GeoTrust DV SSL — quick domain-validated certificate from a long-established brand
GeoTrust is a long-established commercial CA brand, now part of the DigiCert family of roots. GeoTrust DV SSL is the no-frills domain-validated option: confirm you control the domain, get the certificate, ship.
What you get
Issued from GeoTrust roots (chained into DigiCert), trusted by every modern browser and OS
Domain Validation only — no company paperwork required
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the GeoTrust brand but only need domain-level validation
Sites that have outgrown free Let's Encrypt for support / warranty reasons but don't need OV/EV
Mid-tier blogs, marketing sites, light-traffic e-commerce on a known CA
Issuance time
A few minutes to a few hours after DNS or HTTP validation completes.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
GeoTrust DV SSL — quick domain-validated certificate from a long-established brand
GeoTrust is a long-established commercial CA brand, now part of the DigiCert family of roots. GeoTrust DV SSL is the no-frills domain-validated option: confirm you control the domain, get the certificate, ship.
What you get
Issued from GeoTrust roots (chained into DigiCert), trusted by every modern browser and OS
Domain Validation only — no company paperwork required
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the GeoTrust brand but only need domain-level validation
Sites that have outgrown free Let's Encrypt for support / warranty reasons but don't need OV/EV
Mid-tier blogs, marketing sites, light-traffic e-commerce on a known CA
Issuance time
A few minutes to a few hours after DNS or HTTP validation completes.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
GeoTrust DV SSL — quick domain-validated certificate from a long-established brand
GeoTrust is a long-established commercial CA brand, now part of the DigiCert family of roots. GeoTrust DV SSL is the no-frills domain-validated option: confirm you control the domain, get the certificate, ship.
What you get
Issued from GeoTrust roots (chained into DigiCert), trusted by every modern browser and OS
Domain Validation only — no company paperwork required
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the GeoTrust brand but only need domain-level validation
Sites that have outgrown free Let's Encrypt for support / warranty reasons but don't need OV/EV
Mid-tier blogs, marketing sites, light-traffic e-commerce on a known CA
Issuance time
A few minutes to a few hours after DNS or HTTP validation completes.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
RapidSSL is a long-running DigiCert-family DV brand, purpose-built for fast automated issuance with minimal fuss. Domain validation only — confirm you control the domain, certificate ships in minutes.
What you get
Issued from RapidSSL / DigiCert root chain, universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
RapidSSL warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Personal projects, side projects, marketing landing pages
Staging and pre-production where you want a real CA cert without the runtime cost of OV/EV
Bulk site operators who need a known brand at the lowest tier
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
RapidSSL is a long-running DigiCert-family DV brand, purpose-built for fast automated issuance with minimal fuss. Domain validation only — confirm you control the domain, certificate ships in minutes.
What you get
Issued from RapidSSL / DigiCert root chain, universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
RapidSSL warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Personal projects, side projects, marketing landing pages
Staging and pre-production where you want a real CA cert without the runtime cost of OV/EV
Bulk site operators who need a known brand at the lowest tier
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Sectigo ACME (DV) — automated DV via ACME protocol
The same Sectigo DV trust chain, but issued over the standard ACME protocol — the same automation used by Let's Encrypt clients (certbot, acme.sh, Caddy, Traefik, Kubernetes cert-manager). Drop-in commercial replacement when you need support, warranty or longer validity from a paid CA but want to keep your existing ACME automation.
Sectigo EssentialSSL — entry-tier DV with Sectigo trust seal
EssentialSSL is Sectigo's entry DV line with the Sectigo dynamic Trust Logo. Same root trust as PositiveSSL with the Sectigo seal-served-from-Sectigo branding option.
What you get
Sectigo DV issuance, universally trusted
Sectigo dynamic Trust Logo (served from Sectigo infrastructure)
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Small business that wants a visible trust seal on the site
DV use cases where the Sectigo brand on the cert matters slightly more than PositiveSSL
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Sectigo EssentialSSL — entry-tier DV with Sectigo trust seal
EssentialSSL is Sectigo's entry DV line with the Sectigo dynamic Trust Logo. Same root trust as PositiveSSL with the Sectigo seal-served-from-Sectigo branding option.
