Developer ID: renew Mac certificates before February 2027
Apple warns that the original Developer ID intermediate certification authority expires on February 1, 2027. For organizations distributing Mac apps or installers outside the Mac App Store, this is a continuity project: affected signed .pkg files will no longer install after the deadline.
1. What Apple announced
Certificates issued by the original Sub-CA will stop working on February 1, 2027. Apple instructs teams to find certificates expiring on or before that date in Certificates, Identifiers & Profiles, then create a replacement from the Developer ID Certification Authority (G2).
The G2 authority is valid until 2031, but certificates it issues still expire annually. Xcode 11.4 or earlier must be updated before creating the replacement. When selecting a Developer ID certificate intermediary, teams must choose G2 Sub-CA; another option may produce a certificate that also expires in 2027.
2. Mac packages and apps require different treatment
Apple draws a clear distinction between artifacts. From the deadline, a .pkg signed with an affected certificate will no longer install. Every such package that remains in distribution must be re-signed with the new certificate.
A previously signed and notarized Mac app with a secure timestamp will keep working and does not need to be re-signed solely because of this deadline. Future updates should use the new certificate and retain a secure timestamp for notarization.
3. Where the enterprise fleet risk sits
The certificate is often one link in a longer chain: CI/CD build, signing, notarization, package repository, Jamf or another MDM, Self Service, and recovery procedures. An infrequently used legacy installer — for a security agent, driver, VPN client, or recovery tool — may remain available long after a certificate is renewed.
Changing the certificate for the next build therefore leaves residual risk. The inventory must include active packages, pinned versions, recovery copies, automation recipes, and signing identities stored in secrets vaults.
4. What changes for a Belgian or French organization?
The deadline is global: a Belgian small business distributing one internal utility is affected just like a French mid-market company or a European group. The impact is operational. One essential package that can no longer install may block onboarding, Mac compliance remediation, or device recovery.
IT leaders should assign an owner to each binary and require test evidence before February. Security teams need to protect and audit the new private key. Procurement and application owners should obtain a re-signed release when an external vendor or integrator supplies the packages.
5. Underside analysis: treat the certificate as a production dependency
Our view is that this change is less a developer formality than Mac lifecycle management. Apple Business Manager and Automated Device Enrollment enroll the device; Jamf or another MDM orchestrates installation; neither can repair an installer whose signing chain has expired.
The control belongs in the governance of macOS packages managed through MDM and the qualification of Apple business applications. The meaningful indicator is not “certificate renewed,” but “every artifact still available for deployment has been identified, re-signed where required, and tested through its real delivery channel.”
6. Action plan before February 1, 2027
- Inventory Developer ID certificates, their Sub-CA, expiry date, owner, and uses.
- Create replacements through G2 Sub-CA with a current Xcode version, then secure private keys and access rights.
- Find every
.pkgstill available through MDM, Self Service, repositories, and recovery procedures. - Re-sign affected packages, verify signing and notarization, then test them on a pilot Mac through the production channel.
- Confirm retained apps have notarization and a secure timestamp; use the new certificate for future releases.
- Document annual renewal and retire old certificates, keys, and artifacts under a controlled procedure.
Objective: ensure no critical Mac installation still depends on the original Sub-CA when it expires.
Audit your Mac deployment chainOfficial source: Apple Developer — Upcoming expiration of Developer ID Certification Authority (Sub-CA).