DoD is assuming that a level of security exists through acknowledging a valid digital signature, which implies that a trusted source created the code, and that it contains no malware. If no signature is present or the signature could not be verified, then the app must not execute it. Further to this, DoD requires that any mobile code in the app not only be signed, but also be mobile code that has already been categorized. Any uncategorized code, even though potentially safe, must not be used.