For developers · Checked 6 October 2026

Developer ID Sub-CA expiration: what breaks on February 1, 2027 and how to replace your certificate

Short answer: the original Developer ID Certification Authority (Sub-CA) expires on February 1, 2027, and certificates it issued stop working that day. Create a replacement from the Developer ID Certification Authority (G2), re-sign your installer packages before the date, and sign future app updates with the new certificate. Mac apps you already signed and notarized with a secure timestamp keep working.

What happens on February 1, 2027

From Apple Developer News (October 1, 2026) and Apple Developer Help, read 6 October 2026.

What you shipSigned with a certificate from the old Sub-CAWhat to do
Installer package (.pkg)No longer installs from February 1, 2027Re-sign every package with a G2 certificate before the date
Mac app, already signed and notarized with a secure timestampKeeps workingNo action for copies already out there
Future app updatesThe old certificate can no longer signSign with the G2 certificate and include a secure timestamp

Check whether your certificates are affected

In Certificates, Identifiers & Profiles, open Certificates and review your Developer ID Application and Developer ID Installer certificates. Any that expire on or before February 1, 2027 are likely affected, but the date alone does not prove the issuer, and a team can hold two certificates with identical names. To be sure, select your certificate in Keychain Access, expand Issuer Name and read the Organizational Unit: «Apple Certification Authority» means the old Sub-CA, replace it; «G2» means the current Sub-CA, nothing to do. Check your own certificate, not the Developer ID Certification Authority entry itself, which also shows «Apple Certification Authority» because Apple Root CA issued it.

Create a G2 replacement

The Account Holder creates it. In Certificates, click the add button, choose Developer ID Application or Developer ID Installer under Software, and repeat for the other type if you use both, since one does not cover the other. When asked for a Developer ID Certificate Intermediary, pick G2 Sub-CA (Xcode 11.4.1 or later); any other option may issue a certificate that also expires in 2027. If you still use Xcode 11.4 or earlier, update first. Upload a certificate signing request, download the certificate and double-click it to install it in your keychain. You can hold up to five certificates of each type, so you can create and test the replacement while the old one still works.

G2 certificates last one year

The G2 authority itself is valid until 2031, but the certificates it issues expire annually and must be renewed each year. Put the renewal in your release calendar and in your CI secrets rotation, so a build server does not start failing on the anniversary.

Re-sign and update your pipeline

Re-sign every installer package you distribute, including ones on your website or in an update feed, before February 1, 2027. Then point your build scripts, CI and notarization step at the new identity, and keep the secure timestamp when you sign, because notarization needs it. For other Mac platform changes this cycle, see the Rosetta 2 end of support guide.

Where Censuus fits

Keeping your Mac app installable keeps the people you already won; being found brings new ones. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

When does the Developer ID Sub-CA expire?

The original Developer ID Certification Authority expires on February 1, 2027. Certificates issued from it stop working on that date.

Do I need to re-sign apps I already shipped?

Not if they were signed and notarized with a secure timestamp: Apple says previously signed and notarized Mac software keeps working. Installer packages (.pkg) are different, they no longer install from February 1, 2027 and must be re-signed.

How do I know which authority issued my certificate?

In Keychain Access, select your certificate, expand Issuer Name and read Organizational Unit. «Apple Certification Authority» is the old Sub-CA; «G2» is the current one.

How long is a G2 Developer ID certificate valid?

One year. The G2 authority is valid until 2031, but its certificates expire annually and must be renewed each year.

Who can create a Developer ID certificate?

The Account Holder of the developer team. You can hold up to five Developer ID Application and five Developer ID Installer certificates at a time.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.