Code 52: "Windows cannot verify the digital signature"

DeviceInBox editorial team · Last updated October 6, 2026

"Windows cannot verify the digital signature for the drivers required for this device. (Code 52)" means the driver loaded by the device is not signed in a way this version of Windows accepts. The file may be unsigned, signed with a certificate that expired or was revoked, or signed by a cross-certificate that Windows 10 and 11 no longer trust. The driver is there, the device is correct, and the signature is the only thing in the way.

Device status box showing the Code 52 digital signature error
Everything about the device is right except the signature on its driver.

Why it happens now and not before

Since Windows 10 version 1607, kernel drivers have to be signed by Microsoft through the hardware developer portal. Drivers signed the old way, with a vendor certificate and a cross-certificate, still load on machines upgraded from older builds but are rejected on clean installs and on machines with Secure Boot. That is why the same adapter works on one PC and reports Code 52 on another.

The devices that hit this most often are USB-to-serial adapters with counterfeit chips, old TV tuners, ISDN and fax modems, programmers and laboratory interfaces, and drivers from vendors that stopped updating years ago.

Look for a current driver first

A properly signed package exists for most chips, even very old ones, because the chip makers resigned them. Read the hardware ID (how) and look it up rather than reusing the file that came on a mini CD:

Hardware IDDeviceDrivers
USB\VID_067B&PID_2303PL2303 Serial Port9
USB\VID_1A86&PID_7523HL-340 USB-Serial adapter7
USB\VID_10C4&PID_EA60CP210x UART Bridge / myAVR mySmartUSB light14
USB\VID_0403&PID_6001FT232 Serial (UART) IC14

Packages that Microsoft distributes through Windows Update are always signed correctly, so Settings, Windows Update, Advanced options, Optional updates is worth checking before anything else.

Timeline of driver signing rules in Windows and which drivers stop loading
Drivers signed before 2016 fail on clean installs of Windows 10 and 11.

Counterfeit USB-to-serial chips

Cheap adapters often carry copies of the Prolific PL2303 or FTDI chips. The genuine driver detects them and refuses to work, usually with Code 10, and old drivers that did work are the unsigned ones that now give Code 52. The usable approach is a legacy signed driver from the chip vendor for that specific revision, which Prolific publishes separately. A better one is to replace the adapter with a CH340 or CP210x model, which have current signed drivers.

See the family pages for Prolific PL2303, WCH CH340 and Silicon Labs CP210x.

pnputil refusing a package because the INF has no digital signature information
pnputil names the reason when Windows refuses a package.

About disabling signature enforcement

Advance Startup, Troubleshoot, Advanced options, Startup settings, option 7 lets a machine start once with signature enforcement off, and the driver loads until the next restart. It is useful to confirm that the signature really is the problem, or to read data off a device one last time. It is not a fix: the setting does not survive a restart, and the permanent variants of it disable Secure Boot, block some Windows features and leave the machine running unverified kernel code.

Startup settings menu with the option to disable driver signature enforcement for one boot
Use the one-time option for a test, not as a permanent setting.

If a device only works with an unsigned driver and no current package exists, treat the hardware as end of life for this machine. A USB adapter is cheap to replace; for an internal card, a signed driver for a different but compatible chip is often available, which is again a question of the hardware ID.

Related: Code 39, Code 10 and installing a driver from an INF file.

More guides