Join our Newsletter — 33% off our NHI Course
Home› Glossary› Foundations & NHI Taxonomy› Notarized App
Foundations & NHI Taxonomy

Notarized App

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Foundations & NHI Taxonomy

A notarized app is software that has been checked by Apple before release and issued a certificate indicating it was scanned for malware. The certificate is used by macOS to verify the app has passed a screening step, which strengthens user trust and reduces the risk of distributing obviously malicious software.

What Notarized App Means for macOS Distribution

Notarization is a release-time screening step in Apple’s software distribution flow, not a promise that code is perfectly safe. It signals that Apple checked the app before distribution and issued a certificate that macOS can use when evaluating whether to allow the app to run.

For developers, notarization is part of the trust chain that helps software move through Gatekeeper and related macOS protections. For users, it reduces exposure to obviously malicious software while still leaving room for malicious or risky behavior that a scan may not catch.

How Notarization Differs from Signing and App Store Review

Notarization is often confused with code signing, but the two serve different purposes. Code signing ties the app to a developer identity, while notarization indicates that Apple’s automated checks have accepted the submitted build for distribution on macOS.

It is also different from App Store review. A notarized app can be distributed outside the App Store, which makes notarization especially important for software delivered directly from a vendor site or other channels outside Apple’s marketplace.

What macOS Uses the Notarization Result For

On macOS, notarization supports the operating system’s decision-making when an app is launched. The notarization certificate helps the platform verify that the app passed Apple’s screening step, which adds a layer of trust to the local execution path.

This matters most at the point of user execution and installation. A notarized app is still subject to other safeguards, including system security settings, endpoint controls, and user judgment about the publisher and download source.

Why Notarized Apps Still Need Security Review

Notarization improves baseline trust, but it does not eliminate software risk. A build may be notarized and still contain insecure functionality, unwanted behaviors, vulnerable dependencies, or logic that creates operational or privacy concerns after installation.

Security teams should treat notarization as one signal among several, alongside publisher reputation, package provenance, update behavior, and the app’s requested permissions. It is a distribution control, not a substitute for software assurance.

Risk and Threat Considerations

Notarization reduces the likelihood of users being handed obviously malicious software, but it can also create a false sense of safety if teams treat it as a guarantee rather than a screening outcome. A signed and notarized app can still be abused if the publisher is compromised or if a malicious build passes automated checks.

Failure mechanism: An attacker or compromised developer pipeline can distribute a harmful build that still satisfies the notarization process, especially when the malicious behavior is subtle, delayed, or hidden from static screening.

Impact: Users may trust and install software that later enables data theft, persistence, unwanted access, or broader compromise, despite having passed Apple’s release gate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SI-2 — Flaw RemediationNotarized apps still require vulnerability management after screening.
SI-3 — Malicious Code ProtectionNotarization is a malware-screening signal that complements anti-malware controls.
CM-8 — System Component InventoryTrusted software decisions depend on knowing which apps are installed and approved.
Recommendation — Track notarized app versions and remediate vulnerable releases promptly. Scan downloaded macOS apps with malicious-code protection before allowing execution. Maintain an inventory of notarized apps and approved publishers.
CIS Controls v8CIS-2 — Inventory and Control of Software AssetsNotarized apps still need software asset inventory and approval tracking.
CIS-10 — Malware DefensesNotarization supports but does not replace malware defense controls.
CIS-16 — Application Software SecurityTrusted distribution depends on application assurance and secure release handling.
Recommendation — Inventory macOS software and flag unapproved apps even when notarized. Use layered malware defenses to inspect and block harmful macOS software. Verify application provenance and release integrity before deployment.

Practitioner Guidance

What to watch for: Use notarization as a trust signal, not a full assurance standard. The practical question is whether the app comes from the expected publisher, behaves consistently with its stated purpose, and is maintained through a credible release process.

Practitioner takeaway: For enterprise macOS environments, notarization should inform allowlisting and review decisions, but it should not replace provenance checks, software inventory, or post-install monitoring.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org