The original Developer ID Certification Authority (Sub-CA) expires on February 1, 2027. Every certificate it issued stops working that day — and any Mac app still signed with one risks failing verification on users' machines.
What happened
Apple announced that the original Developer ID Certification Authority (Sub-CA) — the intermediate authority behind existing Developer ID certificates — expires on February 1, 2027. Developer ID is what lets Mac software distributed outside the App Store pass Gatekeeper as coming from an identified developer. When the Sub-CA expires, the certificates chained to it stop being valid, so affected installers and app bundles can no longer prove their origin. This is a hard calendar deadline, not a phased rollout: the cutoff applies to everything signed under the old chain.
Who's affected
Any team distributing Mac software outside the App Store — direct downloads, enterprise distribution, notarized utilities — whose signing certificates were issued under the expiring Sub-CA. If your release pipeline has not rotated certificates recently, assume you are in scope until you check.
KappS's take
- Inventory now, not in January 2027. List every shipping binary and installer and confirm which Sub-CA issued its Developer ID certificate.
- Schedule the re-sign and re-notarize cycle ahead of the deadline — it touches builds, installers, auto-update feeds and anything pinning certificate hashes.
- Treat the deadline as release planning, not an ops fire drill. Teams that rotate early avoid the January rush, when everyone discovers the problem at once.
- If users must update, announce it. A quiet rotation that breaks auto-update is worse than a communicated one.