EV SSL Certificates: What They Are and Why Most Sites Don’t Need One

  by Dallas Kashuba
EV SSL Certificates: What They Are and Why Most Sites Don’t Need One thumbnail

An Extended Validation (EV) SSL certificate is an HTTPS certificate that a certificate authority issues only after verifying your organization’s legal identity: company name, operating address, phone number, and domain ownership. EV adds identity vetting, but major browsers no longer show that status in the address bar. And since 2019, Chrome, Firefox, and Safari haven’t shown EV status in the address bar, which is why most websites shouldn’t pay for one.

In 2010, buying an Extended Validation (EV) SSL certificate could make sense because browsers prominently displayed its identity checks.

Back then, EV certificates turned the address bar green, displayed the company’s legal name in the URL bar, and showed a visible padlock confirming a site’s authenticity.

Screenshot of Thawte EV SSL certificate displayed in different browsers

But it’s not 2010. And EV SSLs are beyond dead now.

Today, paying for an EV SSL is like buying a gold toilet. Same outcome, a lot more expensive.

What EV certificates actually did (and why it mattered)

The basic Domain Validation (DV) certificates you see today only verify that you control a domain. Anyone can get one of these certificates, automatically and for free.

Extended Validation certificates require extensive business verification. Sectigo, a major certificate authority, checks your organization’s legal name and good standing, its operational address, its main phone number, and its control of the domain, then puts a human on the phone with whoever signed the subscriber agreement before issuing anything.

Here’s how the three validation levels compare:

Certificate typeWhat the CA verifiesHow it’s issuedWhat visitors see today
Domain Validation (DV)You control the domainAutomated (ACME), no humans involvedStandard HTTPS, same as every secure site
Organization Validation (OV)Domain control, plus checks on the organization behind itManual reviewStandard HTTPS, same as every secure site
Extended Validation (EV)Domain control, plus legal name, address, phone, and a human vetting processManual review with human verificationStandard HTTPS; the company name is visible only if you click into certificate details

The end result of all that EV paperwork was your company name displayed in the browser, like this example from Comodo (a major SSL certificate provider).

Side-by-side of browser UI before and after EV SSL visual changes — the company name and green bar are gone, replaced with a plain URL display.

But as you can see in the second half of that screenshot, even Comodo’s own site no longer shows any markers of an EV SSL.

Get Content Delivered Straight to Your Inbox

Subscribe now to receive all the latest updates, delivered directly to your inbox.

What makes EV SSL certificates a bad choice now?

The main thing that made EV certificates valuable was the visual indicators. And browsers removed them, one by one.

The shift that killed EV certificates

Let’s Encrypt issued its first publicly trusted certificate on September 14, 2015, and free, automated SSL certificates quickly became the standard for websites. By early 2020, 81% of page loads worldwide used HTTPS, according to Firefox telemetry.

Once nearly every site was encrypted, the padlock became an expectation rather than a trust signal, and browsers dismantled the EV display piece by piece:

  • 2018: Apple dropped the EV company name from Safari’s address bar with iOS 12 and macOS 10.14, and Chrome 69 removed the green styling and “Secure” label.
  • 2019: Chrome 77 (September) moved the EV badge out of the address bar and into Page Info, and Firefox 70 (October) relocated its EV indicator to the site information panel.
  • 2023: Chrome 117 replaced the padlock icon with a neutral “tune” icon, after Google’s 2021 research found only 11% of study participants correctly understood what the lock meant.

Meanwhile, any website served over plain HTTP gets marked “Not Secure,” and a site with a broken or invalid certificate triggers a full-page warning.

People have to click “Advanced” and “Proceed to site anyway (unsafe)” before they can view such a website.

Side-by-side of browser UI before and after EV SSL visual changes — the company name and green bar are gone, replaced with a plain URL display.

With that, the value proposition of EV SSL certificates evaporated. Yet you still see companies selling them like nothing has changed!

Browsers also found that EV doesn’t help

The removal of visual cues wasn’t arbitrary. It was backed by research.

The green URL bar would seem valuable in the close-up screenshots.

But when Chrome’s Security UX team reviewed its own large-scale field experiment alongside prior academic studies, it concluded that “the EV UI does not protect users as intended.” In Google’s field experiment, removing the EV badge for a random subset of users didn’t change a wide variety of user behavior metrics.

