- What an OV SSL Certificate Actually Asserts — and What It Does Not
- OV SSL Factor 1: The Browser Stopped Showing the Difference in 2019
- OV SSL Factor 2: The Validity Clock Is 200 Days and Falling
- OV SSL Factor 3: The Premium Feature Is the One That Blocks Automation
- What Each Certificate Type Is Actually Required to Contain
- The Reissuance Arithmetic: What an OV SSL Certificate Costs in Labor
- When an OV SSL Certificate Is Genuinely the Right Call
- What Our Support Queue Says About OV SSL and Certificate Types
- Which Certificate Type Does Your Site Actually Need?
- A Practical Checklist Before You Buy an OV SSL Certificate
- Frequently Asked Questions About OV SSL Certificates
- DV vs OV SSL in 2026: which one does an ordinary business site need?
- What does an OV SSL certificate prove that a DV certificate does not?
- Does AHosting include a free alternative to an OV SSL certificate in 2026?
- EV vs OV SSL: is extended validation worth the extra vetting time?
- When does a WooCommerce store processing card payments actually need an OV SSL certificate?
- How can I check which validation type my certificate actually has?
- How often will a certificate need reissuing under the 2026 validity rules?
- Why does AHosting recommend against an OV SSL certificate for most hosting customers?
- Is an OV certificate more secure than a DV certificate?
- Does AHosting charge extra for the certificate types most sites actually need?
An OV SSL certificate proves the same thing about your domain as a free DV one. The rulebook says so, browsers stopped displaying the difference in 2019, and the organization name is what you are actually buying.
Every hosting control panel now hands out a free certificate, and every certificate authority still sells a more expensive one. The upgrade is usually described in the language of trust: a DV certificate proves you control a domain, while an OV SSL certificate proves a real organization stands behind it. That description is accurate. What it leaves out is that the body writing the rules for every public certificate authority has already stated, in the section of its own rulebook that defines these certificates, that the two are equivalent for the job a certificate does on the wire.
This post is the reassessment rather than the explainer. It sets out what the standards actually require, what changed in 2026, and the four situations where paying more still earns its cost. For the neighboring question of what a free certificate includes and why renewal quietly fails, see our guide to what free SSL and domain management actually covers.
What an OV SSL Certificate Actually Asserts — and What It Does Not
An OV SSL certificate asserts one thing a DV certificate cannot: a verified legal entity, placed in the certificate subject and checked by the issuing authority against business records. Everything else about the two certificates is the same. Consequently, the useful question is not which is stronger but who reads that entity name, and how often.
Four Certificate Types, Not Three
Most explainers list three tiers. In fact the CA/Browser Forum Baseline Requirements define four subscriber certificate profiles, each asserting a fixed Reserved Certificate Policy Identifier. Individual Validated sits alongside the familiar three and names a natural person rather than a company. Notably, that identifier is the only part of this subject a buyer can verify without taking a reseller at their word.
The Sentence the Rulebook Puts in Its Own Profile Section
Directly beneath the table listing those four types, the Baseline Requirements add a note: “Although each Subscriber Certificate type varies in Subject Information, all Certificates provide the same level of assurance of the device identity (domain name and/or IP address).” In other words, the organization that certificate authorities collectively write their own rules through has recorded that the tiers are equivalent for identifying the server you connected to. No certificate authority markets that sentence, and it is the single most load-bearing fact on this page.
OV SSL Factor 1: The Browser Stopped Showing the Difference in 2019
For years the argument for validation tiers rested on what a visitor would see. That argument ended in September 2019. Chrome 76 displayed an Extended Validation badge beside the URL; Chrome 77 moved it into the Page Info panel behind the lock icon, where essentially nobody looks. Apple had made the equivalent change to Safari a year earlier.
Furthermore, the Chromium security team published its reasoning rather than leaving it to be inferred. Their documented rationale for moving the EV indicator states that “Users do not appear to make secure choices (such as not entering password or credit card information) when the UI is altered or removed, as would be necessary for EV UI to provide meaningful protection.” That is a measured finding from a field experiment, not an opinion about design. Therefore any pitch resting on visitor-visible trust is describing a browser that has not existed for seven years.
