Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Code signing

Also known as: Software signing, Digital code signature

German: Codesignierung

In software security, code signing is the use of a digital signature, created with a private key, to let recipients verify that software, firmware or an update comes from the stated publisher and has not been altered since it was signed.

  • OT security

In one sentence

Code signing adds a digital signature to software or firmware so recipients can verify its publisher and that it was not altered.

Example

A drive manufacturer signs each firmware file; the drive only installs an update whose signature it can verify with the manufacturer's public key.

How it applies

  • Engineering: Signing protects the integrity and origin of firmware, PLC runtime components, applications and installers. IEC 62443-4-2 includes requirements for verifying software and information integrity, which signatures help meet.
  • Operation: Verification must actually happen: on the device during installation, at boot through Secure boot, or at least by the service technician before deployment.
  • Maintenance: The signing keys must be protected, for example in a hardware security module, and a plan must exist for key rotation and for revoking a compromised key.
  • Documentation: Release notes and update instructions should state that packages are signed, how the user can check the signature or hash, and what the device does when verification fails. Downloadable manuals and PDFs can be signed too.

Code signing vs. checksum

A checksum or hash shows whether a file changed, but anyone can compute a new one. A signature also proves who produced the file, because only the holder of the private key can create it.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on software security practice and IEC 62443-4-2

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!