{"id":189,"date":"2026-08-14T17:47:28","date_gmt":"2026-08-14T17:47:28","guid":{"rendered":"https:\/\/codesigncert.com\/blog\/?p=189"},"modified":"2026-08-14T18:18:02","modified_gmt":"2026-08-14T18:18:02","slug":"ev-code-signing-without-hardware-token","status":"publish","type":"post","link":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token","title":{"rendered":"EV Code Signing Without Hardware Token: Cloud HSM Compliance Explained"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 ez-toc-wrap-right counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#What_%E2%80%9CWithout_a_Hardware_Token%E2%80%9D_Actually_Means_for_EV_Code_Signing\" >What &#8220;Without a Hardware Token&#8221; Actually Means for EV Code Signing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Why_Hardware_Is_Required_%E2%80%94_The_CABrowser_Forum_Rule\" >Why Hardware Is Required \u2014 The CA\/Browser Forum Rule<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Cloud_HSM_as_the_Compliant_Alternative\" >Cloud HSM as the Compliant Alternative<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#EV_Code_Signing_Without_USB_Token_%E2%80%94_How_the_Workflow_Changes\" >EV Code Signing Without USB Token \u2014 How the Workflow Changes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Remote_Code_Signing_for_CICD_Pipelines\" >Remote Code Signing for CI\/CD Pipelines<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Choosing_a_Cloud-Based_Code_Signing_Certificate\" >Choosing a Cloud-Based Code Signing Certificate<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Cost_Considerations\" >Cost Considerations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n<p>If you&#8217;ve been asked to set up EV code signing and someone on your team said &#8220;no more USB tokens,&#8221; you&#8217;re probably wondering if that&#8217;s even allowed. It is. But the reasoning behind it gets misunderstood constantly, and getting it wrong can cost you a failed audit or a rejected driver submission.<\/p>\n<p>Here&#8217;s the short version: you can drop the physical token. You cannot drop the hardware requirement. Those are two different things, and the gap between them is where most of the confusion lives.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_%E2%80%9CWithout_a_Hardware_Token%E2%80%9D_Actually_Means_for_EV_Code_Signing\"><\/span>What &#8220;Without a Hardware Token&#8221; Actually Means for EV Code Signing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>An EV code signing certificate has never been about the plastic USB stick in your drawer. It&#8217;s about where the private key lives and how it&#8217;s protected. The <a href=\"https:\/\/cabforum.org\/working-groups\/code-signing\/requirements\/\">Certification Authority\/Browser Forum requires that key to sit inside hardware validated to FIPS 140-2 Level 2 or higher<\/a>, a physical token was simply the easiest way to deliver that in 2015.<\/p>\n<p>A cloud HSM (hardware security module) meets the same validation standard. The hardware still exists. It&#8217;s just sitting in a certificate provider&#8217;s data center instead of your desk drawer, and you reach it over an authenticated API call instead of a USB port.<\/p>\n<p>So when someone asks for &#8220;EV code signing without a hardware token,&#8221; what they actually want is EV code signing without a <em>physical<\/em> token they have to plug in, ship to remote employees, or lose track of during an audit. That&#8217;s achievable today. What isn&#8217;t achievable is EV signing where the key sits in software with no hardware backing at all, no provider offers that, because the CA\/Browser Forum won&#8217;t allow it to be issued.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Why_Hardware_Is_Required_%E2%80%94_The_CABrowser_Forum_Rule\"><\/span>Why Hardware Is Required \u2014 The CA\/Browser Forum Rule<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This requirement isn&#8217;t arbitrary. Before mid-2023, some <a href=\"https:\/\/codesigncert.com\/ev-code-signing-certificates\">EV code signing<\/a> and standard code signing keys were stored as software files on developer laptops. Attackers went after exactly those files, and a string of high-profile breaches followed, malware signed with stolen legitimate certificates, which is far more damaging than unsigned malware because it walks past SmartScreen and most endpoint defenses without a second look.<\/p>\n<p>The CA\/Browser Forum&#8217;s response, effective June 2023, mandated hardware-backed key storage for all code signing certificates, with EV held to the stricter FIPS 140-2 Level 2 standard. The private key must be generated inside the hardware boundary and must never leave it in an exportable form. That single rule closed off the easiest attack path against signed software supply chains.<\/p>\n<p>For teams that already ran a token, this changed nothing operationally. For teams trying to sign from a build server with no one physically present to insert a USB device, it created a real problem, one cloud HSM was built to solve.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Cloud_HSM_as_the_Compliant_Alternative\"><\/span>Cloud HSM as the Compliant Alternative<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A cloud HSM is a hardware security module owned and operated by your certificate provider, shared (in a logically isolated way) or dedicated across customers, and accessed through a signing API or a client tool that mimics local signing commands. Your key is generated inside that module and stays there for the life of the certificate.