For a long time, EV SSL certificates were the gold standard of website trust. They turned the browser address bar green and displayed the company name prominently. Visitors saw the visual cue and knew, at a glance, that the site belonged to the verified company.
Things have changed. Browsers have quietly removed most of the visible treatment that made EV certificates valuable. The green bar is gone in most cases. The company name no longer shows in the address bar by default. The visual difference between EV and regular SSL has shrunk to almost nothing.
This piece covers what EV certificates actually are, what the verification process involves, why their value has changed, and if they still make sense for your site.
What Extended Validation Means
EV is the strictest level of SSL certificate validation. The CA performs detailed checks on the organization before issuing the certificate.
The Verification Process
For an EV certificate, the CA verifies several things about the organization:
Legal existence and standing of the company. The CA checks government records to confirm the business is registered, active, and in good standing.
Physical existence of the business. The CA verifies a physical address through public records or in-person verification.
Operational existence. The CA confirms the business is actually operating, not just a registered entity on paper.
Domain ownership. The CA confirms the requester controls the domain the certificate will cover.
Authorization of the requester. The CA confirms the person requesting the certificate is authorized to act on behalf of the organization. This usually involves verifying their identity and confirming their role.
The whole process takes days to weeks depending on how easily the verification documents come together.
What Goes Into the Certificate
Once verified, the certificate includes detailed organization information. The legal name of the company, the registered address, the jurisdiction, the type of business entity. This information is embedded in the certificate and can be viewed by anyone who inspects it.
The point is that the certificate is bound to a verified organization, not just to a domain.
How EV Certificates Used to Display
The visible treatment used to be the main selling point of EV.
The Green Bar Era
Browsers used to display EV certificates with distinctive visual treatment. The address bar background turned green. The company name appeared prominently next to the URL. Some browsers also showed a small lock with a green color or a verified badge.
The treatment was meant to give visitors a clear signal that the site was extra-trustworthy.
The Visual Change
Around 2019 and 2020, the major browsers (Chrome, Firefox, Safari) quietly removed most of the EV visual treatment. The reasons were several.
First, research suggested that most users did not notice or understand the green bar. The visual cue did not actually drive trust in the way browser vendors expected.
Second, attackers had registered legitimately-named companies (Stripe Inc., Apple Inc. variants in different jurisdictions) and obtained EV certificates that displayed the company name. The verified company was real but not the company users thought it was.
Third, the differentiation between EV and other certificates was creating user confusion about what “secure” meant. Browsers shifted toward making HTTPS the baseline and reducing distinctions between certificate types.
What EV Looks Like Now
In modern browsers, EV certificates display the same lock icon as DV and OV certificates. The company name is visible if you click the lock and view certificate details, but it is not in the address bar.
For most users, an EV certificate looks identical to a free Let’s Encrypt certificate. The visual differentiation that justified the premium is mostly gone.
What EV Still Provides
Even with the visual changes, EV certificates still offer some specific value.
Verified Identity in the Certificate
The certificate itself still contains verified organization information. Anyone who inspects the certificate (by clicking the lock and viewing details) can see the legal name, address, and jurisdiction.
For users who do check, the information is more detailed than what DV or OV certificates provide.
Stronger Verification Process
The CA’s verification process is more thorough for EV than for DV or OV. The chain of trust extends further. The organization has been through real scrutiny.
For compliance situations or industries that need to demonstrate due diligence around identity, the EV verification process can be valuable.
Higher Warranty
Most EV certificates come with higher warranty amounts than DV or OV certificates. If the CA messes up, the warranty payout is bigger.
In practice, warranties are rarely claimed. But for organizations that value the protection, EV provides more of it.
Phishing Resistance
For organizations that are common phishing targets (banks, government, major retailers), EV certificates make it harder for attackers to impersonate the brand. An attacker can register a similar-looking domain and get a DV certificate easily. Getting an EV certificate for the same setup requires going through verification that would reveal the impersonation.
For these organizations, the difficulty of obtaining EV is itself a defense.
Who Still Uses EV Certificates
Despite the reduced visual treatment, EV certificates have a place in specific situations.