What you get
Sectigo DV issuance, universally trusted
Sectigo dynamic Trust Logo (served from Sectigo infrastructure)
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Small business that wants a visible trust seal on the site
DV use cases where the Sectigo brand on the cert matters slightly more than PositiveSSL
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Sectigo PositiveSSL — most popular DV line on the internet
Sectigo (formerly Comodo CA) is one of the most-issued commercial CA brands worldwide. PositiveSSL is its high-volume DV line — quick automated issuance from a root that's been in browsers for two decades.
What you get
Issued from Sectigo / Comodo roots, universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Anyone who wants the most widely-used commercial DV at a budget price
Replacing free DV when you want support, warranty and a clear revocation path
Sites with mixed visitor pools (older devices, embedded clients) — Sectigo roots have very long-tail trust coverage
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Sectigo PositiveSSL — most popular DV line on the internet
Sectigo (formerly Comodo CA) is one of the most-issued commercial CA brands worldwide. PositiveSSL is its high-volume DV line — quick automated issuance from a root that's been in browsers for two decades.
What you get
Issued from Sectigo / Comodo roots, universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Anyone who wants the most widely-used commercial DV at a budget price
Replacing free DV when you want support, warranty and a clear revocation path
Sites with mixed visitor pools (older devices, embedded clients) — Sectigo roots have very long-tail trust coverage
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
Sectigo PositiveSSL — most popular DV line on the internet
Sectigo (formerly Comodo CA) is one of the most-issued commercial CA brands worldwide. PositiveSSL is its high-volume DV line — quick automated issuance from a root that's been in browsers for two decades.
What you get
Issued from Sectigo / Comodo roots, universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Anyone who wants the most widely-used commercial DV at a budget price
Replacing free DV when you want support, warranty and a clear revocation path
Sites with mixed visitor pools (older devices, embedded clients) — Sectigo roots have very long-tail trust coverage
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Thawte SSL123 — DV from one of the oldest CA brands
Thawte is one of the oldest certificate authority brands in the industry (founded 1995, now part of DigiCert). SSL123 is its modern DV line — automated domain validation, fast issuance, Thawte name on the certificate.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Customers who specifically want the Thawte brand on their certificate
Sites where the Thawte name has historical recognition (legacy enterprise, finance, .za and ZA-anchored audiences)
DV use cases that need a name with three decades of brand recognition
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Thawte SSL123 — DV from one of the oldest CA brands
Thawte is one of the oldest certificate authority brands in the industry (founded 1995, now part of DigiCert). SSL123 is its modern DV line — automated domain validation, fast issuance, Thawte name on the certificate.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Customers who specifically want the Thawte brand on their certificate
Sites where the Thawte name has historical recognition (legacy enterprise, finance, .za and ZA-anchored audiences)
DV use cases that need a name with three decades of brand recognition
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
Thawte SSL123 — DV from one of the oldest CA brands
Thawte is one of the oldest certificate authority brands in the industry (founded 1995, now part of DigiCert). SSL123 is its modern DV line — automated domain validation, fast issuance, Thawte name on the certificate.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
Domain Validation only — no paperwork
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Customers who specifically want the Thawte brand on their certificate
Sites where the Thawte name has historical recognition (legacy enterprise, finance, .za and ZA-anchored audiences)
DV use cases that need a name with three decades of brand recognition
Issuance time
A few minutes after DNS or HTTP validation completes.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Organization Validation (22)
Verifies a real, registered company stands behind the site. Best for business and SaaS.
DigiCert Basic — entry-level certificate from the world's most-issued commercial CA
DigiCert is one of the largest commercial certificate authorities and one of the longest-established roots in every modern browser and operating system trust store. The Basic line is DigiCert's entry-tier business certificate — issued from DigiCert roots, with the assurance that comes from a top-tier CA, at the most accessible DigiCert price point.
