EV Detailed Validation Guide

When you purchase an Extended Validation (EV) SSL Certificate from Trustico® you will need to complete a comprehensive validation process before your SSL Certificate can be issued. Extended Validation (EV) SSL Certificates provide the highest level of trust available and require thorough verification of your organization's legal status, operational existence, physical presence, and authority to request the SSL Certificate.

Understanding these requirements in advance helps ensure a smooth validation experience : issuance itself takes only minutes once validation completes, and how quickly validation completes depends on how promptly your organization provides the required information and documents.

Trustico® provides Extended Validation (EV) SSL Certificates through our trusted Certificate Authority (CA) partner. The validation process follows strict guidelines established by the Certificate Authority / Browser Forum (CA/Browser Forum) and is conducted by human validation specialists to confirm your organization's identity and legitimacy.

This page explains each step of the Extended Validation (EV) process and provides guidance on how to prepare your organization for successful validation. Learn About Extended Validation (EV) SSL Certificates 🔗

Understanding Extended Validation (EV)

Extended Validation (EV) SSL Certificates represent the highest standard of identity verification in the SSL Certificate industry. Unlike Domain Validation (DV) or Organization Validation (OV) SSL Certificates, Extended Validation (EV) requires a rigorous verification process that is conducted by human validation specialists rather than automated systems.

This thorough verification ensures that only legitimate, verified organizations can obtain Extended Validation (EV) SSL Certificates.

Extended Validation (EV) SSL Certificates are recommended for any website that collects sensitive information, processes financial transactions, or requires the highest level of customer trust. They have become the industry standard for e-commerce websites and are essential for organizations in banking, finance, healthcare, and government sectors.

The verified organization details are embedded within the SSL Certificate and can be viewed by visitors who inspect the Certificate details, providing transparency and building confidence. Discover Organization Validation (OV) SSL Certificates 🔗

Extended Validation (EV) Requirements Overview

The Extended Validation (EV) process follows Certificate Authority / Browser Forum (CA/Browser Forum) guidelines and consists of multiple verification stages that confirm your organization's legal existence, operational status, physical presence, and the authority of individuals involved in the Certificate request.

All Organization Validation (OV) requirements must be met, plus additional Extended Validation (EV) specific checks are performed by human validation specialists.

Details Being Validated

During the Extended Validation (EV) process, the Certificate Authority (CA) will verify several key aspects of your organization. These include your organization's legal name and confirmation that it is in good standing with the relevant registration authority.

If your organization operates under a trade name or Doing Business As (DBA), this will also be verified through government registration or approved third-party databases.

The validation process confirms the current operators of the business, the operational address where business is conducted, and the primary telephone number listed for the organization. Domain ownership and control must be demonstrated for all domains to be included on the SSL Certificate. Finally, the authenticity of the Subscriber Agreement must be verified through direct contact with the authorized signer.

The Seven-Stage Validation Process

Extended Validation (EV) follows a structured validation process established by the Certificate Authority / Browser Forum (CA/Browser Forum). Each stage must be completed successfully before your Extended Validation (EV) SSL Certificate can be issued. Understanding each stage helps you prepare the necessary information and documentation.

Stage One : Extended Validation (EV) Enrollment Verification

The first stage verifies that the person applying for the Extended Validation (EV) SSL Certificate is an employee of the organization and is authorized to proceed with the Certificate purchase. This helps ensure that SSL Certificate requests are legitimate and have proper organizational approval.

Stage Two : Organization Authentication

The Certificate Authority (CA) verifies through government registration information that your organization is a legally registered entity and is active in the registered location. Verification depends on your organization type. Private organizations include incorporated entities with identifiers such as Inc, LLC, Ltd, Pty Ltd, or GmbH. Government entities include departments of government, public schools, and local government bodies.

Business entities include non-incorporated businesses created by filing with a government authority, such as general partnerships and limited partnerships. Non-commercial entities include international organizations not specifically tied to one country.

It is essential that your organization name on the SSL Certificate order matches your legal registration exactly. Do not enter a trade name or Doing Business As (DBA) as your legal name. Trade names can be included on the Certificate alongside the legal name if properly registered.

Stage Three : Flagged Entity Check

The Certificate Authority (CA) screens your organization against security databases including anti-phishing working group lists, the US Treasury Department denied persons list, and other exclusion lists. Organizations found on these lists will either be denied an Extended Validation (EV) SSL Certificate or require additional validation before issuance.

Stage Four : Operational Existence Verification

The Certificate Authority (CA) must verify that your organization has been in operational existence for at least three years. If your organization has been registered for three years or longer, this is typically verified automatically through government registration records. Organizations registered for less than three years must provide additional documentation to demonstrate operational existence.

