CA/B Forum Ballot SC-081v3, effective March 15, 2026, reduced the reuse period for Subject Identity Information (SII) from 825 days to 398 days. For EV certificate holders, this means the full Extended Validation process must now repeat approximately every 13 months instead of every 27 months.
EV validation is substantially more intensive than OV validation. Under the CA/B Forum EV Guidelines, each EV certificate requires verification of legal existence, operational existence, physical address, telephone number, and authorized representative identity , steps that go beyond OV requirements. This full process now runs annually. This article quantifies what that means in total cost of ownership terms and identifies which organizations should maintain EV versus switch to OV.
What EV Validation Actually Requires vs OV Validation
EV validation requirements are defined in the CA/B Forum EV Guidelines. The steps that go beyond OV requirements are:
| Validation step | Required for OV? | Required for EV? | Additional EV requirement |
| Verify legal entity name matches registration | Yes | Yes | EV requires specific jurisdictional registration number |
| Verify registered address | Yes | Yes | EV requires address matching government-issued registration document |
| Verify primary phone number in public directory | Yes | Yes | Same |
| Verify operational existence (3+ years OR active website OR bank account) | Sometimes | Yes, always | EV specifically requires operational existence evidence |
| Authorized representative identity verification | No | Yes | CA must verify the person submitting the EV request is an officer or authorized agent of the legal entity. Requires signature or phone verification of named individual. |
| Jurisdiction of incorporation | No | Yes | EV certificate includes jurisdiction data in the Subject field |
| Legal entity type | No | Yes | EV certificate includes organization type (LLC, Corp, etc.) in Subject |
| EV policy OID in certificate | No | Yes | EV certificates contain specific policy OIDs defined in CA/B Forum EV Guidelines that some compliance frameworks check for |
The authorized representative verification is the step that makes EV validation disproportionately more labor-intensive than OV. Someone at the organization , an officer, director, or specifically authorized agent , must personally confirm the certificate request. CAs verify this via callback to a published business number requesting to speak with the named representative, or via a signed authorization letter. This step cannot be automated and cannot be delegated to a generic admin email address.
EV Revalidation Every 13 Months: The Changed Workload
Under the old 825-day SII reuse window, a business that obtained an EV certificate in January 2023 did not need to repeat the full EV validation until April 2025 , approximately 27 months. A senior staff member needed to be available for the authorized representative call or signature once every 27 months.
Under the 398-day SII reuse window effective March 2026, that same validation must now repeat approximately every 13 months. For a business that completed EV validation in January 2025, the next EV revalidation is due approximately February 2026. The one after that: approximately March 2027. Annual, effectively.
The operational impact depends on the organization’s size and administrative capacity:
- Small business with one designated officer: EV requires the officer to be reachable for a CA phone callback or signature once per year. For a solo founder or small practice owner, this is a recurring administrative demand on leadership time.
- Medium business with dedicated IT or compliance function: EV revalidation is part of the annual compliance calendar. Manageable but requires coordinating the authorized representative step annually.
- Large enterprise with CLM platform: EV revalidation is tracked and triggered automatically. The authorized representative step is the only non-automated element.
Unlike the DCV (domain control validation) reuse reduction, the SII reuse reduction does not require near-weekly revalidation in 2029. The 10-day DCV reuse applies to domain validation only. The 398-day SII reuse window for organizational data is the 2026 change, with no further reduction scheduled under SC-081v3. EV’s additional burden is the authorized representative step, not a reduction in the SII window below 398 days.