What you get
Issued from DigiCert root certificates (universally trusted by browsers, mobile OSes, servers and IoT devices)
OV (Organization Validation) or EV (Extended Validation) — real vetting of your company's legal identity, not just domain control
SHA-2 / 2048-bit RSA (4096-bit and ECC available on request)
Reissue and revoke at any time during the certificate lifetime
$1M+ warranty (DigiCert warranty terms apply)
30-day money-back guarantee
Best for
Established businesses that want the recognised "DigiCert" name on their certificate
Sites where credible identity matters more than absolute lowest cost (regulated industries, B2B SaaS, finance)
Organisations that already standardise on DigiCert across their estate
Issuance time
OV — typically 1–3 business days after document verification. EV — typically 1–5 business days; CA must contact a verified phone listing for your organisation.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Basic — entry-level certificate from the world's most-issued commercial CA
DigiCert is one of the largest commercial certificate authorities and one of the longest-established roots in every modern browser and operating system trust store. The Basic line is DigiCert's entry-tier business certificate — issued from DigiCert roots, with the assurance that comes from a top-tier CA, at the most accessible DigiCert price point.
What you get
Issued from DigiCert root certificates (universally trusted by browsers, mobile OSes, servers and IoT devices)
OV (Organization Validation) or EV (Extended Validation) — real vetting of your company's legal identity, not just domain control
SHA-2 / 2048-bit RSA (4096-bit and ECC available on request)
Reissue and revoke at any time during the certificate lifetime
$1M+ warranty (DigiCert warranty terms apply)
30-day money-back guarantee
Best for
Established businesses that want the recognised "DigiCert" name on their certificate
Sites where credible identity matters more than absolute lowest cost (regulated industries, B2B SaaS, finance)
Organisations that already standardise on DigiCert across their estate
Issuance time
OV — typically 1–3 business days after document verification. EV — typically 1–5 business days; CA must contact a verified phone listing for your organisation.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
DigiCert Basic — entry-level certificate from the world's most-issued commercial CA
DigiCert is one of the largest commercial certificate authorities and one of the longest-established roots in every modern browser and operating system trust store. The Basic line is DigiCert's entry-tier business certificate — issued from DigiCert roots, with the assurance that comes from a top-tier CA, at the most accessible DigiCert price point.
What you get
Issued from DigiCert root certificates (universally trusted by browsers, mobile OSes, servers and IoT devices)
OV (Organization Validation) or EV (Extended Validation) — real vetting of your company's legal identity, not just domain control
SHA-2 / 2048-bit RSA (4096-bit and ECC available on request)
Reissue and revoke at any time during the certificate lifetime
$1M+ warranty (DigiCert warranty terms apply)
30-day money-back guarantee
Best for
Established businesses that want the recognised "DigiCert" name on their certificate
Sites where credible identity matters more than absolute lowest cost (regulated industries, B2B SaaS, finance)
Organisations that already standardise on DigiCert across their estate
Issuance time
OV — typically 1–3 business days after document verification. EV — typically 1–5 business days; CA must contact a verified phone listing for your organisation.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
DigiCert Secure Site — mid-tier from a top-tier CA
DigiCert Secure Site sits above DigiCert Basic: same root trust, stronger warranty, plus value-added services that matter for sites where downtime or compromise has real revenue consequences.
What you get on top of Basic
Larger DigiCert warranty
Priority validation queue — faster issuance than Basic
DigiCert Site Seal (dynamic, served from DigiCert infrastructure)
Malware check and vulnerability assessment included (DigiCert-hosted)
SHA-2 / 2048-bit (4096-bit and ECC on request)
OV or EV identity validation
Best for
Mid-market e-commerce where checkout reputation matters
Companies that want the DigiCert name plus an active site-trust seal
Sites needing routine malware / vulnerability checks bundled with the certificate
Issuance time
OV — typically 1–2 business days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Secure Site — mid-tier from a top-tier CA
DigiCert Secure Site sits above DigiCert Basic: same root trust, stronger warranty, plus value-added services that matter for sites where downtime or compromise has real revenue consequences.