Acceptable documentation for newer organizations includes a Dun and Bradstreet listing, a bank confirmation letter verifying that the organization maintains a demand deposit account with a regulated financial institution, or a Legal Opinion Letter from a licensed attorney or Certified Public Accountant (CPA).

Stage Five : Physical Address Verification

The Certificate Authority (CA) verifies that your organization has a genuine physical address in its country of registration. This must be a real business location where operations are conducted. You cannot use a PO Box, mail stop, mail forwarding address, care of address, virtual office address, or registered agent address for Extended Validation (EV) SSL Certificates.

Physical address verification is typically performed through third-party databases such as Dun and Bradstreet. If your address cannot be verified through these sources, you may need to provide supporting documentation or a Legal Opinion Letter.

Stage Six : Telephone Verification

Your organization must have a verified telephone number that is listed in a third-party database or online directory that receives information directly from telecommunications providers. The telephone listing must match your organization name and physical address exactly as verified in previous stages.

If your telephone number cannot be found in public directories, it may be verified through third-party databases such as Dun and Bradstreet or through a Legal Opinion Letter that includes your verified contact details.

Stage Seven : Domain Ownership Verification

You must demonstrate control over all domain names to be included on your Extended Validation (EV) SSL Certificate.

Domain Control Validation (DCV) is completed using one of four methods : e-mail validation using an approved e-mail address associated with your domain, Domain Name System (DNS) validation by adding a specific CNAME record to your domain's zone, Domain Name System (DNS) validation by adding a specific TXT record to your domain's zone, or Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) file-based validation by placing a validation file on your web server.

Trustico® recommends Domain Name System (DNS) validation as it provides the most reliable method for domain verification. It is important to note that WHOIS-based domain validation is no longer accepted as of July 15, 2025. Explore The Validation Procedure 🔗

Contract Signer and Certificate Approver Verification

Extended Validation (EV) SSL Certificates require verification of the individuals authorized to sign agreements and approve SSL Certificate requests on behalf of your organization. This additional verification step helps ensure that only properly authorized personnel can obtain Extended Validation (EV) SSL Certificates for your organization.

Contract Signer Verification

The person who signs the Extended Validation (EV) Subscriber Agreement must be verified as an authorized representative of your organization. If the signer's name appears on government registration documents or in third-party databases such as Dun and Bradstreet, no additional verification may be required.

If further validation is needed, the Certificate Authority (CA) may contact your Human Resources department or another key person listed within the organization to verify the signer's name, title, and authority to sign on behalf of the organization.

Certificate Approver Verification

The Certificate approver and requester are verified through telephone contact with either Human Resources or the contract signer. Having the contract signer, SSL Certificate approver, and SSL Certificate requester as the same person can help accelerate the validation process.

Final Verification Callback

A telephone callback is made to the verified telephone number of your organization to confirm the authenticity of the Subscriber Agreement signature, the authority of the signer to act on behalf of the organization, that the signer is an employee of the organization, and the signer's title within the organization.

An authorized representative must be available to receive this call for the SSL Certificate to be issued.

Required Documents for Extended Validation (EV)

Extended Validation (EV) SSL Certificate orders require the completion of specific documents that must be submitted to the Certificate Authority (CA) for verification.

Extended Validation (EV) Subscriber Agreement

The Extended Validation (EV) Subscriber Agreement is accepted when you place your initial Extended Validation (EV) SSL Certificate request. This agreement is separate from general terms of service and establishes the legal relationship between your organization and the Certificate Authority (CA) regarding the Extended Validation (EV) SSL Certificate.

Certificate Request Form

The Certificate Request Form (CRF) is sent to the requester via e-mail with instructions on how to complete the click-through process. This form captures essential information about your organization and the individuals authorized to request and approve SSL Certificates.

Legal Opinion Letter

In certain circumstances, the Certificate Authority (CA) may require a Legal Opinion Letter signed by a licensed attorney, Latin Notary, or Certified Public Accountant (CPA) to verify your organization's legal name, address, operational existence, and authority of the signing personnel.

A Legal Opinion Letter may be required for organizations registered for less than three years, when government databases are not accessible, when organization details cannot be verified through standard sources, or when you need to expedite the validation process.

The professional signing the Legal Opinion Letter must have a valid license in the jurisdiction where your organization is registered or maintains a physical presence. To expedite verification of the letter, it is helpful if the signing professional speaks English so they can confirm their signature during telephone verification with the validation specialist.

Preparing for Extended Validation (EV)

Thorough preparation before placing your Extended Validation (EV) SSL Certificate order can significantly reduce validation time and help ensure a smooth issuance process. The following guidance will help you prepare your organization's information and documentation.

