Best Code Signing Software in 2026

In short: SignPath is ranked #1 of 25 as of 3 October 2026, ahead of SignServer and DigiCert Software Trust Manager. The best-ranked option with a free plan is SignServer. The lowest first paid tier on this page is Bamboo Deploy at $15/mo.

25 code signing software ranked on what their makers publish — plans and prices, free tiers, platforms and the facts on their own pages.

25ranked
4free plans on this page
$15/molowest paid tier
3 Oct 2026last checked
#PlatformScoreWhyFromFree planPaid fromSupported targets
1SignPath8.9
RecognisedAPIDocumented
FreeYes—Windows PE files, PowerShell, MSI, CAB, catalog, APPX, MSIX, NuGet, Java archives, containers, Linux packages, macOS code, and custom artifactsView
2SignServer8.7
RecognisedAPIDocumented
FreeYes—Windows PE executables, MSI, CAB, APPX/MSIX, PowerShell scripts, Java archives, Android APKs, Debian packages, Git commits, OpenPGP data, CMS/raw data, firmware, containers, documents, and ePassportsView
3DigiCert Software Trust Manager8.5
RecognisedAPIDocumented
———Windows binaries and packages; Java archives; Android APK/AAB; macOS APP/DMG/PKG; Linux binaries; NuGet packages; containers; firmware and other artifactsView
4Sigstore8.3
RecognisedAPIDocumented
FreeYes——View
5Bamboo Deploy7.6
RecognisedAPIDocumented
$15/moYes—EXE, MSI, DLLView
6LAAVAT PKI and Signing Platform7.3
RecognisedAPIDocumented
—No—NXP HAB/AHAB, AMD/Xilinx Bootgen, TI, MCUboot, FIT, RAUC, SWUpdate, Mender, OP-TEE, OCI/Cosign, Windows, Java, JWT, detached signaturesView
7Cosign7.0
RecognisedAPIDocumented
FreeYes—OCI container images, blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and In-Toto attestationsView
8SignPath Foundation6.8
RecognisedAPIDocumented
—Yes—Windows executables and scripts, MSI, CAB, AppX/MSIX, NuGet, Java archives, Android packages, RPM, Debian packages, Office macros, XML, JSON, OCI container images, ClickOnce, and arbitrary filesView
9Keyfactor Platform6.6
RecognisedAPIDocumented
————View
10Red Hat Trusted Artifact Signer6.5
RecognisedAPIDocumented
———container images, binaries, documents, source-code commits, software bills of materials, build artifacts, AI/ML modelsView
11Aujas Automated Code Signing Platform6.4
RecognisedAPIDocumented
———Windows files; Java JAR/WAR/EAR/HPI; Android APK; RPM; Linux files; Docker images; iOS/macOS DMG, IPA, PKG, APP; XAR; MAGE manifests; WHQL/HLK drivers; VSIX; DLL, EXE, JS, SYS, MSI, VBS, MSP, OCX, PS1, WSF, CAB; Debian packages; Helm chartsView
12GaraTrust6.4
RecognisedAPIDocumented
———Windows Authenticode, Kernel/WHQL, MSI/MSIX, NuGet, PowerShell, ClickOnce, macOS, iOS, Android APK/AAB, Java JAR, Docker, Notary v2, Linux RPM, DEB, GPG, firmware/UEFI, PDF, XML/XAdES, SBOMView
13ComSignTrust Secure Code Signing Platform (ASCS)6.0
RecognisedAPIDocumented
———CAB, COS, EXE, DLL and other Microsoft Authenticode filesView
14The Update Framework6.0
RecognisedAPIDocumented
—Yes—Software updates, repository target files, packages, and digital artifactsView
15sslTrus Remote Code Signing Service5.9
RecognisedAPIDocumented
—No75 /yrAdobe AIR applications, Firefox XPI extensions, macOS applications, Java JAR files, Microsoft Authenticode formats (.exe, .dll, .ocx, .msi, .cab and kernel drivers), Microsoft Office macro/VBA files, and Silverlight XAP filesView
16CyberArk Code Sign Manager - Self-Hosted5.7
RecognisedAPIDocumented
———Code-signing keys and artifacts handled by integrated signing applications; specific target formats not confirmedView
17CodeLocker5.7
RecognisedAPIDocumented
———source-code commits; source code; files; binaries; scripts; SBOMs; software artifactsView
18Notation5.6
RecognisedAPIDocumented
———OCI container images and other OCI artifacts, including SBOMsView
19Code Signing Key Management Server (CSKMS)5.3
RecognisedAPIDocumented
———firmware, software applications, software images, block images, hash fingerprintsView
20Signotaur5.2
RecognisedAPIDocumented
—No—Windows executables and installers, PowerShell scripts, AppX/MSIX, NuGet packages, VSIX packages, ClickOnce/VSTO manifests, RDP files, Apple configuration and provisioning profiles, CMS/PKCS#7 files, archives, PDF and XML documentsView
21GoGetSSL Cloud Code Signing5.1
RecognisedAPIDocumented
—No425 /yrAdobe AIR applications; Mozilla object files; Apple Mac software; Java JAR applets; Microsoft Authenticode files including DLL, OCX, EXE, MSI, CAB and kernel software; Microsoft Office VBA files; Microsoft Silverlight applicationsView
22OpenPubkey5.1
RecognisedAPIDocumented
—Yes—messages and artifactsView
23AWS Signer5.0
RecognisedAPIDocumented
———AWS Lambda deployment packages; IoT and FreeRTOS firmware images; OCI container imagesView
24PACE Code Signing Platform5.0
RecognisedAPIDocumented
———Windows, macOS, Linux, IoT binaries, AAX plug-insView
25Signo4.8
RecognisedAPIDocumented
———Files; Windows executables via AuthenticodeView

Is your platform on this list?

Numbered spots on this list can be sponsored. They are labelled, and the editorial order and scores never change for payment.

Questions about this list

Which code signing software is ranked first on Inferse?

SignPath is ranked #1 of 25 with a score of 8.9. SignServer is second and DigiCert Software Trust Manager third.

How many of these have a free plan?

4 of the 25 on this page publish a free plan on their own pricing pages.

Which is the cheapest paid option?

On this page, Bamboo Deploy has the lowest first paid tier we found: $15/mo.

How is this list ranked?

Ranked on what each maker publishes, open and connectable first: a public API, open-source code, the depth of its documentation and a free tier to try it on. Model lists are sorted by the figure in their title, exactly as each provider publishes it. Paid placements never change a rank.

More in Developer Tools

All developer tools lists