What you get on top of Basic
Larger DigiCert warranty
Priority validation queue — faster issuance than Basic
DigiCert Site Seal (dynamic, served from DigiCert infrastructure)
Malware check and vulnerability assessment included (DigiCert-hosted)
SHA-2 / 2048-bit (4096-bit and ECC on request)
OV or EV identity validation
Best for
Mid-market e-commerce where checkout reputation matters
Companies that want the DigiCert name plus an active site-trust seal
Sites needing routine malware / vulnerability checks bundled with the certificate
Issuance time
OV — typically 1–2 business days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
DigiCert Secure Site — mid-tier from a top-tier CA
DigiCert Secure Site sits above DigiCert Basic: same root trust, stronger warranty, plus value-added services that matter for sites where downtime or compromise has real revenue consequences.
What you get on top of Basic
Larger DigiCert warranty
Priority validation queue — faster issuance than Basic
DigiCert Site Seal (dynamic, served from DigiCert infrastructure)
Malware check and vulnerability assessment included (DigiCert-hosted)
SHA-2 / 2048-bit (4096-bit and ECC on request)
OV or EV identity validation
Best for
Mid-market e-commerce where checkout reputation matters
Companies that want the DigiCert name plus an active site-trust seal
Sites needing routine malware / vulnerability checks bundled with the certificate
Issuance time
OV — typically 1–2 business days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
DigiCert Secure Site Pro — premium DigiCert tier, post-quantum-ready toolkit
DigiCert Secure Site Pro is the top of DigiCert's Secure Site line. Highest warranty, full feature set, and (per DigiCert's current offer) access to post-quantum cryptography test certificates and DigiCert's advanced toolset.
What you get on top of Secure Site
Highest DigiCert warranty (per DigiCert published terms)
Priority validation queue and dedicated DigiCert support escalation
Post-quantum cryptography test certificates (DigiCert PQC programme)
DigiCert Site Seal, malware check, vulnerability assessment all included
OV or EV identity validation
SHA-2 / 2048-bit, 4096-bit and ECC available
Best for
Banks, fintechs, healthcare, government suppliers — sites where the certificate brand is itself a trust signal
Organisations evaluating post-quantum readiness on production endpoints
Large e-commerce where warranty caps materially matter
Issuance time
OV — typically same business day to 2 days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Secure Site Pro — premium DigiCert tier, post-quantum-ready toolkit
DigiCert Secure Site Pro is the top of DigiCert's Secure Site line. Highest warranty, full feature set, and (per DigiCert's current offer) access to post-quantum cryptography test certificates and DigiCert's advanced toolset.
What you get on top of Secure Site
Highest DigiCert warranty (per DigiCert published terms)
Priority validation queue and dedicated DigiCert support escalation
Post-quantum cryptography test certificates (DigiCert PQC programme)
DigiCert Site Seal, malware check, vulnerability assessment all included
OV or EV identity validation
SHA-2 / 2048-bit, 4096-bit and ECC available
Best for
Banks, fintechs, healthcare, government suppliers — sites where the certificate brand is itself a trust signal
Organisations evaluating post-quantum readiness on production endpoints
Large e-commerce where warranty caps materially matter
Issuance time
OV — typically same business day to 2 days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
DigiCert Secure Site Pro — premium DigiCert tier, post-quantum-ready toolkit
DigiCert Secure Site Pro is the top of DigiCert's Secure Site line. Highest warranty, full feature set, and (per DigiCert's current offer) access to post-quantum cryptography test certificates and DigiCert's advanced toolset.
What you get on top of Secure Site
Highest DigiCert warranty (per DigiCert published terms)
Priority validation queue and dedicated DigiCert support escalation
Post-quantum cryptography test certificates (DigiCert PQC programme)
DigiCert Site Seal, malware check, vulnerability assessment all included
OV or EV identity validation
SHA-2 / 2048-bit, 4096-bit and ECC available
Best for
Banks, fintechs, healthcare, government suppliers — sites where the certificate brand is itself a trust signal
Organisations evaluating post-quantum readiness on production endpoints
Large e-commerce where warranty caps materially matter
Issuance time
OV — typically same business day to 2 days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
GeoTrust TrueBusiness ID — business-grade OV / EV from GeoTrust
The TrueBusiness ID family is GeoTrust's business-validated line. OV variants confirm your company's legal identity; EV variants apply the most rigorous CA/B Forum vetting and show certificate details in browsers when users inspect them.