Verify All Business Registrations

Before ordering your Extended Validation (EV) SSL Certificate, confirm that your organization's registration with all relevant government authorities is current, accurate, and in good standing. This includes your primary business registration, any trade name or Doing Business As (DBA) registrations, and professional licenses if applicable.

Ensure all registration details including business name, address, and registration numbers are accurate and up to date.

Update Third-Party Directory Listings

Ensure your organization is listed in major business directories such as Dun and Bradstreet, Bloomberg, or Hoovers with accurate and complete information. Your listing should include your full legal business name exactly as registered, your physical business address where operations are conducted, and your main business telephone number. Consistent information across all directories makes verification faster and more straightforward.

If your organization is not listed in any business directories, strongly consider creating a Dun and Bradstreet listing before placing your order. This can significantly expedite multiple stages of the Extended Validation (EV) process.

Identify Authorized Personnel

Before placing your order, identify who within your organization will serve as the contract signer, Certificate approver, and Certificate requester. Ensure these individuals are available during business hours to respond to verification requests and telephone callbacks. Having the same person serve in multiple roles can simplify the process.

Prepare Supporting Documentation

If your organization has been registered for less than three years, gather documentation to demonstrate operational existence such as bank statements or Dun and Bradstreet listings. If you anticipate any difficulties with standard verification methods, consider obtaining a Legal Opinion Letter in advance to expedite the process.

Tips for Faster Extended Validation (EV) Issuance

Several factors can help accelerate your Extended Validation (EV) SSL Certificate validation process and reduce the time to issuance.

Use Your Legal Organization Name

Always use your legally registered organization name on the SSL Certificate order, not a trade name or Doing Business As (DBA). If you want to include a trade name on the Certificate, it must be registered with a government agency and will be displayed alongside your legal name.

Use Your Operational Business Address

Provide the physical address where your organization actually conducts business. This address must be verifiable and cannot be a PO Box, virtual office, or mail forwarding service.

Ensure Telephone Accessibility

The verification callback is mandatory and cannot be skipped. Ensure the telephone number provided is actively monitored during business hours and that reception staff are aware they may receive a verification call from the Certificate Authority (CA).

Complete Agreement Forms Accurately

When completing the Extended Validation (EV) Subscriber Agreement and Certificate Request Form, use your real name and professional title. Do not use generic identifiers such as IT Administrator or Webmaster. Accurate completion of these forms can help expedite the verification process.

Respond Promptly to Requests

If the validation team requests additional information or documentation, respond as quickly as possible. Delays in providing requested information extend the overall validation timeline.

Validation Timeline for Extended Validation (EV)

Extended Validation (EV) SSL Certificates are issued within minutes once validation completes : how quickly the verification stages complete depends on your organization providing the required information and documents and on the availability of authorized personnel for callbacks, and pre-validation can reduce the entire process to just a few minutes. Organizations with accurate, up-to-date information in government databases and third-party directories typically experience faster validation.

The timeline may be extended if additional documentation is required, if there are difficulties verifying organization details through standard sources, or if authorized representatives are unavailable for verification callbacks. Trustico® provides order tracking through the Trustico® tracking system, where you can monitor the validation progress and see which stages have been completed. View Our SSL Certificate Order Tracking 🔗

Organizations That Qualify for Extended Validation (EV)

Extended Validation (EV) SSL Certificates are available to legally registered organizations that can demonstrate legal, operational, and physical existence. Eligible organization types include private organizations such as corporations, limited liability companies, and other incorporated entities, government entities including federal, state, and local government bodies and public institutions, and business entities that are non-incorporated but have official government registration.

Extended Validation (EV) SSL Certificates are generally not available to individuals unless they operate as a registered sole proprietor or have a registered small business. Some sole proprietors may qualify depending on their jurisdiction's registration requirements.

Getting Help with Extended Validation (EV)

If you experience any difficulties with the Extended Validation (EV) process or have questions about the requirements, Trustico® support is available to assist you. Our team can provide guidance on preparing your documentation, help resolve validation issues, and liaise with the Certificate Authority (CA) validation team on your behalf.

Trustico® is committed to ensuring your Extended Validation (EV) SSL Certificate is issued efficiently while maintaining the rigorous security standards that make Extended Validation (EV) the highest trust level available.

By preparing your information thoroughly, ensuring authorized personnel are available, and responding promptly to any requests for additional information, you can help ensure a smooth and successful validation experience. Explore Trustico® Support Options 🔗

Most Popular Questions

Frequently asked questions covering the Extended Validation (EV) process, including the seven validation stages, organization eligibility, accepted address types, operational existence requirements, Legal Opinion Letters, required documents, and how to prepare for faster issuance.

