Summary
- Microsoft is preparing Windows for next-generation code signing to strengthen software supply chain security and improve trust in signed software.
- Organizations that develop, sign, or distribute software and drivers should review their code-signing certificates, tooling, and signing workflows for future compatibility.
- Existing signing approaches may need updates to align with stronger cryptographic requirements, including newer certificate and hash standards.
- IT and security teams responsible for code-signing infrastructure should assess readiness and plan any needed certificate or process changes.
Microsoft is preparing the Windows ecosystem for next-generation code signing to strengthen software supply chain security and improve trust in signed software. As cryptographic standards evolve, Microsoft is introducing newer signing technologies and guidance to help ensure the continued security and compatibility of Windows applications and drivers.
Microsoft 365 Message Center ID: MC1458947
Primary Service: Windows
Admin Impact: Medium
User Impact: Low
Release Start: 19 Oct 2026
Release End: 19 Oct 2026
Last Modified: August 22, 2026
Category: Message Center
Tags: New feature, Admin impact
Status: Launched
Products & Platforms: Windows
History
8/21/2026 Item Added to Message Center
Rollout schedule
- Microsoft guidance is already available.
- October 19, 2026: Microsoft Windows Production PCA 2011 expires.
- End of 2026: Windows is moving toward stronger signing configurations, including RSA-3072 and SHA-384.
- 2027: Windows signing will transition to post-quantum signing.
Impact on your organization
Who is affected
- Software developers and publishers
- Organizations that develop and distribute internal applications
- IT and security administrators responsible for code-signing infrastructure
What will happen
- Future Windows code-signing requirements will adopt stronger cryptographic protections.
- Organizations using existing code-signing certificates or signing workflows should review their environments and assess readiness.
- Software publishers might need to update certificates, tooling, or signing processes to remain aligned with future requirements.
Action required/recommendations
Review your code-signing certificates, tooling, and signing workflows to understand any potential impact from future code-signing changes. Learn more at Preparing the Windows ecosystem for next-generation code signing.
Compliance considerations
Stronger signing supports evolving security and compliance requirements. Review as appropriate for your organization.