What you get
Issued from GeoTrust roots (chained into DigiCert)
OV — verifies legal company existence, registration, and authorisation; EV — adds physical address, operational existence and exclusive right-to-use checks
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Established small and mid-sized businesses that want a known brand and identity verification on their certificate
B2B sites where buyers may inspect the certificate
Replacing self-signed or free DV on production-critical pages (login, checkout, admin)
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
GeoTrust TrueBusiness ID — business-grade OV / EV from GeoTrust
The TrueBusiness ID family is GeoTrust's business-validated line. OV variants confirm your company's legal identity; EV variants apply the most rigorous CA/B Forum vetting and show certificate details in browsers when users inspect them.
What you get
Issued from GeoTrust roots (chained into DigiCert)
OV — verifies legal company existence, registration, and authorisation; EV — adds physical address, operational existence and exclusive right-to-use checks
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Established small and mid-sized businesses that want a known brand and identity verification on their certificate
B2B sites where buyers may inspect the certificate
Replacing self-signed or free DV on production-critical pages (login, checkout, admin)
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
GeoTrust TrueBusiness ID — business-grade OV / EV from GeoTrust
The TrueBusiness ID family is GeoTrust's business-validated line. OV variants confirm your company's legal identity; EV variants apply the most rigorous CA/B Forum vetting and show certificate details in browsers when users inspect them.
What you get
Issued from GeoTrust roots (chained into DigiCert)
OV — verifies legal company existence, registration, and authorisation; EV — adds physical address, operational existence and exclusive right-to-use checks
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Established small and mid-sized businesses that want a known brand and identity verification on their certificate
B2B sites where buyers may inspect the certificate
Replacing self-signed or free DV on production-critical pages (login, checkout, admin)
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Sectigo ACME (OV) — OV-validated certificates via ACME
Same as Sectigo ACME (DV), with full Organization Validation applied: Sectigo verifies your company's legal existence, registration and authorisation before any certificate issues. After the first OV validation completes, follow-up certificates on the same organisation can issue at ACME speed.
What you get
ACME endpoint + EAB credentials tied to an OV-validated organisation
Sectigo roots, universally trusted
OV identity vetting (one-time per organisation, with renewal cycles)
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Best for
SaaS platforms whose certificates need to show real company identity to customers
Regulated environments (finance, healthcare) where automation + OV are both required
Multi-tenant providers issuing certificates for downstream customer domains
Issuance time
First OV validation: 1–3 business days. Subsequent ACME issuances under that validation: seconds to minutes.
InstantSSL is Sectigo's entry-tier business OV line — your company legally vetted, certificate issued in days not weeks, on universally-trusted Sectigo roots.
What you get
Issued from Sectigo roots, universally trusted
Organisation Validation — Sectigo verifies your company's legal existence and authorisation
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Small / mid-sized business graduating from DV to a vetted business certificate
B2B sites where the certificate identity matters for sales conversations
Login and checkout pages on sites that don't need full EV
Issuance time
Typically 1–3 business days after document verification.
Sectigo PremiumSSL Wildcard — OV wildcard from Sectigo
PremiumSSL Wildcard covers one domain plus every first-level subdomain (e.g. *.example.com) under a single Sectigo Organisation-Validated certificate. One cert, unlimited subdomains, one renewal.
What you get
Wildcard coverage on one domain + unlimited first-level subdomains
Issued from Sectigo roots, universally trusted
OV validation — Sectigo verifies your company's legal existence
SHA-2 / 2048-bit RSA
Sectigo warranty (per published terms)
30-day money-back guarantee
Best for
Multi-app deployments under one domain (api, app, www, blog, status, docs…)
Kubernetes ingress or platform routing needing one cert for many internal services
SaaS providers with many subdomains per customer or environment
Issuance time
Typically 1–3 business days after document verification.
Sectigo UCC is a multi-domain certificate purpose-built for Microsoft Exchange, Lync, Skype-for-Business and Office Communications Server topologies — environments where one certificate has to cover several internal hostnames (autodiscover, mail, owa, ext.) plus public domains, all under unified communications.