Mozilla reached a similar conclusion, citing research that the company name display “does not add any additional security parameters” and noting that for EV to work, users would have to notice its absence on a malicious site.

In short: spending on EV certificates didn’t translate to better protection from actual threats, like phishing or malicious websites.

Most users never see EV information anymore

Once Chrome 77 and Firefox 70 shipped in the fall of 2019, the last bit of EV information was hidden away as well.

Example of a valid SSL certificate in action — the browser confirms the connection is secure, often shown with a padlock icon.

The company name, the extended validation status, the verified business information: everything was tucked behind the site information icon, where users have to click to view certificate details.

So the majority of users will never see the EV details that supposedly justify the premium pricing.

A certificate’s a certificate: all of them provide identical encryption

The job of an SSL certificate is to encrypt data traveling from a visitor’s browser to the company server. This ensures that bad actors cannot spy on the data.

Visual comparison of insecure (HTTP) vs secure (HTTPS) connections — showing how SSL certificates protect data in transit.

ANY SSL certificate can encrypt data the same way.

DV, OV, and EV describe how thoroughly the certificate authority verifies the applicant. EV adds legal-identity checks, but major browsers no longer present those checks as a visible address-bar trust signal.

Whether you’re using a free SSL certificate or an Extended Validation certificate that costs hundreds of dollars a year, the actual security protecting your users’ data is exactly the same.

With EV, you’re paying for additional identity vetting that provides little practical benefit for most public websites, though a contract or internal policy may still require it.

What’s a better option in 2026 and beyond?

Let’s Encrypt completely disrupted the SSL market by making certificates free, automated, and just as secure as expensive alternatives. Now everyone with a domain can get an SSL certificate.

Let’s Encrypt dominates the market for a reason

Let’s Encrypt, the free domain validation certificate provider, is the certificate authority behind 67.8% of all websites whose SSL certificate authority W3Techs can identify (64.4% of all websites, period), as of August 2026. The rest of the market is shared between other DV, OV, and EV providers.

Let’s Encrypt issued its billionth certificate on February 27, 2020.

Bar chart of Let's Encrypt single-day issuance milestones: 1 million certificates in a day in September 2018, and 10 million certificates in a day for the first time at the end of September 2025.
Source: Let’s Encrypt

And the pace keeps climbing: Let’s Encrypt crossed 10 million certificates issued in a single day for the first time at the end of September 2025, and by late 2025 it was hitting that volume frequently.

Automation is better than manual processes

While the SSL industry sold expensive certificates with manual verification processes, Let’s Encrypt introduced automation and efficiency.

The ACME protocol allows certificates to be issued, installed, and renewed without any human intervention. Your server proves it controls the domain, gets a certificate, and repeats the process automatically before every expiration.

That automation is also what makes short-lived certificates practical. Let’s Encrypt certificates are valid for 90 days by default (subscribers can even opt into 6-day certificates). If a certificate’s private key is ever compromised, or the information in it goes stale, a short-lived certificate ages out of circulation quickly instead of staying trusted for years.

Short lifespans make manual verification almost impossible

The SSL industry is moving toward even shorter certificate validity periods, and this time it’s official policy, not a prediction.

In April 2025, the CA/Browser Forum approved ballot SC-081v3 (proposed by Apple, passed 29–0), which caps maximum certificate lifespans at 200 days from March 15, 2026, then 100 days from March 15, 2027, and 47 days from March 15, 2029. Domain validation reuse drops to 10 days by 2029.

As certificate lifespans shrink, organizations will need to replace certificates more often. Automated issuance and renewal make that schedule easier to manage than a manual process.

Domain Validation (DV) certificates are usually all you need

Domain Validation certificates (whether free or paid) offer several advantages over expensive EV certificates.

  • Identical encryption: Your users get the same security
  • Automatic renewal: Far less risk of an expired-certificate outage
  • Automated deployment: No waiting on paperwork or verification phone calls
  • No administrative overhead: No legal documents or business verification to maintain
  • Future-proof: Automated renewal doesn’t care whether certificates last 90 days or 47

A free DV certificate from Let’s Encrypt provides the same level of protection as a paid one. If that’s all you need (and for most sites, it is), go with the free certificate.