OV SSL Factor 2: The Validity Clock Is 200 Days and Falling
Meanwhile the operational ground shifted underneath every validation tier at once. Ballot SC081v3 passed in April 2025 and wrote a reduction schedule into the Baseline Requirements. Certificates issued before 15 March 2026 could run 398 days. From that date the ceiling is 200 days; from 15 March 2027 it is 100 days; from 15 March 2029 it is 47. Above all, these limits apply to every subscriber certificate equally, so buying a higher tier buys no relief from them.
Why the Two Reuse Clocks Disagree
Interestingly, the schedule moves two clocks at different speeds, and the gap between them is the whole operational story of an OV SSL certificate. Subject Identity Information validation data may be reused for 398 days. Domain Name and IP Address validation data may be reused for 200 days today, 100 from March 2027, and just 10 from March 2029. As a result, the organization vetting you paid for stays valid for roughly a year while the certificate carrying it must be replaced at least twice inside that same year.
What Ballot SC102 Took Away From EV in July 2026
Six weeks before this post was written, ballot SC102 was adopted and quietly removed the last places where Extended Validation had rules of its own for the domain half of the job. The EV Guidelines had carried a hardcoded 398-day domain data reuse period and their own validity text; both now simply point at the Baseline Requirements. The ballot also dropped the EV-only registrant re-check against WHOIS and RDAP. Accordingly, EV and DV are now validated against the domain by the same procedures on the same clock.
OV SSL Factor 3: The Premium Feature Is the One That Blocks Automation
Put those two facts together and the commercial logic inverts. The feature that makes a certificate premium is a human checking business records, and a human checking business records is precisely what cannot be automated. Let’s Encrypt states the position plainly: it does not offer organization or extended validation “primarily because we cannot automate issuance for those types of certificates.”
That was a defensible trade when a certificate lasted three years. Currently it is a commitment to a manual vetting pass at least twice a year, rising toward eight times a year once the 47-day ceiling arrives. Our own product page quotes EV issuance at one to three business days. Multiply that by the reissuance cadence rather than by a single purchase, and the real price of the tier becomes visible. Meanwhile the free alternative on every AHosting shared hosting plan is issued and renewed by cPanel AutoSSL, which “automatically installs domain-validated SSL certificates” and uses Let’s Encrypt as its default provider.
What Each Certificate Type Is Actually Required to Contain
Below is the profile the Baseline Requirements impose on each of the four types, reduced to the parts a buyer can act on. Specifically, the policy identifier is machine-readable: open any certificate, find its certificate policies extension, and the value tells you what you were sold regardless of what the invoice called it.
| Type | Policy identifier | Organization name in subject | Domain validated by | Assurance of device identity |
|---|---|---|---|---|
| Domain Validated (DV) | 2.23.140.1.2.1 | Forbidden — any attribute beyond country and a deprecated common name must not be present | Baseline Requirements domain control methods | Same |
| Individual Validated (IV) | 2.23.140.1.2.3 | A verified natural person, with locality | Baseline Requirements domain control methods | Same |
| Organization Validated (OV) | 2.23.140.1.2.2 | A verified legal entity, with country and locality | Baseline Requirements domain control methods | Same |
| Extended Validation (EV) | 2.23.140.1.1 | A verified legal entity under the EV Guidelines, with no placeholder characters permitted | Baseline Requirements domain control methods, since ballot SC102 | Same |
The Reissuance Arithmetic: What an OV SSL Certificate Costs in Labor
Price comparisons treat a certificate as an annual purchase. That framing expired on 15 March 2026. Ultimately the cost that matters is issuance events per year multiplied by the human effort each one demands, and only one of those two numbers is falling.
| Period | Maximum validity | Domain data reuse | Reissues per year | Automated DV effort | OV or EV effort at 1–3 business days per pass |
|---|---|---|---|---|---|
| Until 14 Mar 2026 | 398 days | 398 days | 1 | None | 1–3 business days |
| 15 Mar 2026 — 14 Mar 2027 | 200 days | 200 days | 2 | None | 2–6 business days |
| 15 Mar 2027 — 14 Mar 2029 | 100 days | 100 days | 4 | None | 4–12 business days |
| From 15 Mar 2029 | 47 days | 10 days | about eight reissues a year | None | 8–24 business days |
Notably, the DV column never changes. Automation is indifferent to frequency, which is exactly why the schedule was written the way it was. For an agency carrying certificates across dozens of client domains on reseller plans, that indifference is the difference between a background process and a recurring calendar obligation nobody owns.
