DV, OV and EV certificates: which kind of SSL certificate you really need

The short answer: for almost every site, a DV (domain validation) certificate is enough, and it is the free one that already comes with your account. OV and EV add a check of the company behind the site, which matters to those who need to show an identity. The encryption, the part that protects data on the connection, is the same in all three: what changes is what someone confirmed about you before issuing it.

The three kinds, side by side

Kind What is checked Who it is for
DV (Domain Validation) Only that you control the domain, by a file, an e-mail or a DNS record. Issued in minutes. Websites, blogs, small shops, businesses in general. It is the AutoSSL one.
OV (Organization Validation) On top of the domain, that the organisation exists, with official documents. Takes longer. Companies that want the certificate to show the organisation’s name, or that a client requires it of.
EV (Extended Validation) A deeper check of the organisation, with more documents and steps. Banks, large shops and organisations with formal requirements.

A point many people do not know: modern browsers stopped showing the green bar with the company name for EV certificates. Today the visitor sees the same padlock whatever the type. The difference lies in the certificate’s details, which only someone who opens them reaches.

All of them have an expiry date, and the maximum lifetime has been getting shorter: do not be surprised to see a certificate valid for under a year. We explain why in why a certificate shows fewer than 365 days. What matters is that it renews in time, and with AutoSSL that is automatic.

What about certificates for several domains?

Coverage What it does
Single domain Covers the name it was issued for (for example, with and without www).
Wildcard Covers the domain and all first-level subdomains (shop., blog., and so on).
Multi-domain Covers a list of different domains in one certificate.

How to decide

1 Have an ordinary site? Stay with the free DV that AutoSSL issues and renews by itself. See what an SSL certificate is.
2 Does a client, a tender or a regulator want identity in the certificate? Consider OV or EV. In that case the certificate is paid, and validation takes paperwork and time.
3 Lots of subdomains? Consider a wildcard, which saves managing one certificate per subdomain.
4 Buy and install a paid certificate following how to activate and install a paid SSL certificate, and if validation gets stuck, domain validation. The types and what each covers are on the SSL certificates page.
A dearer certificate does not make the site safer. It does not protect the site against break-ins, a vulnerable plugin or a weak password. It only guarantees the encrypted connection and, with OV and EV, who is behind it. Do not let anyone sell it to you as protection against hacking.
There is also the CAA record, which says who may issue certificates for your domain. If you use one, make sure it does not stop AutoSSL: CAA records.

Need a certificate with company validation? Tell us the domain and what you are being asked for.

See SSL certificates

SEE ALSO

What is an SSL certificate and why does it matter?

How to activate and install a paid SSL certificate

CAA records: who may issue certificates for your domain

SSL certificates

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?