Client Services
Dv ov ev SSL certificates — Three validation levels, one awkward client conversation
Your client's accountant has told them they need a better certificate, and you have to explain validation levels without either patronising them or overselling.
Straight answer first
Domain validation proves control of the name, organisation validation proves the company exists, and extended validation proves it with a human checking documents — and for the overwhelming majority of client sites the first is all anybody needs, because it is what the included free certificate already provides.
Where the levels genuinely matter to you is scheduling and paperwork. Domain validation is minutes. Extended validation is one to three days and depends on your client finding company documents, which is the part of a launch plan that slips.
Written by the Hosting Seller staff · Checked 24 August 2026
24/7
Cover behind your desk
1-click
Installs for repeat builds
Free
Certificates on every site
Daily
Backups across client accounts
This is a conversation you will have dozens of times, usually started by somebody outside the project — an accountant, a payment provider, a friend who read something. Having a clear, honest script for it saves you an hour each time and makes you look like the professional in the room.
The three levels are not tiers of security. They are tiers of identity checking, and the encryption is identical across all of them. Once a client understands that sentence, most of the conversation is finished.
What each level actually checks
Domain validation checks one thing: that whoever is asking controls the domain name. It is automated, it takes minutes, and it is what the free certificate on every account uses.
Organisation validation adds a check that the company exists and is who it claims to be, using public records. Extended validation goes further, with a defined verification procedure and a human confirming documents, and the checked company name ends up inside the certificate itself.
The encryption is the same in every case. A visitor's connection to a domain-validated site is exactly as private as a connection to an extended-validation one, which is the single most useful fact you can give a worried client.
Who does the paperwork, and what it costs you
For domain validation, nobody does paperwork. For extended validation, your client does — company registration details, a verifiable phone listing, and someone available to answer when the check is made.
Plan for that being slow. The client contact who signed your proposal is often not the person who can produce a company document, and the call-back stage assumes somebody answers a landline. Our team steers the client through each validation step, but no amount of help removes the dependency on their paperwork.
Bill for the coordination. Chasing documents is real work, and quoting the certificate at cost while absorbing three weeks of chasing is a pattern worth breaking early.
Where validation timing wrecks a launch date
A wildcard certificate is domain-validated and usually issued the same day, which means it can sit near the end of a project plan without risk. Extended validation takes one to three days once the client has done their part, and their part is unbounded.
So sequence it early. Start validation at the beginning of a build, not the week of launch, and make the client's document deadline a milestone in your project plan with a name against it.
If a launch date is fixed and validation is uncertain, launch on the included certificate and swap later. The site is fully secure in the meantime, and swapping a certificate is a small job compared with moving a launch.
What we stock, and what to talk a client out of
The shelf carries two paid certificates because those are the two that do something the free one cannot: a wildcard, domain-validated, covering your domain and every subdomain beneath it, installable on as many servers as you like; and an EV certificate carrying a checked company name with a warranty behind it.
A single-domain paid certificate is not advertised, because every plan already includes a free automatically reissuing certificate that does exactly the same job. It can still be issued if a client's procurement process insists on one, which occasionally happens.
Talk clients out of buying identity they do not need, and be specific about the exception. Regulated sectors, and businesses whose own customers are told to check who they are dealing with, are the cases where a checked name inside a certificate is worth the paperwork.

Advice you can repeat to a client
We would rather arm you with an honest explanation than sell you certificates your clients do not need. Free SSL is on every site you host, reissued automatically, and we say so on the product page as well as here.
When a paid certificate is warranted, our team fits it and walks the validation through, so the coordination cost of an EV order does not land entirely on your week.
- Free certificates on every client site
- Wildcard for subdomain-heavy builds
- EV with the checked company name
- Fitting and validation help included
Why Hosting Seller
On every plan, as standard
One script, many conversations
Same encryption, different identity checking — one sentence that ends most certificate arguments before they start.
Free on every account
Domain-validated certificates issued and reissued automatically on every site you host, at every tier.
Subdomains covered once
A wildcard written as *.yourdomain, usually same-day, for builds that create a subdomain per client or per environment.
Identity where it is required
EV certificates carrying a checked company name, backed by a relying-party warranty, issued in one to three days.
Fitted for you
Installation handled at no extra charge, so a client's certificate is not an evening of copying keys between servers.
Reissue as often as needed
Unlimited reissues on the paid certificates, which matters when an estate changes shape more often than a single site does.
First Steps
From choosing to live
- 1
Ask what specifically has to be demonstrated
Encryption, or identity? The answer decides the level, and it is usually the first time anybody has asked the client that question directly.
- 2
Start validation at the beginning of the build
Not the week of launch. Extended validation depends on a client producing documents, and that dependency has no upper bound.
- 3
Name the person who owns the paperwork
Put a name and a date in the project plan. Company documents live with a finance contact, not the marketing contact who briefed you.
- 4
Launch on the free certificate if the date is fixed
The site is fully secure either way. Swapping a certificate later is a small job; moving a launch is not.
In the Box
Packed with every plan
- Free domain-validated SSL on every site you host, reissued automatically
- A wildcard certificate covering your domain and every subdomain beneath it
- Same-day issue in most cases on domain-validated certificates
- EV certificates carrying a checked company name where it is required
- One to three days quoted for extended validation, plus client paperwork
- Installation carried out by our team at no extra charge
- 256-bit encryption on a 2048-bit key across the paid certificates
- Unlimited reissues, and installation on as many servers as you need
- A single-domain certificate available on request for awkward procurement
- Free SSL included on inherited client sites the moment they migrate in
Across the Counter
Things people ask us all the time
A client has been told they need EV for compliance. How do I check?
Ask which requirement, in writing, and from whom. Genuine cases name a regulator or a payment condition and ask for a verified company identity. Vague reassurance is not a requirement, and the included certificate secures the connection identically. Getting this in writing also protects you if the client changes their mind about the cost later.
Who supplies the paperwork for validation, me or the client?
The client, because it is their company being verified — registration details, a verifiable phone listing, and somebody available to take the call. Our team guides each step, but the dependency is theirs. Put a named person and a date in your project plan, because this is where launches slip.
How much time should I allow in a launch plan?
Effectively none for a domain-validated certificate, which is usually issued the same day. One to three days for extended validation once the client's part is done, and their part is unbounded. If the launch date cannot move, start on the included certificate and swap afterwards.
Do OV or EV certificates change anything a visitor can actually see?
Very little in modern browsers, which is worth saying honestly. The verified details are in the certificate for anyone who inspects it, and a site seal can be shown in a footer. If a client is buying visible reassurance for ordinary visitors, they are buying the wrong thing.
Read next
WordPress.com vs Self-Hosted WordPress
Which side of the WordPress split an agency can actually put its name on and bill for.
Hosting for Portfolios With Booking
Booking-led client builds, where a certificate warning on a payment page costs a real booking.
SSL Certificates
Wildcard and EV certificates, fitted and validated for you when a client genuinely needs one.
WordPress Hosting
Managed WordPress accounts to resell, with certificates included on every site you create.
Moving your site to another host? Start with this checklist.
A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.
Give clients the honest answer.
Free certificates on every site you host, plus the wildcard and EV options for the cases that genuinely need them.
See SSL Certificates plans