Skip to main content
    Comparisons

    How Long Does SSL Certificate Validation Take?

    DV validation finishes in minutes; OV takes 1–3 business days; EV up to two weeks. What CAs verify at each level and how to avoid delays.

    MS
    My-SSL Security Team
    ·
    12 min read
    ·Published July 19, 2026·Last updated July 19, 2026

    The short answer

    SSL certificate validation takes minutes for DV, about 1–3 business days for OV, and typically 3–7 business days — up to roughly two weeks — for EV. The difference is who does the checking: DV (Domain Validation) is fully automated, so it clears in minutes to a few hours. OV (Organization Validation) and EV (Extended Validation) add human vetting of your organization, which is what adds the days. As of July 2026, domain control itself is proven automatically by a DNS record or an HTTP file, so on OV and EV the wait is almost entirely the organization checks — most often a verification callback to a phone number the CA can confirm independently.

    If you're deciding what to buy and the timeline is part of the choice, the DV, OV, and EV SSL certificates each list their validation level up front. If you've already ordered and you're just waiting, skip to why validation stalls — it's usually one fixable thing.

    Validation timelines at a glance

    DV certificates issue in minutes, OV in 1–3 business days, and EV in 3–7 business days, sometimes closer to two weeks. Those are typical figures once your details are in order; the ranges widen when the certificate authority has to chase something down. The table below is the fast version, and the timeline underneath it shows why the gap between levels exists at all.

    LevelTypical timeWho checksWhat it proves
    DVMinutes to a few hoursAutomated systemControl of the domain
    OV1–3 business daysA person at the CADomain control + a registered organization
    EV3–7 business days (up to ~2 weeks)A person at the CA, stricter checklistDomain control + legal, operational & physical existence
    SSL validation timeline for DV, OV and EV certificatesThree horizontal timeline lanes from an order placed at the left. DV finishes within minutes after an automated domain check. OV adds a human organization-vetting segment ending around one to three business days. EV extends that vetting segment out toward two weeks. The human-review portion, shown in gold, is what accounts for the wait.Orderminutes1 day3 days1 week2 weeksDVOVEVAutomatedOrganization vetting (human)Legal + operational + physical checks, phone callback
    The gray segment — the automated domain check — is fast for all three. Everything past it is a human confirming your organization, which is exactly why OV and EV take days rather than minutes.

    Notice that every level starts the same way — an automated domain check that takes minutes. If you only need HTTPS working today, that's your escape hatch: a DV certificate gives you a live padlock now, and you can move to OV or EV later without taking the site down. The rest of the wait is the organization vetting, so it's worth knowing exactly what that involves.

    What the CA verifies at each level

    Every SSL certificate proves one thing in common: that you control the domain. DV stops there. OV adds a check that your organization is a real, registered legal entity and that you're allowed to request the certificate. EV keeps the OV checks and layers on verification of your organization's legal, operational, and physical existence, plus a verified phone callback — the checklist the CA/Browser Forum's Extended Validation guidelines spell out. More to verify means more that can slow down.

    Domain control itself is proven the same way regardless of level, and the accepted methods are narrowing. As of July 2026 you prove control with a DNS record or an HTTP file challenge; the older email- and phone-based methods are being retired under CA/Browser Forum ballot SC-090 (phone-based control ends by March 15, 2027 and email-based by March 15, 2028, both already discouraged). We cover that shift in detail in the 2026 domain validation changes. The practical takeaway: pick DNS or HTTP control when you order, because it's automated and it isn't going away.

    The OV and EV certificate validation pipelineFive sequential steps: order and CSR submission, domain control validation by DNS or HTTP, organization lookup in an official registry, a verification callback to a listed phone number, and certificate issuance. The callback step is highlighted as the one that most often delays an order.1Order placed +CSR submitted2Domain controlcheck (DNS orHTTP)3Organizationlooked up in aregistry4Verificationcallback tolisted number5CertificateissuedOV / EV validation, start to finish
    Steps 1 and 2 are automated. The clock you actually wait on is steps 3 and 4 — and a phone number the CA can't independently verify is where most orders lose a day or more.

    That pipeline is the same shape for OV and EV — EV just runs a longer checklist at step 3 and is stricter at step 4. Steps 1 and 2 are automated and quick. The time you actually wait on is a human working through steps 3 and 4, which is why the next three sections look at each level's real-world clock.

    DV validation: minutes, fully automated

    DV validation is usually done in minutes because no human is involved. You place the order, submit a CSR, and prove you control the domain by publishing a DNS record or a small file the CA fetches over HTTP. The moment the CA's system sees the record or file, it issues. There's nothing to verify about your identity, so there's nothing to wait on beyond the automated check.

    When DV takes longer than minutes, it's nearly always DNS propagation or a record in the wrong place — a TXT value under the wrong host, or a caching resolver still serving the old answer. If your order sits in "pending", re-check the exact record name and value the CA asked for before assuming anything is broken. Because DV proves only domain control, it's the level behind most automated and free certificates; if that fits your use, our guide on which SSL certificate you need walks through when DV is enough and when it isn't.

