Preparing the Windows ecosystem for next-generation code signing

🚨 The Signal: Microsoft is updating Windows code signing to use stronger cryptography (RSA-3072, SHA-384, post-quantum) by 2027. This enhances software supply chain security and requires organisations to update their code-signing certificates and processes.

The Impact

Software developers, publishers, and IT/security administrators are affected, facing a risk of unsigned or untrusted applications if code-signing processes are not updated.

  • Software developers: Risk of applications failing Windows integrity checks.
  • Software publishers: Risk of distribution issues due to untrusted binaries.
  • IT administrators: Risk of internal applications being blocked or flagged.
  • Security administrators: Risk of supply chain vulnerabilities if signing is not updated.

The Action

  1. Identify all internal applications and drivers that are currently code-signed for Windows.
  2. Review existing code-signing certificates for cryptographic strength and expiration dates (e.g., Microsoft Windows Production PCA 2011 expires Oct 2026).
  3. Assess current code-signing tooling and workflows for compatibility with RSA-3072 and SHA-384.
  4. Plan for certificate renewal or acquisition with stronger cryptographic parameters.
  5. Update code-signing processes and tools to align with future Windows requirements by late 2026.

Domain: Other · Impact: high · Workload: Other · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871