The Browser Treatment Reality in 2026
The original commercial rationale for EV certificates was the green address bar: browsers displayed the organization’s name in green in the address bar, providing visible proof to users that the site was operated by a verified legal entity. This visual treatment has been removed from every major browser:
- Google Chrome: removed EV green bar treatment in September 2019
- Firefox: removed EV green bar treatment in July 2020
- Safari: removed distinct EV visual treatment in 2020
- Edge: removed EV visual treatment following Chrome’s lead
In June 2026, a visitor to a website secured with an EV certificate sees the identical padlock icon and HTTPS address bar treatment as a site secured with an OV certificate. The only way to see the EV verification details is to click on the certificate and navigate to the certificate details panel, where the EV policy OID and organizational data are visible. No browser presents this information in a way that casual users notice.
The loss of browser visual treatment matters primarily for the original use case: consumer trust at the point of payment or personal data submission. An informed security-conscious user can still verify EV status by inspecting certificate details. But the casual visitor who once saw a green bar now sees nothing different from an OV certificate. The marketing argument for EV , ‘customers see you’re a verified business’ , no longer applies to how the certificate appears in browsers.
EV vs OV Total Cost of Ownership: The Full Calculation
The full cost of an EV certificate is not the purchase price alone. It includes:
- Certificate price: EV from SSL2BUY at $61.60/year (lowest documented authorized reseller EV price, verified June 2026). Sectigo OV from Certera at $49/year for comparison.
- Initial validation time: first-time EV validation typically takes 5-10 business days versus 1-3 business days for OV. The longer timeline reflects the additional authorized representative verification step.
- Annual revalidation time (under 398-day rule): revalidation for existing verified organizations typically takes 1-5 business days. However, the authorized representative step must still be completed, which requires an executive or officer to be available for a callback or signature.
- Administrative overhead: EV revalidation requires preparing or providing evidence of legal existence (government registry, Articles of Incorporation), operational existence (utility bill, bank statement, or equivalent), and identifying the authorized representative by name and title.
| Cost component | OV certificate (Sectigo, Certera) | EV certificate (Sectigo, SSL2BUY) |
| Certificate price | $49/year | $61.60/year |
| Initial validation time | 1-3 business days | 5-10 business days |
| Revalidation frequency (post March 2026) | Once per 13 months | Once per 13 months |
| Revalidation time (existing org, updated) | 1-3 business days | 1-5 business days (plus authorized representative availability) |
| Revalidation requires executive involvement | No: admin staff can complete via D&B or callback | Yes: named officer or authorized representative must be available |
| Visible browser difference from OV | None | None since 2019-2020 |
| Certificate shows organization name | Yes: verified O= field in Subject | Yes: verified O= field plus jurisdiction and entity type |
| EV policy OID in certificate | No | Yes: allows OID-based compliance checking |
| Reseller warranty | $1,000,000 (Sectigo OV) | $1,750,000 (Sectigo EV) |
Who Should Still Buy EV in 2026: The Remaining Use Cases
EV certificates are still appropriate in specific documented circumstances. The question to ask is: does your specific situation require EV by name, or does it require something EV provided (like browser visual treatment) that is no longer available?
Use case 1: Compliance frameworks that explicitly require EV by policy OID
Some regulated sector compliance frameworks and enterprise procurement checklists specify EV certificates by reference to the CA/B Forum EV policy OIDs or the specific EV certificate profile. Banking regulators, payment network compliance requirements, and some government contracting frameworks include explicit EV requirements. If your organization’s compliance documentation specifically requires EV, maintain EV.
Verify this by locating the specific document that requires EV. If the document says ‘EV certificate’ or references specific EV policy OIDs, you are in this category. If the document says ‘valid SSL certificate’ or ‘TLS encryption’ without specifying EV, OV satisfies the requirement.
Use case 2: Enterprise B2B procurement security questionnaires
Some large enterprise customers include certificate validation level in their vendor security assessments. A supplier to a Fortune 500 company may face a security questionnaire that asks whether the supplier’s website uses an EV certificate. If failing this checklist item affects the supplier relationship, EV is worth maintaining for the checklist value.
The practical test: ask your enterprise customer contacts whether EV is required on the questionnaire or simply listed. If required, maintain EV. If listed as a positive signal but not required, OV is typically acceptable.