When an OV SSL Certificate Is Genuinely the Right Call
An argument that ends in “never” is not an honest argument. There are real cases, and they share a shape: something other than a browser reads the organization name. In practice that means a regulator, an auditor, or a counterparty with a contract.
eIDAS, QWACs, and the One Place Identity Is Legally Required
In the European Union, identity inside a certificate is not decorative. The European Commission’s guidance on trust services explains that a qualified website authentication certificate “makes it possible to authenticate a website and to link the website to the identity of the person to whom the certificate is issued”. The same guidance states that the Regulation obliges web browsers to accept a QWAC and to display the identity data of the website owner in a user-friendly manner. That is the one context where the identity assertion is guaranteed a reader. However, the same guidance is explicit that use of such certificates “should be voluntary”, so this is a real exception rather than a requirement on ordinary sites.
Procurement Checklists, and How to Answer One Without Overbuying
The commonest genuine trigger is a contract. Enterprise security questionnaires, acquiring banks and public-sector frameworks still name validation tiers, and a supplier who argues with the clause loses the deal rather than the argument. Similarly, a store taking card payments may find its processor asking, even though no card scheme rule turns on the tier. Buy exactly what the clause names. Do not let an OV requirement become an EV purchase on a security argument the standards do not support, and read our note on where checkout trust is actually won or lost before attributing conversion problems to a certificate.
When the answer is genuinely OV or EV, the certificate stops being a plan feature and becomes a purchase, and the validation is the part you are buying. Accordingly it is worth buying from somewhere that will do the vetting alongside you rather than emailing a form: our SSL certificate options start at $9.99 for the coverage cases and run through to EV for the contractual ones.
What Our Support Queue Says About OV SSL and Certificate Types
Search data reveals what people ask a search engine. A support queue reveals what actually goes wrong afterwards, and the two rarely agree. Over the last twelve months our three brands logged 341, 447 and 254 technical tickets respectively, of which 76 concerned SSL and certificates — 11 at AHosting, 42 at ASEOHosting and 23 at SEOHost.net.
Interestingly, the recurring subjects in that set are uniformly operational: SSL Renew, renew SSL, SSL Cert, SSL Certs, ssl problem, Weird SSL. Not one of the recurring subjects concerns which validation tier to buy. The tier is a decision made once, usually at purchase, and then never revisited. Renewal is the thing that breaks, repeatedly, for years.
That is worth stating plainly because it inverts the sales conversation. The problem customers actually bring us is the problem automation solves and manual vetting worsens. For the mechanics of why renewals fail in the first place, which is almost always a DNS question rather than a certificate one, our post on server-level protection and what it does not cover sets out where certificate handling sits relative to everything else on a host.
Which Certificate Type Does Your Site Actually Need?
Rather than reasoning from a comparison table, answer four questions about the site you actually run. Above all, note that three of the four have nothing to do with security — which is itself the finding.
OV SSL Decision Checker
Four questions. Nothing is sent anywhere; the verdict is calculated in your browser.
1. Does a contract, acquiring bank, or procurement questionnaire name the validation tier in writing?
2. Do you serve EU users under a rule that requires a qualified website authentication certificate?
3. Do you need one certificate covering a wildcard or several unrelated domain names?
4. Can somebody complete a vetting call on demand, twice a year, every year?
A Practical Checklist Before You Buy an OV SSL Certificate
Take this to any certificate reseller, including this one. Each item has a factual answer, and a vague response to any of them is itself the answer:
- Which Reserved Certificate Policy Identifier will the issued certificate assert, and can you confirm it before I pay?
- What is the maximum validity period I will actually receive, given the current 200-day ceiling?
- How many separate vetting passes will that require from my staff over the next three years?
- Is the organization name you will verify the one on my incorporation documents, or the one on my invoice?
- If my requirement is wildcard or multi-domain coverage, can I buy that scope at the DV tier?
- Which named contract, regulation, or scheme rule requires the tier you are recommending?
- What happens to my certificate if a vetting call cannot be completed inside the reissuance window?