If you’d rather have a paid certificate with a certificate authority’s support team behind it, that’s an option too: DreamHost supports adding paid or third-party SSL certificates alongside the free ones.

Do big companies use EV certificates and does anyone actually need them?

If EV certificates were truly necessary for security and trust, you’d expect the biggest companies to use them.

They don’t.

Amazon, Netflix, and Walmart skipped EV years ago

Troy Hunt, the creator of Have I Been Pwned, shared a tweet when Chrome first started experimenting with removing the EV indicator from the browser in the first half of 2018.

This tweet underscores the decline of EV SSL visibility—Chrome's shift away from showing organization names in the address bar signals a broader move toward simplified, padlock-only indicators.
Source

Later that year, in his post “Extended Validation Certificates are Dead,” Hunt clicked through the biggest shopping, social media, health, and government sites on the web: Amazon, Netflix, eBay, Walmart, Facebook, Pinterest, the National Institutes of Health, GOV.UK. Not an EV certificate among them (of everything he checked, insurer USAA was the lone exception). He also noted major brands actively dropping EV that year, including Shutterstock, Target, UPS, Visa, and Twitter.

If the enterprises with the biggest security budgets and millions of customers entering payment details every day decided EV wasn’t worth it, what exactly are EV certificate vendors claiming to protect you from?

These companies aren’t cutting corners on security. They’re using certificates that provide the exact same encryption without the documentation overhead and costs. Platforms went the same way: Shopify’s and Squarespace’s Let’s Encrypt integrations were significant contributors to the first day Let’s Encrypt issued a million certificates, back in September 2018.

Does it make financial sense to pay for EV certificates?

The economics of EV certificates don’t add up when you look at what you’re actually getting.

The sales pitch comes from the people selling

The CA/Browser Forum, made up of certificate authorities and browser makers, sets the baseline rules for certificates. Some prominent EV marketing has come from companies with EV certificates to sell.

Troy Hunt documented a memorable example: a Comodo marketing email claimed “customers are 50% more likely to trust and purchase from a website with a green address bar,” citing a DevOps.com survey. When pressed, the survey’s author confirmed the study had been commissioned by Comodo CA itself.

A redditor who claimed to have worked for a certificate authority answered the question: “What’s the point of high-end SSL certificates?”

They stated that there’s no difference between a high-end SSL vs. a regular one. It’s just a way for certifying authorities to sell you more certificates.

This Reddit comment highlights a growing skepticism: many view SSL certificates—especially premium ones—as more about profit than protection, with little practical difference in security.

When a certificate seller funds a study used to market its own certificates, a healthy dose of skepticism is warranted.

Those million-dollar warranties are marketing gimmicks

EV certificates come with headline-grabbing warranties. Sectigo, for example, advertises a $1,750,000 warranty on its EV certificates. These warranties supposedly pay out if the certificate authority makes mistakes that lead to losses.

Scott Helme, the founder of Report URI, examined the three scenarios these warranties cover.

Statement of Scott Helme, the founder of Report URI, regarding certificate warranties

His breakdown: certificate authorities are already required to validate your information under the industry’s Baseline Requirements, a CA should never possess your private key in the first place, and the consumer-payout scenario comes wrapped in fine print (60-day claim windows, revocation checks the victim was supposed to have performed manually) that makes a successful claim close to impossible. Helme couldn’t find a single documented case of anyone successfully claiming on one of these warranties, and when Troy Hunt asked a certificate seller’s CEO for examples, he got insults instead of answers.

I’d recommend reading through Scott’s article as well as Troy’s article to get a clearer understanding of why I, too, am calling these marketing gimmicks.

Do you ever need an EV certificate then?

Despite everything we’ve talked about above, EV certificates do have some use.

Here are a few specific situations where you’d need to fall back on EV certificates.

  • A regulator or contract requires one: If your industry regulator, a banking partner, or an enterprise customer’s contract explicitly mandates EV certificates, you don’t have a choice. Comply first, argue later.
  • Enterprise policies requiring specific certificate types: Some large corporations have internal policies mandating EV certificates for public-facing sites. This is usually more about corporate risk management than actual security.

For the vast majority of websites, including blogs, e-commerce stores, SaaS applications, marketing sites, and most business websites, an EV certificate provides no meaningful benefit over free alternatives.