Use case 3: Specific fintech and financial services contexts
Some payment processing relationships and financial services contexts still specify EV for merchant identity verification, independent of PCI DSS requirements. PCI DSS itself does not require EV; it requires TLS with compliant configuration. But specific acquiring bank relationships, payment network registrations, or financial services firm customer requirements may still specify EV. Verify with the specific counterparty.
Use case 4: Organizations where authorized representative availability is not a constraint
For large organizations with designated security officers, EV revalidation is an annual administrative task that flows through existing compliance processes. If the administrative overhead of EV annual revalidation is not a practical burden, the $12.60/year price premium over Sectigo OV from authorized resellers is negligible and EV’s additional verification rigor is a reasonable security posture choice.
The Case for Switching to OV
For most businesses that are currently on EV but do not fall into the specific documented use cases above, switching to OV at next renewal is the rational decision under the new 398-day revalidation schedule.
OV provides in 2026:
- CA-verified organization name in the certificate Subject field: identical visible result to EV in all browsers
- Structural separation from DV certificate category: 0% of phishing sites use OV (Zscaler 2024)
- CA site seal showing verified organization name
- Equivalent browser trust standing
- Lower annual administrative overhead: no authorized representative step in annual revalidation
- Lower certificate price: $49/year from Certera vs $61.60/year for EV from SSL2BUY
OV does not provide in 2026:
- EV policy OIDs in the certificate (relevant only for OID-based compliance checks)
- Jurisdiction of incorporation and legal entity type in the certificate Subject
- EV warranty ($1,750,000 EV vs $1,000,000 OV)
For organizations buying EV because they believed it would display a green bar or organization name in the browser address bar, OV provides the same visible result at lower price and lower administrative overhead. For organizations buying EV for documented compliance reasons that specifically require EV, continue EV.
When evaluating whether to renew EV or switch to OV: check whether the specific compliance requirement, procurement questionnaire, or contractual obligation that drove the original EV purchase still exists and still specifies EV. Regulations and procurement checklists are often updated, and some EV requirements written before 2019 have been revised since browsers removed EV visual treatment. Locate the current version of any compliance document before renewing on the assumption that EV is required.
Frequently Asked Questions
We are a payment processor. Does PCI DSS 4.0 require EV certificates?
No. PCI DSS 4.0.1 (mandatory March 31, 2025) does not require EV certificates. The PCI DSS TLS requirements specify TLS version, cipher suites, forward secrecy, and certificate inventory documentation. Certificate validation level (DV, OV, EV) is not a PCI DSS requirement. An OV certificate with TLS 1.2 minimum and compliant cipher suites satisfies PCI DSS 4.0 TLS requirements. If a specific acquiring bank or payment network has added an EV requirement in their own documentation beyond PCI DSS, that is a counterparty requirement to verify separately.
We are switching from EV to OV. Does our EV certificate need to be revoked?
No. An EV certificate does not need to be revoked when switching to OV. The EV certificate can run to its natural expiry date. At renewal, purchase an OV certificate instead of EV. Install the OV certificate when it is ready and allow the EV certificate to expire naturally, or replace it immediately upon receipt of the OV certificate. There is no technical benefit to revoking a valid EV certificate early unless the private key has been compromised.
With the 398-day SII reuse, does EV revalidation mean restarting the full application process each time?
Revalidation for an organization already in the CA’s verified database is less intensive than first-time EV validation. The CA has most organizational data on file; the revalidation confirms it is still current rather than starting from scratch. However, the authorized representative step must still be completed annually: the CA must re-confirm that a named officer or authorized agent of the organization is authorizing the continued use of EV certificates. This is the step that distinguishes EV revalidation from OV revalidation. OV revalidation can often complete via automated directory lookup (D&B, Google Business Profile) without any human involvement beyond the CA’s automated checks. EV revalidation cannot.