What you get
Multi-Domain (SAN) certificate with full OV validation
Issued from Sectigo roots, universally trusted
Optimised for Microsoft UC server topologies but works on any multi-name endpoint
Thawte's business-grade line. OV variants verify your company's legal identity; EV variants apply the full CA/B Forum extended-validation checklist (legal, physical, operational, phone) and surface certificate details when users inspect the lock.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
OV or EV identity validation
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the Thawte brand combined with OV / EV identity verification
Regulated or legacy enterprise environments standardised on Thawte
Mid-market e-commerce and financial services
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Thawte's business-grade line. OV variants verify your company's legal identity; EV variants apply the full CA/B Forum extended-validation checklist (legal, physical, operational, phone) and surface certificate details when users inspect the lock.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
OV or EV identity validation
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the Thawte brand combined with OV / EV identity verification
Regulated or legacy enterprise environments standardised on Thawte
Mid-market e-commerce and financial services
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
Thawte's business-grade line. OV variants verify your company's legal identity; EV variants apply the full CA/B Forum extended-validation checklist (legal, physical, operational, phone) and surface certificate details when users inspect the lock.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
OV or EV identity validation
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the Thawte brand combined with OV / EV identity verification
Regulated or legacy enterprise environments standardised on Thawte
Mid-market e-commerce and financial services
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Wildcard
Secures one domain and every first-level subdomain (e.g. example.com plus blog.example.com, shop.example.com, mail.example.com). One certificate, unlimited subdomains, one renewal.
Extended Validation (14)
Most rigorous vetting; certificate details visible in browsers. Best for finance, regulated industries, high-trust e-commerce.
DigiCert Basic — entry-level certificate from the world's most-issued commercial CA
DigiCert is one of the largest commercial certificate authorities and one of the longest-established roots in every modern browser and operating system trust store. The Basic line is DigiCert's entry-tier business certificate — issued from DigiCert roots, with the assurance that comes from a top-tier CA, at the most accessible DigiCert price point.
What you get
Issued from DigiCert root certificates (universally trusted by browsers, mobile OSes, servers and IoT devices)
OV (Organization Validation) or EV (Extended Validation) — real vetting of your company's legal identity, not just domain control
SHA-2 / 2048-bit RSA (4096-bit and ECC available on request)
Reissue and revoke at any time during the certificate lifetime
$1M+ warranty (DigiCert warranty terms apply)
30-day money-back guarantee
Best for
Established businesses that want the recognised "DigiCert" name on their certificate
Sites where credible identity matters more than absolute lowest cost (regulated industries, B2B SaaS, finance)
Organisations that already standardise on DigiCert across their estate
Issuance time
OV — typically 1–3 business days after document verification. EV — typically 1–5 business days; CA must contact a verified phone listing for your organisation.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Basic — entry-level certificate from the world's most-issued commercial CA
DigiCert is one of the largest commercial certificate authorities and one of the longest-established roots in every modern browser and operating system trust store. The Basic line is DigiCert's entry-tier business certificate — issued from DigiCert roots, with the assurance that comes from a top-tier CA, at the most accessible DigiCert price point.
What you get
Issued from DigiCert root certificates (universally trusted by browsers, mobile OSes, servers and IoT devices)
OV (Organization Validation) or EV (Extended Validation) — real vetting of your company's legal identity, not just domain control
SHA-2 / 2048-bit RSA (4096-bit and ECC available on request)
Reissue and revoke at any time during the certificate lifetime
$1M+ warranty (DigiCert warranty terms apply)
30-day money-back guarantee
Best for
Established businesses that want the recognised "DigiCert" name on their certificate
Sites where credible identity matters more than absolute lowest cost (regulated industries, B2B SaaS, finance)
Organisations that already standardise on DigiCert across their estate
Issuance time
OV — typically 1–3 business days after document verification. EV — typically 1–5 business days; CA must contact a verified phone listing for your organisation.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
DigiCert Secure Site — mid-tier from a top-tier CA
DigiCert Secure Site sits above DigiCert Basic: same root trust, stronger warranty, plus value-added services that matter for sites where downtime or compromise has real revenue consequences.
