Transport Notes
Dv ov ev SSL certificates — Open the certificate and see what you are actually buying
You have been asked how far your certificate needs to go in proving who you are, and every explanation you have found describes a green address bar that no longer exists.
The short answer
Read the file rather than the sales page: DV records only that somebody controlled the domain, OV records a verified organisation in the subject field, and EV records the same after a deeper audit — and no browser shows any of it in the address bar any more.
So the operational differences are what is written inside the certificate and how long issuance takes. DV covers the everyday site, OV earns its keep when partners genuinely inspect certificates, and EV belongs where a written policy or a high-value payment flow demands it. All three exist here.
By the HostingFast team · Reviewed 24 August 2026
24/7
Engineers reachable
1-click
WordPress install
Free
SSL certificates
Daily
Backups, all plans
Retiring the green company indicator flattened the visible difference between validation tiers to nothing. What still separates them is data — the organisational fields recorded inside the certificate file, and the warranty printed on the contract behind it.
That makes this a question you can answer by inspection rather than by argument. Every certificate on the public web is readable, and so is its issuance record. Ten minutes with two command-line tools tells you exactly what each tier does and does not assert.
Read a certificate before you buy one
openssl prints the full text of any certificate, including the subject line. On a DV certificate the subject carries the common name and nothing else. On OV and EV it carries the organisation name, and on EV the jurisdiction and registration number as well. That is the entire difference, stated in fields.
Certificate Transparency logs make the same information public for every certificate ever issued. Search a domain in a CT log viewer and you can see the issuing authority, the validity window and the names covered — for your own domains and for anyone you are about to compare yourself against.
Do this before you decide. Looking at what a competitor or a supplier actually uses is more informative than any tier comparison, and it takes less time than reading one.
What each tier evidences, and to whom
DV asserts control of a hostname at the moment of issuance. That is exactly what the transport layer needs to establish an encrypted channel with the right server, and it is why DV is sufficient for the overwhelming majority of sites on the web.
OV adds a verified organisation. The authority checks the company exists and that the requester is connected to it, then records the result in the certificate. Security reviewers, procurement teams and B2B partners running supplier due diligence do open certificates and read that field.
EV adds an extended audit of the same organisation, with legal registration, address and signing authority verified. Retail customers never see any of it — they see a padlock and move on. Buying EV to get a green company name back into the address bar is buying something the browsers removed years ago.
Lead time is the operational difference
DV issues in minutes because the check is automated. OV takes longer because a human verifies a company. EV is a paperwork exercise: expect one to three working days while the authority confirms registration, address and the authority of whoever placed the order.
That lead time is a project risk rather than a technical one. Order EV against a launch date the way you would order anything else with a human in the loop — early, with the documents ready, and with somebody named who can answer the verification call.
None of this affects the handshake. The negotiated protocol, the cipher suite and the round-trip cost are identical across all three tiers, which is worth stating plainly because the tier names imply a security gradient that the transport layer does not have.
Deploy it without leaving a gap
The most common deployment fault is an incomplete chain: the leaf and the root are present, an intermediate is missing, and most browsers paper over it while a handful do not. Connect to your own host with openssl and read back the certificates in the order the server sent them.
The second is renewal that completed without the service being reloaded, so the old certificate is still on the wire. Monitor the expiry of what is being served rather than what is on disk, because those two can differ for weeks without anybody noticing.
For everything below the OV threshold, free SSL is included on every plan here and renews itself before it can lapse. Wildcard and EV certificates are available for the cases that genuinely name them, so escalating later does not mean changing supplier.

Inspect first, purchase second
This page hands you openssl and a Certificate Transparency search because both are free and both settle the question faster than any tier comparison could.
Free SSL ships on every plan and renews automatically; wildcard and EV certificates sit alongside it for the requirements that specifically call for them.
- Subject fields are the real difference
- CT logs make it all public anyway
- EV is paperwork, so schedule it
- Verify the chain, not just the padlock
Why HostingFast
Standard on every plan
Free SSL on every plan
Issued as soon as your domain points here and renewed automatically before it can expire.
Wildcard certificates available
One certificate across every subdomain when staging, development and client hostnames start multiplying.
EV where a policy names it
An EV SSL Certificate is available for the audits and payment flows that genuinely require one.
Escalate without switching supplier
Moving up a validation tier is an order, not a migration, and the hosting underneath is unchanged.
DNS you can edit yourself
Validation records go in from the control panel, so issuance is not blocked behind somebody else's queue.
Hardened underneath the padlock
Imunify360 on the higher plans, account isolation and DDoS filtering at the edge.
Quick Start
From order to online
- 1
Inspect a certificate you already trust
Print the full text of a certificate from a site you consider comparable and read its subject line. If the organisation field is empty, the site you are benchmarking against is on DV and you have your answer.
- 2
Search the Certificate Transparency logs
Look your domain up in a CT viewer and check every certificate ever issued for it. Old certificates you forgot about, and hostnames you did not expect, both show up here.
- 3
Schedule EV like paperwork, not like software
Allow one to three working days, have the registration documents ready and name the person who will take the verification call. Technical readiness is not the constraint on this one.
Built In
Loaded onto every plan
- Free SSL on every plan, renewed automatically before it can expire
- Wildcard SSL Certificate available when subdomain counts grow
- EV SSL Certificate available where a written policy requires it
- DNS records editable from the control panel for validation
- HTTPS end to end, ready for the compliance questions that follow
- Imunify360 shielding sites on the higher plans, ImunifyAV+ on the rest
- LiteSpeed caching in front of PHP on every tier
- NVMe SSD storage across the range, not only the top plans
- Daily backups with self-service restores from the panel
- No setup fee, and a renewal at the rate you ordered at
Frequently Asked
What people ask us most often
How do I read what is actually inside a certificate?
Print its full text with openssl and look at the subject line. A DV certificate carries a common name and no organisation. OV carries a verified organisation name. EV adds jurisdiction and registration number. Everything else about the three tiers is contract and process rather than content.
Will a visitor ever see the OV or EV details in a browser?
Not in the address bar. Chrome, Firefox and Safari all removed the company-name indicator years ago and none of them plan to bring it back. The details are still in the certificate and still visible to anyone who opens it — which in practice means security reviewers and procurement teams, not customers.
How do I check that a certificate chain is complete?
Connect to your own host with openssl and read back every certificate the server presented, in order. A missing intermediate is invisible in most browsers because they cache or fetch it, and highly visible in the clients that do neither. Fix the bundle rather than hoping.
How far ahead should I order EV for a launch date?
Allow one to three working days of verification, and start earlier if your registration details have changed recently. The authority checks legal registration, business address and the signing authority of whoever ordered — none of it technical, all of it capable of stalling a launch.
Keep reading
WordPress.com vs Self-Hosted WordPress
Which of the two WordPress products lets you actually profile a slow page, and which does not.
Hosting for Portfolios With Booking
What a scheduler embed costs a portfolio in milliseconds, and how to claw most of it back.
SSL Validation Levels (DV, OV, EV) (Glossary)
The three validation levels defined precisely, with the fields each one writes into the file.
SSL Certificates
Free SSL on every plan, with wildcard and EV certificates when a requirement names them.
WordPress Hosting
Managed WordPress with LiteSpeed, Redis object caching and staging copies included.
Changing hosts? Run through our checklist first.
A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.
Start with the free one.
Automatic SSL on every plan, wildcard and EV available on order, and DNS you can edit yourself for validation.
View SSL Certificates plans