A notarized app is software that has been checked by Apple before release and issued a certificate indicating it was scanned for malware. The certificate is used by macOS to verify the app has passed a screening step, which strengthens user trust and reduces the risk of distributing obviously malicious software.
What Notarized App Means for macOS Distribution
Notarization is a release-time screening step in Apple’s software distribution flow, not a promise that code is perfectly safe. It signals that Apple checked the app before distribution and issued a certificate that macOS can use when evaluating whether to allow the app to run.
For developers, notarization is part of the trust chain that helps software move through Gatekeeper and related macOS protections. For users, it reduces exposure to obviously malicious software while still leaving room for malicious or risky behavior that a scan may not catch.
How Notarization Differs from Signing and App Store Review
Notarization is often confused with code signing, but the two serve different purposes. Code signing ties the app to a developer identity, while notarization indicates that Apple’s automated checks have accepted the submitted build for distribution on macOS.
It is also different from App Store review. A notarized app can be distributed outside the App Store, which makes notarization especially important for software delivered directly from a vendor site or other channels outside Apple’s marketplace.
What macOS Uses the Notarization Result For
On macOS, notarization supports the operating system’s decision-making when an app is launched. The notarization certificate helps the platform verify that the app passed Apple’s screening step, which adds a layer of trust to the local execution path.
This matters most at the point of user execution and installation. A notarized app is still subject to other safeguards, including system security settings, endpoint controls, and user judgment about the publisher and download source.
Why Notarized Apps Still Need Security Review
Notarization improves baseline trust, but it does not eliminate software risk. A build may be notarized and still contain insecure functionality, unwanted behaviors, vulnerable dependencies, or logic that creates operational or privacy concerns after installation.
Security teams should treat notarization as one signal among several, alongside publisher reputation, package provenance, update behavior, and the app’s requested permissions. It is a distribution control, not a substitute for software assurance.
Risk and Threat Considerations
Notarization reduces the likelihood of users being handed obviously malicious software, but it can also create a false sense of safety if teams treat it as a guarantee rather than a screening outcome. A signed and notarized app can still be abused if the publisher is compromised or if a malicious build passes automated checks.
Failure mechanism: An attacker or compromised developer pipeline can distribute a harmful build that still satisfies the notarization process, especially when the malicious behavior is subtle, delayed, or hidden from static screening.
Impact: Users may trust and install software that later enables data theft, persistence, unwanted access, or broader compromise, despite having passed Apple’s release gate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-2 — Flaw Remediation | Notarized apps still require vulnerability management after screening. |
| SI-3 — Malicious Code Protection | Notarization is a malware-screening signal that complements anti-malware controls. | |
| CM-8 — System Component Inventory | Trusted software decisions depend on knowing which apps are installed and approved. | |
| Recommendation — Track notarized app versions and remediate vulnerable releases promptly. Scan downloaded macOS apps with malicious-code protection before allowing execution. Maintain an inventory of notarized apps and approved publishers. | ||
| CIS Controls v8 | CIS-2 — Inventory and Control of Software Assets | Notarized apps still need software asset inventory and approval tracking. |
| CIS-10 — Malware Defenses | Notarization supports but does not replace malware defense controls. | |
| CIS-16 — Application Software Security | Trusted distribution depends on application assurance and secure release handling. | |
| Recommendation — Inventory macOS software and flag unapproved apps even when notarized. Use layered malware defenses to inspect and block harmful macOS software. Verify application provenance and release integrity before deployment. | ||
Practitioner Guidance
What to watch for: Use notarization as a trust signal, not a full assurance standard. The practical question is whether the app comes from the expected publisher, behaves consistently with its stated purpose, and is maintained through a credible release process.
Practitioner takeaway: For enterprise macOS environments, notarization should inform allowlisting and review decisions, but it should not replace provenance checks, software inventory, or post-install monitoring.
Related resources from NHI Mgmt Group
- Why can a single SaaS app create such a large blast radius?
- What is the difference between a service account and an OAuth-connected app?
- What is the difference between a disabled app and a deleted app in Microsoft 365?
- What is the difference between app visibility and identity visibility in SaaS security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org