TLS & PKI

What is Extended Validation?

Also known as: EV

Definition

Extended Validation (EV) is the highest level of TLS certificate assurance, requiring the certificate authority to perform rigorous, human-verified checks on the legal identity and operational existence of the requesting organization before issuance.

Extended Validation (EV) is a type of X.509 TLS certificate defined by the CA/Browser Forum Baseline Requirements. It demands the most thorough identity vetting process of any publicly trusted certificate class. Before issuing an EV certificate, the certificate authority must confirm the legal status of the organization, its physical address, operational existence, and that the individual requesting the certificate holds authority to bind the organization. These checks are performed against government registries and other authoritative sources, with human review of every step.

When a website presents an EV certificate in the past, browsers formerly displayed the legal entity name in the address bar (often in green), along with the certificate chain indicator. Starting around 2019, browsers like Chrome and Firefox removed this special UI treatment, citing low user understanding and diminishing security benefit relative to other validation types. The underlying validation process remains stricter than Organization Validation (OV) or Domain Validation (DV). However, EV does not provide stronger cryptographic protection; it only represents a higher standard of identity assurance. An EV certificate uses the same X.509v3 format and key sizes as other certificates.

EV certificates are still used by financial institutions, government agencies, and other high-stakes online services where proving legal identity to users or systems carries compliance or contractual weight. The CA/Browser Forum maintains the EV Guidelines as a separate document within its Baseline Requirements framework. Revocation checks for EV certificates follow the same OCSP and CRL mechanisms as other public TLS certificates. EV does not replace code signing or S/MIME certificate classes, which have their own Extended Validation variants (EV Code Signing and EV S/MIME).

Key facts

  • Defined by CA/Browser Forum EV Guidelines, a superset of Baseline Requirements.
  • Requires human verification of legal entity name, address, and registration number.
  • Browsers removed prominent UI indicators for EV certificates starting in 2019.
  • EV does not change cryptographic key strength or TLS protocol security.
  • EV certificates are valid for a maximum of 27 months under current Baseline Requirements.

How it works in practice

A large online bank applies for an EV certificate for its login page. The CA requests articles of incorporation, a utility bill, and a notarized letter from the bank's VP of IT. After 3 business days of manual checks, the CA issues the certificate. Before 2019, users saw 'Great Northern Bank, Inc.' in green next to the lock icon. After the UI change, the bank shows the same lock icon as any other HTTPS site, but its certificate indicates Extended Validation in the policy OID 2.23.140.1.1.

Related terms

Domain Validation Organization Validation Certificate Authority CA/Browser Forum Baseline Requirements X.509

References

More in TLS & PKI

ACME Protocol

ACME (Automated Certificate Management Environment) is a protocol that automates the issuance, renewal, and revocation of TLS certificates, defined in RFC 8555.

Certificate Authority

A Certificate Authority (CA) is a trusted entity that issues digital certificates after verifying that the requester controls the domain or identity named in the certificate.

Certificate Chain

A certificate chain is an ordered list of certificates, starting with the server certificate and ending with a root CA, that a client validates to establish trust in the server's identity.

Certificate Pinning

A security technique where an application trusts only a specific, pre-selected certificate or public key for a given server, bypassing the standard chain of trust.

Cipher Suite

A cipher suite is a named set of cryptographic algorithms negotiated during a TLS handshake, specifying key exchange, authentication, encryption, and integrity protection for secure communications.

Domain Validation

Domain Validation (DV) is the lowest level of certificate validation used in TLS/SSL, where the certificate authority verifies only that the applicant controls the domain name, typically via an HTTP or DNS challenge.

ECH

Encrypted Client Hello (ECH) is a TLS extension that encrypts the Client Hello message, including the Server Name Indication (SNI), to prevent on-path observers from learning the target hostname during the handshake.

HSTS

HTTP Strict Transport Security (HSTS) is a web security policy mechanism that forces browsers to interact with a website only over HTTPS, preventing downgrade attacks and cookie hijacking.

Intermediate Certificate

An intermediate certificate is a subordinate CA certificate signed by a root CA, used to sign end-entity certificates and enable path validation while the root remains offline.

Let's Encrypt

Let's Encrypt is a free, automated, public certificate authority operated by the Internet Security Research Group (ISRG) that issues short-lived Domain Validation (DV) TLS certificates via the ACME protocol.

Who Is Online

In total there are 60 users online: 0 registered, 53 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369