Should you just get free certificates and move on?

In my opinion, the answer is a resounding YES. For the overwhelming majority of websites, the answer is yes.

Here’s why:

The market has already decided

Free, automated certificates make up the bulk of the market.

Pie chart showing Let's Encrypt is the SSL certificate authority for 67.8% of websites with a known certificate authority, with all other providers sharing the remaining 32.2% (W3Techs, August 2026).
Source: W3Techs, August 2026

Let’s Encrypt alone is the certificate authority for 67.8% of websites with an identifiable SSL provider (W3Techs, August 2026). And the encryption those free certificates enable is now the norm: roughly 80% of page loads worldwide use HTTPS, and close to 95% in the U.S., according to Firefox telemetry cited by Let’s Encrypt.

Invest your money in security that actually matters

The time and money you save can go toward security measures that actually matter: better hosting infrastructure, security monitoring, regular backups, web application firewalls, or penetration testing.

DreamHost offers free Let’s Encrypt SSL certificates that you can configure in the panel to renew automatically. If your host still charges for basic SSL, compare that cost with providers that include a free certificate.

EV SSL certificate FAQs

What is an EV SSL certificate?

An EV (Extended Validation) SSL certificate is an HTTPS certificate issued only after the certificate authority verifies the organization’s legal identity, including its registered name, operational address, phone number, and domain ownership, through a human-conducted vetting process. It encrypts traffic exactly like any other SSL certificate; only the identity paperwork differs.

What is the difference between standard SSL and EV SSL?

Validation depth, not security. A standard Domain Validation (DV) certificate confirms you control the domain and is issued automatically. An EV certificate adds manual verification of the business behind the domain. Both encrypt connections identically, and major browsers display both the same way in the address bar.

Is EV SSL dead?

As a visible trust signal, yes. Safari dropped the EV company name in 2018, Chrome 77 moved it out of the address bar in September 2019, and Firefox 70 followed in October 2019. EV certificates are still sold and still work as valid HTTPS certificates, but visitors no longer see any difference without digging into certificate details.

Are EV certificates worth it?

For most websites, no. You get the same encryption from a free DV certificate, and browsers stopped displaying EV indicators in 2019. An EV certificate is only worth buying when a regulator, contract, or internal corporate policy explicitly requires one.

How much does an EV SSL certificate cost?

Typically hundreds of dollars per year. As of August 2026, Sectigo lists its single-domain EV certificate starting at $257.66 per year on a six-year subscription, with shorter terms and multi-domain options costing more. A Domain Validation certificate from Let’s Encrypt costs nothing.

Do I need an EV certificate for an ecommerce site?

No. The encryption protecting your customers’ payment details is identical on a free DV certificate, and when Troy Hunt surveyed the web’s biggest shopping sites in 2018, Amazon, eBay, and Walmart were already running without EV. The exception: if a payment partner or regulator contractually requires EV, that agreement wins.

Stop overthinking it, a DV SSL is all you need

Extended Validation certificates are expensive solutions to problems that can mostly be solved for free. I’m not referring to the highly regulated cases that genuinely require EV SSLs — for the rest of the world, a DV SSL should suffice.

The encryption is identical, browsers killed the visual indicators, and even the largest companies don’t use them.

Here’s what you should actually do:

  • Log into your hosting control panel
  • Enable free SSL with one click
  • You’re done

Your users get the same encryption that protects the biggest sites on the web.

If your host doesn’t offer a free SSL, move to a hosting provider like DreamHost that does.

Save your money for security that actually matters: backups, monitoring, or a web application firewall.

Those will protect your website far better than paying hundreds annually for premium paperwork.

If you’d rather hand the technicalities over to a professional, we’ve got you covered with our professional website management services.

Pro Services – Website Management

We’ll Handle the Technical Stuff

Bring enterprise-grade performance and reliability to your website. Leave the backend to the experts – you focus on your business.

See More

Dallas Kashuba co-founded DreamHost while attending Harvey Mudd College and has spent nearly three decades building infrastructure at scale. Today he serves as an advisor, board member, and investor for various tech startups, with a consistent focus on user privacy, open source, and data portability. When he's not thinking about the Open Web, he's probably making music. Follow Dallas on X.