Apple's Developer ID certificate authority expires in 2027
The Sub-CA that signs Developer ID certificates for software distributed outside the Mac App Store expires on 1 February 2027, and Apple is telling developers to replace affected certificates and re-sign their installer packages.

Apple has warned that the original Developer ID certification authority - the Sub-CA that signs certificates for Mac software distributed outside the App Store - expires on 1 February 2027, and that certificates issued by it will stop working on that date.
How to check whether you are affected
Developers can check in Certificates, Identifiers and Profiles for certificates that expire on or before 1 February 2027. Apple points to its support page on replacing Developer ID certificates issued from the previous Sub-CA for help identifying a certificate's authority.
Creating a replacement
A replacement is generated from the current authority, Developer ID Certification Authority (G2), which is valid until 2031. The authority outlasts the certificates it signs, though: those expire annually and must be renewed each year. Anyone still using Xcode 11.4 or earlier needs to update before creating a new certificate, and must select the G2 Sub-CA as the Developer ID Certificate Intermediary. Choosing another option can issue a certificate that also expires in 2027.
What stops working, and when
Installer packages are the sharp edge. From 1 February 2027, .pkg files signed with an affected certificate will no longer install, so every package must be re-signed with the new certificate before that date. Mac apps are gentler: software already signed and notarised with a secure timestamp keeps working, with no action required. Future updates simply need to be signed with the new certificate and to carry a secure timestamp for notarisation.
Our opinion
A certificate expiry is the least glamorous kind of deadline and, for a developer, the most expensive one to miss: nothing breaks during the long run-up, and then an installer that worked yesterday refuses to open. Apple's notice is unusually clear about the asymmetry - apps coast on existing notarisation, packages do not - and that is the part worth reading twice, because the teams most likely to be caught out are the ones distributing .pkg builds and the least likely to have it on a calendar. The annual renewal rule for G2 certificates sharpens the point further: this is not a one-off migration but a recurring appointment. Put the reminder in January.