Every SSL certificate encrypts the connection between your website and your visitors. But there are important differences in how the identity of the website owner is verified. There are three types of SSL certificates: Domain Validation (DV), Organization Validation (OV) and Extended Validation (EV). In this article we explain what each type entails and which certificate you need.

What exactly does an SSL certificate do?

An SSL certificate does two things. First, it encrypts all data exchanged between your visitor's browser and your web server. Passwords, form data and payment information are therefore not readable by third parties. Second, it confirms the identity of your website: visitors know that they are actually communicating with your server and not with a fake website.

The difference between DV, OV and EV lies in that second point: how thoroughly the identity is checked before the certificate is issued.

Domain Validation (DV): the basics

What is a DV certificate?

A DV certificate is the most basic type of SSL certificate. The certificate issuer only checks whether you are the owner of the domain. This usually happens by replying to a verification email, adding a DNS record or placing a file on your server. The whole validation usually takes less than five minutes.

What is in the certificate?

Only the domain name. No company name, no address, no other organisation details. When a visitor clicks the padlock in the address bar, they only see the domain and the name of the certificate issuer.

Cost of a DV certificate

Free through Let's Encrypt or ZeroSSL, or around 10 to 50 euros per year with commercial providers. The encryption is technically identical to more expensive certificate types. There is no difference in the strength of the encryption.

When do you choose DV?

  • Blogs and personal websites
  • Small business websites without online payments
  • Test environments and development servers
  • Internal company tools and applications

Organization Validation (OV): the business standard

What is an OV certificate?

With an OV certificate the certificate issuer checks not only the domain, but also the organisation behind it. They verify that your company actually exists and that you are authorised to request a certificate. This happens through verification of business registration details, telephone confirmation or written documentation.

What is in the certificate?

The domain name plus the full company name, location and country. Visitors who view the certificate by clicking the padlock see that it belongs to a verified company. This gives extra trust, especially in business transactions.

Cost of an OV certificate

Around 50 to 200 euros per year. The validation process takes 1 to 3 working days because the certificate issuer has to check your organisation manually.

When do you choose OV?

  • Business websites and company portals
  • Online stores and e-commerce platforms with direct payments
  • SaaS applications that process customer data
  • Government websites and educational institutions

Extended Validation (EV): the highest standard

What is an EV certificate?

EV is the strictest validation level available. The certificate issuer carries out an extensive check of your organisation. This includes verification of the legal existence of your company, the physical address, the operational status and the identity of the contact person. The whole process usually takes 1 to 2 weeks.

What is in the certificate?

All organisation details including the officially registered company name and the jurisdiction. Browsers used to show the company name in a green bar next to the URL, but this has now been abolished in most browsers. The extensive details are still visible if you click the padlock and view the certificate.

Cost of an EV certificate

Around 100 to 500 euros per year. The extensive validation procedure and the higher trust level justify the higher price for organisations that need it.

When do you choose EV?

  • Banks and financial institutions
  • Large e-commerce platforms with high transaction volumes
  • Insurers and healthcare providers that process medical data
  • Organisations that want to convey maximum trust to their customers

The three types compared side by side

The most important differences at a glance:

  • Encryption: identical for all three. DV, OV and EV use exactly the same encryption algorithms and key strengths.
  • Validation time: DV in minutes, OV in 1 to 3 working days, EV in 1 to 2 weeks.
  • Organisation name in certificate: no with DV, yes with OV and EV.
  • Cost per year: DV free to 50 euros, OV 50 to 200 euros, EV 100 to 500 euros.
  • SEO advantage: no difference. Google makes no distinction between DV, OV and EV certificates in the search results.

Wildcard and multi-domain certificates

Besides the validation level, you can also choose special certificate types that cover multiple domains or subdomains:

Wildcard SSL certificate

A wildcard certificate covers your main domain and all subdomains on a single level. Handy if you use multiple subdomains, such as shop.example.com, mail.example.com and blog.example.com. Available as DV or OV, not as EV.

Multi-domain (SAN) SSL certificate

A multi-domain certificate covers multiple completely different domain names in a single certificate. Ideal if you manage multiple websites and want to secure them with a single certificate. Available as DV, OV or EV.

Frequently asked questions about types of SSL certificates

Is a free DV certificate less secure than a paid certificate?

No. The encryption is identical. A free Let's Encrypt certificate uses the same encryption as a 500-euro certificate. The difference lies only in the identity verification, not in the security of the connection.

Does an EV certificate still make sense now that browsers no longer show the green bar?