    OV validation: 1–3 business days

    OV validation typically takes 1–3 business days. After the automated domain check, a validation specialist at the CA confirms your organization is a real, registered legal entity — usually by looking it up in an official government registry or a trusted business directory such as Dun & Bradstreet — and confirms that you're authorized to request the certificate. It commonly finishes with a verification call to a phone number the CA can independently confirm belongs to your organization.

    The reason OV usually lands inside three days is that the CA prefers to verify from sources it already trusts rather than documents you upload. That's also why the delays cluster around a single thing: a phone number it can't confirm. In our experience processing certificate orders through Certum, the paperwork is rarely the holdup — an unlisted or mismatched business number is. If OV fits your site, the organization-validated SSL certificates page shows what the issued certificate includes, and the OV vs EV comparison covers where the extra EV checks are worth the wait.

    EV validation: days to two weeks

    EV validation usually takes 3–7 business days and can reach about two weeks. It includes everything OV does, then adds verification of your organization's operational and physical existence, a stricter check that the person requesting the certificate has authority, and a verified phone callback made to a number the CA sourced independently. Newer companies feel this most, because "operational existence" can mean showing the business has been active for a set period or providing confirmation from a lawyer, accountant, or bank.

    None of the EV steps is individually slow — the two-week cases happen when several checks each need a follow-up. A registry record that doesn't match your requested name, an address the CA can't confirm, or a callback that goes unanswered each add a round trip. If you know an EV order is coming, line up the supporting details before you buy. The extended-validation SSL certificates page lists what EV verifies, so you can gather it in advance rather than mid-order.

    What to have ready before you order

    For OV and EV, the fastest orders are the ones where the CA can confirm everything from sources it already trusts. You rarely need to upload a stack of documents; you need your organization's details to match those sources exactly. Get these lined up before you place the order and you remove most of the reasons an order stalls:

    • Exact registered legal name. Match your government registration character-for-character, including "Ltd", "GmbH", or "LLC" — not your trading or brand name.
    • Registered address. The one on file with your business registry, matching what the CA will find when it looks you up.
    • A publicly listed business phone number. The single biggest time-saver. The CA needs to find it through an independent source — a registry, a phone directory, or a verified listing — not just on your own website.
    • A valid CSR generated on your server. Its details should line up with your organization. If you're new to this, our guide to what a CSR is explains what goes in it and why the private key never leaves your server.
    • For EV, proof of operational existence (sometimes). Newer organizations may be asked for confirmation from a lawyer or accountant, or evidence the business has been active for a set period. Check your CA's exact list before ordering.

    Why validation stalls — and how to avoid it

    Most stalled SSL orders come down to one of three things: the domain control check never completed, the CA can't find your organization in a source it trusts, or it can't confirm your phone number. The first is a DV-and-up problem; the last two are what push OV and EV past their normal windows. The good news is that all three are checkable before you order, not after.

    Three checks that decide whether an OV or EV order stallsA checklist of three gates an order must clear: the domain is reachable for the control check, the organization appears in an official registry, and the phone number is independently verifiable. The phone-number gate, highlighted in gold, is the one that fails most often.Will your OV / EV order clear validation cleanly?Is the domain reachable for the DNS or HTTP check?Fails if the record or file isn't publishedIs your organization in an official registry?Fails if newly registered or not yet listedIs your phone number publicly, independently verifiable?The most common blocker
    Clear all three before you order and OV usually lands inside its 1–3 day window. The gold gate is worth a two-minute check: confirm your business number is listed where the CA can find it.

    The phone-number gate is worth a special mention because it fails quietly. Your number can be all over your own website and still not be verifiable to a CA that only trusts independent sources. Confirm it's listed in your business registry or a recognized directory before you order, and answer the verification call the same day it comes. When you do hit a wall, respond to the CA's request quickly — a same-day reply routinely turns a would-be week into a day.

    One more timing note for renewals: with certificate lifetimes now capped at 199 days, OV and EV certificates come up for renewal far more often than they used to, and organization details are re-checked. Don't leave a renewal to the last day — build in a buffer, which is exactly the argument in our SSL certificate renewal guide.

    FAQ

    Order with the timeline in mind

    My-SSL issues DV, OV, and EV certificates through Certum, a publicly trusted certificate authority, so each order runs the standard validation for its level. Match the level to how soon you need to be live — DV for minutes, OV for a couple of days, EV when the extra checks are required — on the SSL certificates page, and have your organization details ready so validation clears on the first pass.

    Related reading

    Sources worth checking directly

    • CA/Browser Forum — TLS Baseline Requirements (domain control and OV organization validation)
    • CA/Browser Forum — Extended Validation Guidelines (the EV verification checklist)
    • CA/Browser Forum — Ballot SC-090 (sunset of email- and phone-based control methods)