What you get on top of Basic
Larger DigiCert warranty
Priority validation queue — faster issuance than Basic
DigiCert Site Seal (dynamic, served from DigiCert infrastructure)
Malware check and vulnerability assessment included (DigiCert-hosted)
SHA-2 / 2048-bit (4096-bit and ECC on request)
OV or EV identity validation
Best for
Mid-market e-commerce where checkout reputation matters
Companies that want the DigiCert name plus an active site-trust seal
Sites needing routine malware / vulnerability checks bundled with the certificate
Issuance time
OV — typically 1–2 business days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Secure Site — mid-tier from a top-tier CA
DigiCert Secure Site sits above DigiCert Basic: same root trust, stronger warranty, plus value-added services that matter for sites where downtime or compromise has real revenue consequences.
What you get on top of Basic
Larger DigiCert warranty
Priority validation queue — faster issuance than Basic
DigiCert Site Seal (dynamic, served from DigiCert infrastructure)
Malware check and vulnerability assessment included (DigiCert-hosted)
SHA-2 / 2048-bit (4096-bit and ECC on request)
OV or EV identity validation
Best for
Mid-market e-commerce where checkout reputation matters
Companies that want the DigiCert name plus an active site-trust seal
Sites needing routine malware / vulnerability checks bundled with the certificate
Issuance time
OV — typically 1–2 business days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
DigiCert Secure Site Pro — premium DigiCert tier, post-quantum-ready toolkit
DigiCert Secure Site Pro is the top of DigiCert's Secure Site line. Highest warranty, full feature set, and (per DigiCert's current offer) access to post-quantum cryptography test certificates and DigiCert's advanced toolset.
What you get on top of Secure Site
Highest DigiCert warranty (per DigiCert published terms)
Priority validation queue and dedicated DigiCert support escalation
Post-quantum cryptography test certificates (DigiCert PQC programme)
DigiCert Site Seal, malware check, vulnerability assessment all included
OV or EV identity validation
SHA-2 / 2048-bit, 4096-bit and ECC available
Best for
Banks, fintechs, healthcare, government suppliers — sites where the certificate brand is itself a trust signal
Organisations evaluating post-quantum readiness on production endpoints
Large e-commerce where warranty caps materially matter
Issuance time
OV — typically same business day to 2 days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
DigiCert Secure Site Pro — premium DigiCert tier, post-quantum-ready toolkit
DigiCert Secure Site Pro is the top of DigiCert's Secure Site line. Highest warranty, full feature set, and (per DigiCert's current offer) access to post-quantum cryptography test certificates and DigiCert's advanced toolset.
What you get on top of Secure Site
Highest DigiCert warranty (per DigiCert published terms)
Priority validation queue and dedicated DigiCert support escalation
Post-quantum cryptography test certificates (DigiCert PQC programme)
DigiCert Site Seal, malware check, vulnerability assessment all included
OV or EV identity validation
SHA-2 / 2048-bit, 4096-bit and ECC available
Best for
Banks, fintechs, healthcare, government suppliers — sites where the certificate brand is itself a trust signal
Organisations evaluating post-quantum readiness on production endpoints
Large e-commerce where warranty caps materially matter
Issuance time
OV — typically same business day to 2 days after document verification (priority queue). EV — typically 1–3 business days.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
GeoTrust TrueBusiness ID — business-grade OV / EV from GeoTrust
The TrueBusiness ID family is GeoTrust's business-validated line. OV variants confirm your company's legal identity; EV variants apply the most rigorous CA/B Forum vetting and show certificate details in browsers when users inspect them.
What you get
Issued from GeoTrust roots (chained into DigiCert)
OV — verifies legal company existence, registration, and authorisation; EV — adds physical address, operational existence and exclusive right-to-use checks
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Established small and mid-sized businesses that want a known brand and identity verification on their certificate
B2B sites where buyers may inspect the certificate
Replacing self-signed or free DV on production-critical pages (login, checkout, admin)
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
GeoTrust TrueBusiness ID — business-grade OV / EV from GeoTrust
The TrueBusiness ID family is GeoTrust's business-validated line. OV variants confirm your company's legal identity; EV variants apply the most rigorous CA/B Forum vetting and show certificate details in browsers when users inspect them.