Finally, a note on migration that catches people out. Certificate vetting does not travel with a site, so a move to a new provider means reissuing, and an organization-validated certificate means re-vetting on somebody else’s schedule. That is worth planning for before the move rather than during it — see our guide to moving a site with zero downtime.
Frequently Asked Questions About OV SSL Certificates
DV vs OV SSL in 2026: which one does an ordinary business site need?
Typically, an ordinary business site needs DV and nothing more. Both certificate types encrypt the connection identically, and the CA/Browser Forum states in its own certificate profile section that every subscriber certificate type provides the same level of assurance of the device identity. What OV adds is a verified organization name inside the certificate, which no mainstream browser has surfaced in its address bar since 2019. The decision table in this post sets out the four cases where that name still earns its cost.
What does an OV SSL certificate prove that a DV certificate does not?
Specifically, an OV SSL certificate carries a verified legal entity in its subject field, where a DV certificate is forbidden from carrying one at all. The Baseline Requirements permit only a country code and a deprecated common name in a DV subject, and require that any other attribute must not be present. Both certificates prove exactly the same thing about the domain, because both are validated by the same domain control methods under the same section of the same rulebook.
Does AHosting include a free alternative to an OV SSL certificate in 2026?
Indeed, every AHosting hosting plan includes a free domain-validated certificate issued and renewed automatically through cPanel AutoSSL, which uses Let’s Encrypt as its default provider. That covers the encryption and the domain assurance in full. It does not carry an organization name, because Let’s Encrypt does not issue organization-validated certificates at all, and the reason it gives is the reason this post exists.
EV vs OV SSL: is extended validation worth the extra vetting time?
In practice, extended validation is now harder to justify than it was a year ago. Ballot SC102 passed in July 2026 and replaced the EV Guidelines’ own validity period and domain data reuse period with plain references to the Baseline Requirements, so EV no longer has separate rules for the domain half of the job. What remains distinct is the organizational vetting, which our own product page quotes at one to three business days per issuance.
When does a WooCommerce store processing card payments actually need an OV SSL certificate?
Notably, almost never on the strength of the payments alone. Card processing requirements are satisfied by a validly issued certificate and a correctly configured server, not by a particular validation tier, and no browser shows a checkout visitor the difference. The genuine triggers are contractual rather than technical: an acquiring bank, an enterprise customer, or a procurement questionnaire that names the tier explicitly.
How can I check which validation type my certificate actually has?
Fortunately, this is machine-checkable rather than a matter of trust. Every publicly trusted certificate asserts a Reserved Certificate Policy Identifier that names its type, and the four values are fixed by the Baseline Requirements. Open the certificate in your browser, find the certificate policies extension, and read the identifier. The table in this post maps each of the four values to the type it declares.
How often will a certificate need reissuing under the 2026 validity rules?
In practice, at least twice a year. The maximum validity period for any subscriber certificate fell to 200 days on 15 March 2026, drops to 100 days on 15 March 2027, and reaches 47 days on 15 March 2029. Those limits apply to every validation tier equally, so a certificate that requires manual vetting to reissue requires that vetting on the same shrinking schedule as a free one that renews itself.
Why does AHosting recommend against an OV SSL certificate for most hosting customers?
Ultimately, because the tier that costs more is the tier that cannot be automated, and the calendar is moving against manual issuance. Let’s Encrypt states that it does not offer organization or extended validation primarily because issuance for those types cannot be automated. Set that against a validity period falling from 200 days to 47, and the premium purchase becomes the one that generates recurring work for an assurance the browser does not display.
Is an OV certificate more secure than a DV certificate?
However tempting the assumption, no. The cryptography, the key sizes, the signature algorithms and the domain validation methods are identical, and the standards body that governs every public certificate authority says so directly in the section that defines the certificate profiles. The difference is what the certificate asserts about the organization behind the domain, and that assertion is read by auditors and procurement teams rather than by browsers.
Does AHosting charge extra for the certificate types most sites actually need?
Accordingly, no. The domain-validated certificate that covers the overwhelming majority of sites is included on every plan at no cost and renews without anyone touching it. Paid certificates start from $9.99 and exist for the cases this post identifies as genuine, which are wildcard and multi-domain coverage, and the contractual situations where a verified organization name is required rather than merely offered.