<\/p>\n<p>Practically, this shifts who&#8217;s responsible for the physical security piece. With a token, that&#8217;s you, safe storage, controlled access, physical inventory. With a cloud HSM, that responsibility moves to the provider, who&#8217;s already running audited, access-controlled infrastructure built for exactly this purpose. You keep the compliance outcome. You lose the physical custody burden.<\/p>\n<h3>FIPS 140-2 Compliant Code Signing in the Cloud<\/h3>\n<p>Not every cloud HSM is validated to the same level, and this is worth checking before you commit to a provider. FIPS 140-2 Level 2 is the CA\/Browser Forum floor for EV. Some providers run Level 3 modules, which add tamper-evidence and stricter access controls, useful if your own security review or a customer&#8217;s vendor questionnaire asks for it specifically.<\/p>\n<p>Ask your provider directly which level their cloud HSM is validated to, and ask for documentation you can hand to an auditor. A reputable provider will have this ready without hesitation. If they hedge on the question, that&#8217;s a signal worth paying attention to.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"EV_Code_Signing_Without_USB_Token_%E2%80%94_How_the_Workflow_Changes\"><\/span>EV Code Signing Without USB Token \u2014 How the Workflow Changes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The certificate issuance process itself barely changes. You still go through the same organization validation, legal entity checks, phone verification, sometimes a notarized document depending on your jurisdiction. EV validation exists to confirm who you are, and that part of the process is identical whether your key ends up on a token or in a cloud HSM.<\/p>\n<p>What changes is what happens after issuance. Instead of receiving a physical device in the mail, your provider walks you through a key attestation step, essentially proving your cloud HSM setup (whether provider-managed or your own) meets the required hardware standard before they&#8217;ll issue against it. Once that&#8217;s done, signing happens through a client application or API call rather than a local USB connection.<\/p>\n<p>One practical difference worth planning for: token-based signing works the moment the token is plugged in, anywhere. Cloud HSM signing requires network access to the signing service, so an air-gapped build environment needs a different plan entirely \u2014 that&#8217;s a real limitation, not a marketing footnote.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Remote_Code_Signing_for_CICD_Pipelines\"><\/span>Remote Code Signing for CI\/CD Pipelines<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is where cloud HSM earns its keep. A build server doesn&#8217;t have hands to insert a token, and passing a physical device between machines defeats the point of automation. Remote code signing solves this by letting your pipeline authenticate to the signing service directly and request a signature as part of the build job.<\/p>\n<p>In practice, this usually means a signing client wraps the existing Windows signing tool your pipeline already calls, so the build script barely changes, you&#8217;re mostly swapping a local certificate reference for an authenticated service call. GitHub Actions, Azure DevOps, Jenkins, and GitLab CI all support this pattern without much friction once the initial setup is done.<\/p>\n<h3>Headless and Linux Build Environments<\/h3>\n<p>Here&#8217;s where it gets more specific. If your build agents run Windows, the signing client typically integrates cleanly because it&#8217;s built to sit alongside the native Windows signing tool. If you&#8217;re signing from Linux runners, you&#8217;re usually working directly against the provider&#8217;s signing API rather than a wrapped client, which means more setup work upfront and less plug-and-play convenience.<\/p>\n<p>Ask specifically about Linux and headless support before you commit. Some providers handle it well. Others treat it as a secondary use case, and you&#8217;ll find that out the hard way mid-integration if you don&#8217;t ask first.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Choosing_a_Cloud-Based_Code_Signing_Certificate\"><\/span>Choosing a Cloud-Based Code Signing Certificate<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A few things separate a service that works from one that becomes a support ticket queue:<\/p>\n<ul>\n<li><strong>Validation level support<\/strong> \u2014 confirm EV specifically is supported through the cloud HSM path, not just OV. Some providers restrict EV to their higher-tier plans.<\/li>\n<li><strong>Attestation process clarity<\/strong> \u2014 a provider should be able to explain, in plain terms, how they verify your key meets FIPS requirements before issuance.<\/li>\n<li><strong>API and CI\/CD compatibility<\/strong> \u2014 check documented support for your specific pipeline tooling before you buy, not after.<\/li>\n<li><strong>Audit logging<\/strong> \u2014 every signing event should be logged with enough detail to satisfy an internal security review or customer audit request.