risk of unsigned or untrusted applications if code-signing processes are not updated.
- Software developers: Risk of applications failing Windows integrity checks.
- Software publishers: Risk of distribution issues due to untrusted binaries.
- IT administrators: Risk of internal applications being blocked or flagged.
- Security administrators: Risk of supply chain vulnerabilities if signing is not updated.
The Action
- Identify all internal applications and drivers that are currently code-signed for Windows.
- Review existing code-signing certificates for cryptographic strength and expiration dates (e.g., Microsoft Windows Production PCA 2011 expires Oct 2026).
- Assess current code-signing tooling and workflows for compatibility with RSA-3072 and SHA-384.
- Plan for certificate renewal or acquisition with stronger cryptographic parameters.
- Update code-signing processes and tools to align with future Windows requirements by late 2026.
Domain: Other · Impact: high · Workload: Other · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871