If you received an email from your CA or reseller asking you to reverify your organization’s information for your SSL certificate, this is expected, legitimate, and not a sign of any problem with your certificate. A CA/B Forum rule change effective March 2026 reduced the period for which organization validation data can be reused from approximately 27 months to approximately 13 months. Your certificate is fine; the organizational data on file with the CA simply needs to be refreshed.
This article explains what changed, what the reverification process actually involves, and how to complete it as quickly as possible.
What Changed and Why
When a business purchases an OV (Organization Validation) SSL certificate, the Certificate Authority verifies the legal business name, registered address, and primary phone number before issuing the certificate. This verified organizational data is stored by the CA and can be reused to issue subsequent certificates without re-verifying the same information.
Under the old rule, this organizational data could be reused for 825 days , approximately 27 months. A business that went through OV verification in January 2024 would not have needed to repeat the process until April 2026 under the old rule.
CA/B Forum Ballot SC-081v3, passed April 2025, reduced the Subject Identity Information (SII) reuse period from 825 days to 398 days , approximately 13 months. DigiCert implemented this change on February 24, 2026. Sectigo and other major CAs implemented it on or around the same date. Starting in early 2026, OV certificates now require organizational data reverification roughly once per year instead of once every two-plus years.
The 398-day reuse window applies to the organization’s verified data, not to the certificate itself. If your certificate was issued before the new rule took effect and is still within its validity period, it continues to work normally. The reverification requirement affects your ability to issue new OV certificates from the same CA using the same organizational data. Your existing certificate will not be revoked due to the organizational data expiring.
What the Change Means Practically
| Old rule (before March 2026) | New rule (March 2026 onward) | |
| Organization validation reuse period | 825 days (~27 months) | 398 days (~13 months) |
| Reverification frequency | Roughly once every 2 years | Roughly once per year |
| Impact on existing certificates | None: existing certificates remain valid until expiry | None: existing certificates remain valid until expiry |
| Impact on issuing new OV certificates | Can reuse validation data for up to 27 months | Must reverify if organizational data is older than 13 months |
| EV certificate validation reuse | Also 825 days (~27 months) | Also reduced to 398 days (~13 months) |
What Organization Reverification Actually Involves
OV reverification confirms that the organizational information the CA has on file is still current and accurate. It is significantly less intensive than first-time OV validation. For most businesses, it confirms the same information that was verified originally: legal entity name, registered business address, and a main business phone number that can be found in a public directory.
The CA’s reverification request typically involves one of the following:
- Automated callback: the CA calls the business phone number on file (or a phone number the CA can independently verify in a business directory) and plays an automated message. A representative confirms by pressing a key. This is the fastest reverification method when the business phone number is verifiable in D&B, Google Business Profile, or a state business registry.
- Document submission: the CA asks for a current document proving the business name and address, such as a filed annual report, business license, utility bill in the business name, or government registration document.
- Third-party directory verification: the CA uses an automated lookup against Dun and Bradstreet (D&B), Hoovers, or similar business directories. If the business information in the CA’s records matches what appears in the directory, verification may complete automatically without any action from the business owner.
The typical timeline for OV reverification is 1 to 3 business days when the business information is current and publicly verifiable. It can take up to 5 business days if documents need to be submitted and reviewed manually.
The fastest reverification outcome comes from a current Dun and Bradstreet DUNS listing that matches the organizational information the CA has on file exactly: same legal entity name (including LLC, Inc., or other entity suffix), same registered address, and a phone number that appears on the D&B record. Update your D&B listing (free at dnb.com) 48-72 hours before responding to the CA’s reverification request. A matching D&B record often allows the CA to complete verification automatically within hours.
Your Certificate Is Fine: Understanding What Is and Is Not Expiring
Two separate timers govern an OV certificate:
- Certificate validity period: the certificate itself has an expiry date shown in the certificate details. This is currently up to 199 days for newly issued certificates. When this expires, the padlock stops working and visitors see an SSL error. The certificate validity period has not changed due to the organizational data reuse reduction.
- Organizational validation data reuse period: the CA’s record of your verified organization information. When this period expires (now 398 days under the new rule), the CA can no longer issue new certificates for your organization until the data is reverified. Your existing certificate keeps working normally until its own expiry date.
