DV vs OV vs EV Certificates: Does EV Even Matter Anymore?
Certificate authorities sell three broad tiers of SSL/TLS certificate — Domain Validated, Organization Validated, and Extended Validation — each with a different verification process and, historically, a different price point. Understanding what each one actually confirms, and what changed with the visual treatment browsers give them, explains why EV certificates in particular have become a much more contested purchase than they used to be.
Domain Validation: Proving You Control the Domain
A DV certificate verifies exactly one thing: that whoever is requesting the certificate has some demonstrable control over the domain it's being issued for, typically confirmed through an automated challenge — adding a specific DNS TXT record, placing a designated file at a specific URL, or responding to an email sent to a standard administrative address at the domain. This process can be, and routinely is, fully automated, which is precisely why DV certificates from providers like Let's Encrypt can be issued in seconds at no cost, discussed further in the piece on Let's Encrypt's industry impact elsewhere on this blog.
Organization Validation: Adding a Real-World Identity Check
OV certificates add a genuine, manual verification layer beyond domain control — the certificate authority checks that the requesting organization is a real, legally registered business entity, typically cross-referencing government business registries and sometimes placing a verification phone call to a publicly listed number for the organization. This process takes meaningfully longer than DV issuance (commonly one to several business days) and costs more, reflecting the real human verification labor involved, but it results in a certificate that at least confirms a legitimate, registered business is behind the domain, information a DV certificate simply doesn't verify at all.
Extended Validation: The Highest, Most Rigorous Tier
EV certificates require the most extensive verification process of the three: confirming the organization's legal, physical, and operational existence through multiple independent, authoritative sources, verifying the specific individual requesting the certificate has actual authorization to do so on the organization's behalf, and checking against government business registries with a standardized, industry-defined verification procedure that all EV-issuing certificate authorities are required to follow consistently. This process typically takes several business days to a couple of weeks and costs considerably more than either DV or OV.
What Changed: The Disappearing Green Address Bar
For years, EV certificates carried a distinctive, highly visible browser treatment — a green address bar explicitly displaying the verified company name directly next to the padlock, intended to give visitors an at-a-glance, elevated trust signal for verified businesses, particularly valuable for banking, e-commerce, and other high-stakes transactional sites. Starting around 2019, major browsers — Chrome and Firefox both, within a similar timeframe — removed this distinctive visual treatment entirely, following research suggesting the special indicator wasn't actually improving user security behavior or phishing detection in practice, and that most users didn't understand or actively look for the distinction anyway.
Why This Change Was Controversial
The removal was genuinely contentious within the security and e-commerce industry. Certificate authorities that had built meaningful revenue around EV certificate sales, and businesses that had specifically invested in EV certification for the visible trust signal, argued the removal eliminated a legitimate, verifiable differentiator between a real, accountable business and an anonymous or fraudulent one. Browser vendors countered with usability research showing the distinction rarely influenced actual user behavior and that a more effective anti-phishing strategy focused on other signals (like Google Safe Browsing's active blocklisting) rather than a passive visual indicator most users never consciously registered.
Does EV Still Provide Any Value Today?
With the distinctive visual treatment gone, an EV certificate today looks essentially identical to a DV or OV certificate in the browser's address bar to an ordinary visitor — the verified organization name is still recorded in the certificate itself and can be inspected by clicking into certificate details, but this requires deliberate action almost no visitor ever takes. The remaining value of EV largely shifts to backend and compliance considerations: some industries and specific compliance frameworks still reference EV certification as an expected or required baseline, and some organizations value the rigorous underlying verification process for its own sake — genuine confirmation of legal identity — independent of whether it produces any visible browser distinction anymore.
Where the Verification Rigor Still Pays Off Indirectly
Even without a customer-facing visual reward, the underlying identity verification EV certification requires can still serve a genuine purpose in specific scenarios: some enterprise procurement and vendor-risk processes explicitly ask whether a partner's certificate is EV-validated as a proxy for confirming a documented, third-party-verified legal identity, independent of anything a browser displays. A handful of industries with particularly stringent compliance obligations — certain financial services contexts among them — have historically referenced EV or an equivalent verification depth in their own internal security standards, meaning the certificate can still clear a specific procurement or audit checkbox even though it no longer changes what an ordinary visitor sees.
The Takeaway
The three certificate tiers still represent genuinely different verification depths, but the browser-level incentive to pay for the highest tier largely disappeared once the distinctive EV visual treatment was removed. For most businesses today, a DV certificate provides identical encryption strength and an identical address bar appearance to an EV certificate, and the decision to pursue OV or EV increasingly comes down to specific compliance requirements or organizational preference for documented identity verification, rather than any longer a meaningful, visible customer-facing trust signal.
Tags: certificate types, domain validation, EV certificates