Extended Validation (EV) and Its Additional Verification

Extended Validation (EV) represents the highest standard of identity verification in the SSL Certificate industry. Unlike Domain Validation or Organization Validation SSL Certificates, EV requires rigorous verification by human validation specialists rather than automated systems, ensuring only legitimate, verified organizations can obtain EV SSL Certificates.

Validation and Issuance Timing for Extended Validation (EV) SSL Certificates

Issuance takes only minutes once validation is complete, so the timing of an Extended Validation (EV) order depends on the validation stages rather than on issuance. How quickly those stages complete depends on the customer providing the required information and documents, and on authorized representatives being available for the verification callback. An organization that has already been validated keeps that standing for up to three years, leaving Domain Control Validation (DCV) as the only remaining requirement.

The Seven Stages of Extended Validation (EV)

The seven stages are : Extended Validation (EV) Enrollment Verification, Organization Authentication, Flagged Entity Check, Operational Existence Verification, Physical Address Verification, Telephone Verification, and Domain Ownership Verification. Each stage must be completed successfully before your EV SSL Certificate can be issued.

Organization Types That Qualify for Extended Validation (EV)

Eligible organization types include private organizations such as corporations and limited liability companies, government entities including federal, state, and local government bodies, and business entities that are non-incorporated but have official government registration. Extended Validation (EV) SSL Certificates are generally not available to individuals unless they operate as a registered sole proprietor.

Address Types Not Accepted for Extended Validation (EV)

You cannot use a PO Box, mail stop, mail forwarding address, care of address, virtual office address, or registered agent address for Extended Validation SSL Certificates. You must provide a genuine physical business address where your organization actually conducts operations.

Requirements for Organizations Registered Less Than Three Years

Organizations registered for less than three years must provide additional documentation to demonstrate operational existence. Acceptable documentation includes a Dun and Bradstreet listing, a bank confirmation letter verifying a demand deposit account with a regulated financial institution, or a Legal Opinion Letter from a licensed attorney or Certified Public Accountant.

The Legal Opinion Letter and When It Applies

A Legal Opinion Letter is a document signed by a licensed attorney, Latin Notary, or Certified Public Accountant to verify your organization's legal name, address, operational existence, and authority of signing personnel. It may be required for organizations registered for less than three years, when government databases are not accessible, or when organization details cannot be verified through standard sources.

Personnel Required to Be Available During Validation

You must identify a contract signer, Certificate approver, and Certificate requester who are available during business hours to respond to verification requests and telephone callbacks. Having the same person serve in multiple roles can simplify and accelerate the validation process.

The Mandatory Final Verification Callback

The final verification callback is a mandatory telephone call made to your organization's verified telephone number. It confirms the authenticity of the Subscriber Agreement signature, the authority of the signer, and their employment status and title. This callback cannot be skipped, and an authorized representative must be available to receive the call.

Using Your Legal Business Name Rather Than a Trade Name

Always use your legally registered organization name on the SSL Certificate order, not a trade name or Doing Business As (DBA). If you want to include a trade name on the SSL Certificate, it must be registered with a government agency and will be displayed alongside your legal name.

Preparing Your Organization for Faster Validation

To expedite validation, ensure your organization's registration is current and in good standing, and update your listings in third-party directories like Dun and Bradstreet with accurate information. It also helps to identify authorized personnel in advance and prepare supporting documentation if your organization is less than three years old.

Domain Control Validation (DCV) Methods for Extended Validation (EV)

Domain Control Validation can be completed using e-mail validation with an approved e-mail address, Domain Name System (DNS) validation by adding a specific CNAME record to your domain's zone, or Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) file-based validation by placing a validation file on your web server. Trustico® recommends DNS validation as it provides the most reliable method. Note that WHOIS-based validation is no longer accepted as of July 15, 2025.

Screening Against Security Exclusion Lists

During Stage Three (Flagged Entity Check), the Certificate Authority screens your organization against security databases including Anti-Phishing Working Group lists and the US Treasury Department denied persons list. Organizations found on these lists will either be denied an Extended Validation SSL Certificate or require additional validation before issuance.

Tracking the Progress of Your Extended Validation (EV) Order

Trustico® provides order tracking in the tracking system, where you can monitor the validation progress and see which stages have been completed. This allows you to stay informed throughout the validation process and respond quickly to any requests for additional information.

Documents Required for an Extended Validation (EV) Order

Required documents include the Extended Validation (EV) Subscriber Agreement, which is accepted when you place your initial order, and the Certificate Request Form, which is sent via e-mail with instructions for completion. In certain circumstances, a Legal Opinion Letter may also be required to verify organization details and authority of signing personnel.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6