A business that received a reverification request while their current OV certificate is still valid should complete the reverification to restore their ability to issue new certificates, but there is no urgency from the perspective of the current certificate’s operation. The website stays secure. The certificate keeps working.
The verification request you received is about the next certificate issuance, not about your current certificate. Think of it as renewing a business registration: the current registration document is valid until its expiry date, but the underlying records need periodic refreshing to maintain the ability to renew. Your site’s SSL continues working normally throughout the reverification process.
How to Complete OV Reverification: Step by Step
- Locate the reverification email or notice from your CA or reseller. It will include a reference number or order identifier for the verification request.
- Confirm your D&B listing is current: search dnb.com for your business. Verify that the company name, address, and phone number match what you submitted for the original OV certificate. If anything differs (a moved office address, a changed phone number, a business name update), update D&B first and wait 48 hours before proceeding.
- Confirm your Google Business Profile is current: Google Business Profile is a common QIIS (Qualified Independent Information Source) that CAs use for automated verification. Check that your profile shows the correct business name, current address, and current phone number.
- Respond to the CA’s verification request: depending on the CA’s process, this may involve clicking a link in the verification email, providing a phone number for an automated callback, or uploading a current business document.
- Wait for confirmation: once the CA confirms successful reverification, you receive a notification. Your ability to issue new OV certificates under the same organizational data is restored for another 398 days.
If the Reverification Process Is Frustrating: This Is a Good Time to Evaluate Resellers
The 398-day organizational reuse period means OV certificate customers will now interact with their CA or reseller’s reverification process approximately once per year instead of once every two years. For businesses whose current CA or reseller has a cumbersome, poorly documented, or slow reverification process, the new annual cadence is a genuine reason to consider switching at next renewal.
What differs between resellers on OV reverification:
- Communication quality: the reverification request email should clearly explain what is needed, why, and how long it takes. Some resellers’ communications are clear and link to specific instructions; others are confusingly worded.
- Process documentation: good resellers maintain current knowledge base articles explaining exactly what documents are accepted for OV verification and exactly what the automated callback process involves. Check whether the reseller you are evaluating has this documentation before purchasing.
- Support responsiveness: when a reverification step fails or a document is rejected, response time matters. A reseller with phone support (like Certera) resolves issues faster than one with email-only support.
- D&B and directory integration: resellers using automated directory lookup rather than manual document review complete reverification faster for businesses with current D&B or Google Business records.
The certificate itself is identical across authorized Sectigo resellers. The verification process experience varies. Under the new annual revalidation cadence, the verification experience is part of the annual value a reseller delivers.
Frequently Asked Questions
I just went through OV verification six months ago. Why am I getting this request again?
If you received an OV reverification request within 13 months of your previous verification, one of three things has likely happened: first, your previous verification was conducted before the March 2026 rule change, and the CA is applying the new 398-day limit retroactively to all organizational data on file, including pre-existing verifications that were established under the old 825-day rule. Second, your organization’s information in the CA’s records may have been flagged as requiring update (for example, if a D&B record shows a different address than the CA has on file). Third, the reseller’s notification may be proactive , sent before the actual expiry to give you time to reverify without any lapse in your ability to issue certificates. Contact your reseller to confirm which situation applies.
Does this affect multi-year OV certificate subscriptions?
Yes. If you purchased a 3-year OV certificate subscription from an authorized reseller, the subscription covers the cost of multiple certificate issuances over 3 years. Under the new 398-day organizational data reuse rule, you will need to complete organizational reverification approximately twice during a 3-year subscription term (once per year). The reverification itself does not cost anything additional; it is a process step, not a purchase. The reseller’s support team should guide you through the reverification when it comes due.
I am a sole trader or single-person business. What documents are typically accepted for OV verification?
For sole traders and single-person businesses, the CA’s primary need is to verify that the business entity named in the certificate is real and currently active. Accepted documentation typically includes: a current business registration or DBA (Doing Business As) registration from a state or local government; a professional license in the business name; a business bank account statement showing the entity name and address; or a utility bill in the business name at the registered address. Google Business Profile with the business name and phone number is accepted as a QIIS by most CAs and often allows automated verification without document submission. Ensure your Google Business Profile is verified and current before submitting the reverification request.