Banks & Financial Institutions
Many banks still use EV certificates. The internal compliance and security teams value the additional verification, and the visible-to-inspection company information matters for users who do verify.
Government Sites
Government websites often use EV certificates as part of compliance requirements and to provide assurance to citizens.
Major Brands & Common Phishing Targets
Companies that are frequently impersonated by phishers (PayPal, Apple, Microsoft, Google, and others) use EV certificates as one layer of defense. The verification process makes brand impersonation harder.
Compliance-Driven Industries
Healthcare, legal, and other industries with strict identity verification requirements sometimes use EV as part of their compliance posture.
Who Should Probably Skip EV
For most sites, EV is no longer worth the cost.
Most Small Businesses
A typical small business site, e-commerce store, or service business does not need EV. The cost outweighs the value for sites where visitors are not actively inspecting certificates.
Personal Sites & Blogs
EV is overkill for personal sites. Free DV certificates cover everything a personal site needs.
Sites Without Specific Identity Concerns
If you do not have compliance requirements that call for EV and you are not a common phishing target, the verification process is not buying you much.
Sites That Want the Green Bar
Most browsers do not show the green bar anymore. Buying EV expecting the old visual treatment leads to disappointment.
What EV Certificates Cost
EV certificates are the most expensive type.
Direct from CAs
Buying EV directly from major CAs like DigiCert or Sectigo, you are looking at $150 to $500 per year. Some specialty providers charge significantly more.
The price reflects the verification work involved on the CA’s side. The process is labor-intensive.
Through Resellers
Resellers like Namecheap and SSLs.com offer EV at lower prices than direct purchase. You can find EV certificates for around $80 to $200 per year through resellers.
The certificate is the same. The verification is the same. The discount comes from buying in bulk.
Renewal Considerations
EV verification is required at each renewal, though typically less detailed than the initial verification. Plan for time on each renewal cycle, not just for the cost.
Alternatives to EV
For sites that want identity verification without paying for full EV, alternatives exist.
OV Certificates
Organization Validation certificates verify the organization but with less strict verification than EV. The certificate includes organization information that can be inspected, just like EV.
OV costs less than EV and is faster to issue. For sites that want some identity verification but not the full EV process, OV is a reasonable middle ground.
Trust Badges
Many e-commerce sites display trust badges from services like Trustpilot, BBB, or industry-specific certifications. These provide visual trust cues that work better than EV in modern browsers.
The badges are not technically related to SSL, but they often achieve the trust-building goal that EV was supposed to address.
Verified Social Media
A verified social media presence with significant following provides identity assurance to visitors. The verification badges on Twitter, LinkedIn, and other platforms give visitors confidence that they are dealing with a real organization.
Strong Brand Presence Elsewhere
Sites that show up in search results, get covered by press, and have established brand presence are inherently more trustworthy than sites that appear out of nowhere. Strong overall brand presence does more for trust than any certificate type.
Bringing the EV Story to a Close
EV certificates have had a complicated few years. They went from being the visible badge of website trust to being almost invisible to typical visitors. The verification process behind them is still strong, but the visible differentiation that justified the premium has mostly disappeared.
For most sites, EV is no longer worth the cost. Free DV certificates provide the same encryption, the same lock icon, and the same browser treatment that EV used to claim. The premium of EV pays for a verification process that few visitors will actually check.
For specific situations, EV still makes sense. Banks, government sites, common phishing targets, and organizations with compliance requirements still use EV as part of their security posture. For these organizations, the verification process and the certificate contents matter even though the visible browser treatment has changed.
If you are deciding about EV for a new site, the answer is probably no. The cost and verification work are not justified for typical use cases. Free DV through Let’s Encrypt covers what you need.
If you already have an EV certificate and are deciding about renewal, look at if anything has changed. If your situation has not changed and you valued EV before, the renewal probably makes sense. If you got EV because of the green bar and the green bar is gone, this might be the time to drop down to OV or DV depending on your verification needs.
The SSL market has matured past the era where EV was the obvious choice for serious sites. The choice now is more nuanced, and for most sites, the answer is simpler than it used to be.