The visual advantage has indeed become smaller. But the extensive verification still has value for organisations that have to meet compliance requirements or that want to offer extra trust to customers who check the certificate manually.

Which type does an average online store choose?

Most small to medium online stores use a DV certificate, often free through Let's Encrypt. This offers sufficient security for the connection. Larger online stores and platforms sometimes choose OV to show their company name in the certificate.

Our recommendation

For most websites a free DV certificate from Let's Encrypt is the best choice. The encryption is identical to more expensive options, installation is simple and renewal happens automatically. Only invest in an OV or EV certificate if your organisation specifically benefits, for example because of compliance or business trust.

At Theory7 you get a free SSL certificate with every hosting plan, installed and renewed automatically. This way your website is always secured without extra costs or effort.

Choosing an SSL certificate: step-by-step plan

Are you unsure which of the three types of SSL certificates best suits your website? Work through this short step-by-step plan to reach the right choice:

Step 1: determine the type of website

Do you have a blog, portfolio or information website without transactions? A free DV certificate is enough. Do you have an online store, SaaS platform or business application? Consider OV or EV, depending on the size and type of customer.

Step 2: determine your budget

With a budget of zero euros you choose Let's Encrypt (DV). This is no compromise on security: the encryption is identical. Do you have a budget of 50 to 200 euros per year and do you want your company name in the certificate? Then OV is a good investment. Only with specific compliance requirements or if your organisation wants to convey maximum trust is EV worth it.

Step 3: check compliance requirements

Some sectors set requirements for the type of certificate. Financial institutions and healthcare providers sometimes have to demonstrably use an OV or EV certificate. Check the regulations in your industry before you make a choice.

Installing an SSL certificate at Theory7

At Theory7 a free Let's Encrypt DV certificate is included as standard with every hosting plan. The certificate is installed automatically when you connect your domain and is renewed automatically every 90 days. You do not have to do anything for this.

Do you want to use an OV or EV certificate? Then you can purchase a certificate from a certificate issuer of your choice and install it through DirectAdmin. Our support team is happy to help you with the installation and configuration. All you need is the certificate file, the private key and any intermediate certificates.

Common mistakes when choosing an SSL certificate

When choosing between the different types of SSL certificates, we regularly see the same mistakes:

  • Paying for DV while Let's Encrypt is free: some hosting providers sell DV certificates for 30 to 50 euros per year, while Let's Encrypt offers exactly the same security for zero euros. Only pay if you specifically need OV or EV validation.
  • Buying EV for a small online store: the investment of 200 to 500 euros per year cannot be justified for most SMB online stores. The green bar has been abolished in browsers and your customers do not notice the difference.
  • Not renewing the certificate: the most important thing is not which type you choose, but that it stays valid. Set up automatic renewal or put a reminder in your calendar.
  • No redirect from HTTP to HTTPS: even with the best certificate your site is not fully secured if visitors can still enter over HTTP.

Summary: choosing the right type

The three types of SSL certificates all offer the same strong encryption. The difference lies solely in the way your identity as a website owner is verified. For the vast majority of websites a free DV certificate is the right choice: you get the same security as a certificate costing hundreds of euros per year.

Only invest in OV or EV if your organisation demonstrably benefits, for example because of compliance requirements, business trust or if your customers specifically ask for organisation verification. In all other cases Let's Encrypt is the wisest choice. At Theory7 you get this certificate free and automatically with every hosting plan, so that your website is always secured without extra costs or maintenance.

With the right knowledge about the different types of SSL certificates you make a well-considered choice. Whether you run a personal blog or manage a large online store: there is always a certificate type that suits your situation and budget. The three types of SSL certificates each offer a different level of identity verification, but the encryption is always equally strong.

Frequently asked questions about types of SSL certificates

Which types of SSL certificates are free?

Only DV certificates are available for free through Let's Encrypt. OV and EV certificates require manual verification by a certificate authority and therefore always cost money. Prices vary from 50 euros per year for OV to more than 200 euros per year for EV.

Which of the three types of SSL certificates is the most secure?

All types of SSL certificates offer exactly the same 256-bit encryption. There is no difference in the technical security of the connection. The difference lies solely in how much information about the owner of the certificate is verified and displayed. A DV certificate is therefore just as secure as an EV certificate in terms of the data connection.

Can I upgrade to another type of certificate?

Yes, you can switch to another type at any time. If you now have a DV certificate and want to upgrade to OV or EV, you simply request a new certificate from a certificate authority. The switch requires no technical changes to your website, only the installation of the new certificate on your server. So you can always reconsider the choice between the different types of SSL certificates if your needs change.