<\/li>\n<li><strong>Support responsiveness<\/strong> \u2014 signing failures block releases. A provider&#8217;s response time on signing issues matters more than it does for most other support categories.<\/li>\n<\/ul>\n<p>Run a small test signing job before migrating your full pipeline over. It catches integration gaps early, when they&#8217;re cheap to fix.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Cost_Considerations\"><\/span>Cost Considerations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Pricing for <a href=\"https:\/\/codesigncert.com\/azure-code-signing-certificate\">cloud HSM\u2013backed EV code signing certificates<\/a> typically breaks into two pieces: the certificate itself, priced similarly to token-based EV, and a service or attestation fee tied to the cloud HSM setup. Some providers roll this into a flat annual price; others charge separately for the attestation step, particularly if you&#8217;re bringing your own HSM rather than using theirs.<\/p>\n<p>The trade-off worth calculating isn&#8217;t just certificate price against certificate price. Factor in what you&#8217;re currently spending on token logistics, shipping, replacement tokens for lost or damaged devices, and the staff time spent managing physical inventory across a distributed team. For teams signing frequently from CI\/CD, that operational cost often outweighs the difference in certificate pricing itself.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Is a hardware token mandatory for EV code signing certificates?<\/strong> No. Hardware-backed key storage is mandatory, a cloud HSM validated to FIPS 140-2 Level 2 or higher satisfies that requirement without a physical USB token.<\/p>\n<p><strong>What&#8217;s the difference between a hardware token and a cloud HSM for code signing?<\/strong> Both store your private key inside FIPS-validated hardware. A token puts that hardware in a physical device you control directly. A cloud HSM puts it in provider-managed infrastructure you access through an authenticated signing service.<\/p>\n<p><strong>Which certificate authorities offer EV code signing without shipping a physical token?<\/strong> Several major certificate providers now offer cloud HSM\u2013backed EV signing as an alternative to token delivery. Availability and setup process vary, so confirm EV support specifically, some providers limit cloud signing to OV certificates only.<\/p>\n<p><strong>Is cloud HSM code signing FIPS 140-2 compliant?<\/strong> Yes, when the provider&#8217;s HSM is validated to at least FIPS 140-2 Level 2, which meets the CA\/Browser Forum&#8217;s minimum requirement for EV private key storage. Ask for the specific validation level and documentation before signing up.<\/p>\n<hr \/>\n<p><em>This article reflects code signing practices and CA\/Browser Forum requirements as of publication. Requirements around key storage and validation continue to evolve, so confirm current rules with your certificate provider before making infrastructure decisions.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you&#8217;ve been asked to set up EV code signing and someone on your team said &#8220;no more USB tokens,&#8221; you&#8217;re probably wondering if that&#8217;s even&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47],"tags":[],"class_list":["post-189","post","type-post","status-publish","format-standard","hentry","category-ev-code-signing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>EV Code Signing Without Hardware Token: Cloud HSM Explained<\/title>\n<meta name=\"description\" content=\"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\/Browser Forum rules for compliant remote signing.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EV Code Signing Without Hardware Token: Cloud HSM Explained\" \/>\n<meta property=\"og:description\" content=\"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\/Browser Forum rules for compliant remote signing.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token\" \/>\n<meta property=\"og:site_name\" content=\"CodeSignCert\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/codesigncert\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-14T17:47:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-14T18:18:02+00:00\" \/>\n<meta name=\"author\" content=\"Jessica Foster\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@codesigncert\" \/>\n<meta name=\"twitter:site\" content=\"@codesigncert\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jessica Foster\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token\"},\"author\":{\"name\":\"Jessica Foster\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#\\\/schema\\\/person\\\/9af8cbd9dd564d4534f25cd63a48d02d\"},\"headline\":\"EV Code Signing Without Hardware Token: Cloud HSM Compliance Explained\",\"datePublished\":\"2026-08-14T17:47:28+00:00\",\"dateModified\":\"2026-08-14T18:18:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token\"},\"wordCount\":1604,\"articleSection\":[\"EV Code Signing\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token\",\"name\":\"EV Code Signing Without Hardware Token: Cloud HSM Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-08-14T17:47:28+00:00\",\"dateModified\":\"2026-08-14T18:18:02+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#\\\/schema\\\/person\\\/9af8cbd9dd564d4534f25cd63a48d02d\"},\"description\":\"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\\\/Browser Forum rules for compliant remote signing.