Additional Microsoft Defender tools and services that provide security across various platforms and environments
The accepted answer here is machine-generated and cites nothing, so here are the actual sources.
A Microsoft employee answered the same question in April, for an OV renewal with a new key: "the existing reputation does not carry over and even long-standing publishers can see the 'Windows protected your PC' warning until the new certificate and signed binaries accumulate enough real-world download and execution telemetry", and "there is no manual whitelisting, no fast-track for small publishers, and no direct SmartScreen contact channel beyond the supported submission workflows" (https://learn.microsoft.com/en-us/answers/questions/5857071/how-can-a-small-software-publisher-build-smartscre). That is the answer to questions 1, 3 and 4: no transfer, no portal, no CA liaison.
Why it works this way, since Daedalus asked. Reputation is attached to the specific certificate, not to the company name, and it has been since 2010: "Reputation is assigned to the specific certificate that a developer or ISV uses to sign their code, not the certificate issuer." The reason is that reputation goes both ways. If your certificate signs malware, the certificate loses its reputation, not the file alone. So from SmartScreen's side a new key is a new identity, and it cannot tell your routine renewal from someone who registered the same company name and bought a certificate. It does not read the CA's paperwork. It counts downloads.
Why it feels new for EV specifically: it used to be handled. Microsoft's 2012 announcement of EV code signing said EV certificates "have a unique identifier which makes it easier to maintain reputation across certificate renewals" (https://learn.microsoft.com/en-us/archive/blogs/ie/microsoft-smartscreen-extended-validation-ev-code-signing-certificates). That identifier was the EV OID, and the Trusted Root Program removed EV code-signing OIDs from its roots in August 2024 and now treats "all Code Signing certificates equally" (https://learn.microsoft.com/en-us/security/trusted-root/program-requirements, section 3.D.3). So the renewal continuity EV buyers were promised in 2012 went away with the OID, and nobody announced that part.
One question back, because it is the only unknown left. Did your renewal generate a new key pair, or reuse the old one? Microsoft's confirmed case is new-key. I have not seen anyone report what happens on a same-key renewal, in either direction. If yours kept the key and still reset, that is worth knowing.
I put the whole thing, with Microsoft's wording on what resets reputation and what does not help, here: https://signalscreen.dev/blog/smartscreen-warning-signed-installer