What you get
Issued from GeoTrust roots (chained into DigiCert)
OV — verifies legal company existence, registration, and authorisation; EV — adds physical address, operational existence and exclusive right-to-use checks
SHA-2 / 2048-bit RSA
GeoTrust warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Established small and mid-sized businesses that want a known brand and identity verification on their certificate
B2B sites where buyers may inspect the certificate
Replacing self-signed or free DV on production-critical pages (login, checkout, admin)
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
PerfectSSL — best price-to-trust ratio in the catalogue
PerfectSSL is the own-brand certificate line of our upstream wholesale partner Realtime Register, chained under established public CA roots (currently the Sectigo / Comodo CA root chain). You get a publicly-trusted certificate, no caveats, at materially lower retail price than the marquee CA brands.
What you get
Issued from publicly-trusted root certificates already in every browser, mobile and OS trust store
DV (instant), OV (business-vetted) and EV (most rigorous) variants available across single / multi / wildcard
SHA-2 / 2048-bit RSA
Reissue and revoke during the lifetime
Standard PerfectSSL warranty
30-day money-back guarantee
Best for
Customers who want a real, trusted certificate without paying for the marquee CA brand name
Multi-site operators where unit cost adds up — same trust level, more certificates per budget
Anyone replacing free DV who wants support, warranty and a paid revocation path
Issuance time
DV — minutes after validation. OV — 1–3 business days after document verification. EV — 1–5 business days; phone verification required.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
Sectigo's Extended Validation line. CA/B Forum-standard vetting: legal existence, physical address, operational presence, exclusive right-to-use the domain, plus phone verification. The most stringent identity bar a public CA can apply.
What you get
Sectigo EV roots, universally trusted
Full EV vetting — legal, physical, operational, phone verification
Certificate details visible to users who inspect the lock icon
SHA-2 / 2048-bit RSA (4096-bit and ECC on request)
Any site where a visitor inspecting the certificate should see a real company name
Issuance time
Typically 1–5 business days. CA must verify a registered phone listing and complete the EV vetting checklist.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Sectigo's Extended Validation line. CA/B Forum-standard vetting: legal existence, physical address, operational presence, exclusive right-to-use the domain, plus phone verification. The most stringent identity bar a public CA can apply.
What you get
Sectigo EV roots, universally trusted
Full EV vetting — legal, physical, operational, phone verification
Certificate details visible to users who inspect the lock icon
SHA-2 / 2048-bit RSA (4096-bit and ECC on request)
Any site where a visitor inspecting the certificate should see a real company name
Issuance time
Typically 1–5 business days. CA must verify a registered phone listing and complete the EV vetting checklist.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.
Thawte's business-grade line. OV variants verify your company's legal identity; EV variants apply the full CA/B Forum extended-validation checklist (legal, physical, operational, phone) and surface certificate details when users inspect the lock.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
OV or EV identity validation
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the Thawte brand combined with OV / EV identity verification
Regulated or legacy enterprise environments standardised on Thawte
Mid-market e-commerce and financial services
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Single Domain
Secures one fully-qualified domain. The most common choice for a primary website. If you want subdomains covered, choose Wildcard; for several unrelated domains, choose Multi-Domain.
Thawte's business-grade line. OV variants verify your company's legal identity; EV variants apply the full CA/B Forum extended-validation checklist (legal, physical, operational, phone) and surface certificate details when users inspect the lock.
What you get
Issued from Thawte roots (chained into DigiCert), universally trusted
OV or EV identity validation
SHA-2 / 2048-bit RSA
Thawte warranty (per published terms)
Reissue and revoke during the lifetime
30-day money-back guarantee
Best for
Businesses that want the Thawte brand combined with OV / EV identity verification
Regulated or legacy enterprise environments standardised on Thawte
Mid-market e-commerce and financial services
Issuance time
OV — typically 1–3 business days. EV — typically 1–5 business days; CA must verify a registered phone listing.
Coverage — Multi-Domain (SAN)
Secures multiple distinct domains under a single certificate (Subject Alternative Names). Ideal when you operate several brands or services and want one renewal date and one private key to manage.