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/ev-code-signing-without-hardware-token#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"EV Code Signing Without Hardware Token: Cloud HSM Compliance Explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\",\"name\":\"CodeSignCert\",\"description\":\"All in One Code Signing Certificate Store\",\"alternateName\":\"Code Sign Cert\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#\\\/schema\\\/person\\\/9af8cbd9dd564d4534f25cd63a48d02d\",\"name\":\"Jessica Foster\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g\",\"caption\":\"Jessica Foster\"},\"description\":\"Jessica Foster is a contributing writer for the CodeSignCert blog, covering code signing, software security, and certificate management topics. She has 10 years of experience helping developers and businesses secure their software through code signing and related PKI solutions.\",\"sameAs\":[\"https:\\\/\\\/codesigncert.com\"],\"url\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/author\\\/jessicafoster\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"EV Code Signing Without Hardware Token: Cloud HSM Explained","description":"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\/Browser Forum rules for compliant remote signing.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token","og_locale":"en_US","og_type":"article","og_title":"EV Code Signing Without Hardware Token: Cloud HSM Explained","og_description":"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\/Browser Forum rules for compliant remote signing.","og_url":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token","og_site_name":"CodeSignCert","article_publisher":"https:\/\/www.facebook.com\/codesigncert","article_published_time":"2026-08-14T17:47:28+00:00","article_modified_time":"2026-08-14T18:18:02+00:00","author":"Jessica Foster","twitter_card":"summary_large_image","twitter_creator":"@codesigncert","twitter_site":"@codesigncert","twitter_misc":{"Written by":"Jessica Foster","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token#article","isPartOf":{"@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token"},"author":{"name":"Jessica Foster","@id":"https:\/\/codesigncert.com\/blog\/#\/schema\/person\/9af8cbd9dd564d4534f25cd63a48d02d"},"headline":"EV Code Signing Without Hardware Token: Cloud HSM Compliance Explained","datePublished":"2026-08-14T17:47:28+00:00","dateModified":"2026-08-14T18:18:02+00:00","mainEntityOfPage":{"@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token"},"wordCount":1604,"articleSection":["EV Code Signing"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token","url":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token","name":"EV Code Signing Without Hardware Token: Cloud HSM Explained","isPartOf":{"@id":"https:\/\/codesigncert.com\/blog\/#website"},"datePublished":"2026-08-14T17:47:28+00:00","dateModified":"2026-08-14T18:18:02+00:00","author":{"@id":"https:\/\/codesigncert.com\/blog\/#\/schema\/person\/9af8cbd9dd564d4534f25cd63a48d02d"},"description":"Learn how EV code signing works without a USB token. See how cloud HSM meets FIPS 140-2 and CA\/Browser Forum rules for compliant remote signing.","breadcrumb":{"@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/codesigncert.com\/blog\/ev-code-signing-without-hardware-token#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/codesigncert.com\/blog\/"},{"@type":"ListItem","position":2,"name":"EV Code Signing Without Hardware Token: Cloud HSM Compliance Explained"}]},{"@type":"WebSite","@id":"https:\/\/codesigncert.com\/blog\/#website","url":"https:\/\/codesigncert.com\/blog\/","name":"CodeSignCert","description":"All in One Code Signing Certificate Store","alternateName":"Code Sign Cert","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/codesigncert.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/codesigncert.com\/blog\/#\/schema\/person\/9af8cbd9dd564d4534f25cd63a48d02d","name":"Jessica Foster","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/540326c0491587e08522922cbd7c078549e5cafa48300998cdd9613a30e2fec4?s=96&d=mm&r=g","caption":"Jessica Foster"},"description":"Jessica Foster is a contributing writer for the CodeSignCert blog, covering code signing, software security, and certificate management topics. She has 10 years of experience helping developers and businesses secure their software through code signing and related PKI solutions.","sameAs":["https:\/\/codesigncert.com"],"url":"https:\/\/codesigncert.com\/blog\/author\/jessicafoster"}]}},"_links":{"self":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/posts\/189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/comments?post=189"}],"version-history":[{"count":1,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/posts\/189\/revisions"}],"predecessor-version":[{"id":190,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/posts\/189\/revisions\/190"}],"wp:attachment":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/media?parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/categories?post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/tags?post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}