The short answer
SSL certificate validation takes minutes for DV, about 1–3 business days for OV, and typically 3–7 business days — up to roughly two weeks — for EV. The difference is who does the checking: DV (Domain Validation) is fully automated, so it clears in minutes to a few hours. OV (Organization Validation) and EV (Extended Validation) add human vetting of your organization, which is what adds the days. As of July 2026, domain control itself is proven automatically by a DNS record or an HTTP file, so on OV and EV the wait is almost entirely the organization checks — most often a verification callback to a phone number the CA can confirm independently.
If you're deciding what to buy and the timeline is part of the choice, the DV, OV, and EV SSL certificates each list their validation level up front. If you've already ordered and you're just waiting, skip to why validation stalls — it's usually one fixable thing.
On this page
Validation timelines at a glance
DV certificates issue in minutes, OV in 1–3 business days, and EV in 3–7 business days, sometimes closer to two weeks. Those are typical figures once your details are in order; the ranges widen when the certificate authority has to chase something down. The table below is the fast version, and the timeline underneath it shows why the gap between levels exists at all.
| Level | Typical time | Who checks | What it proves |
|---|---|---|---|
| DV | Minutes to a few hours | Automated system | Control of the domain |
| OV | 1–3 business days | A person at the CA | Domain control + a registered organization |
| EV | 3–7 business days (up to ~2 weeks) | A person at the CA, stricter checklist | Domain control + legal, operational & physical existence |
Notice that every level starts the same way — an automated domain check that takes minutes. If you only need HTTPS working today, that's your escape hatch: a DV certificate gives you a live padlock now, and you can move to OV or EV later without taking the site down. The rest of the wait is the organization vetting, so it's worth knowing exactly what that involves.
What the CA verifies at each level
Every SSL certificate proves one thing in common: that you control the domain. DV stops there. OV adds a check that your organization is a real, registered legal entity and that you're allowed to request the certificate. EV keeps the OV checks and layers on verification of your organization's legal, operational, and physical existence, plus a verified phone callback — the checklist the CA/Browser Forum's Extended Validation guidelines spell out. More to verify means more that can slow down.
Domain control itself is proven the same way regardless of level, and the accepted methods are narrowing. As of July 2026 you prove control with a DNS record or an HTTP file challenge; the older email- and phone-based methods are being retired under CA/Browser Forum ballot SC-090 (phone-based control ends by March 15, 2027 and email-based by March 15, 2028, both already discouraged). We cover that shift in detail in the 2026 domain validation changes. The practical takeaway: pick DNS or HTTP control when you order, because it's automated and it isn't going away.
That pipeline is the same shape for OV and EV — EV just runs a longer checklist at step 3 and is stricter at step 4. Steps 1 and 2 are automated and quick. The time you actually wait on is a human working through steps 3 and 4, which is why the next three sections look at each level's real-world clock.
DV validation: minutes, fully automated
DV validation is usually done in minutes because no human is involved. You place the order, submit a CSR, and prove you control the domain by publishing a DNS record or a small file the CA fetches over HTTP. The moment the CA's system sees the record or file, it issues. There's nothing to verify about your identity, so there's nothing to wait on beyond the automated check.
When DV takes longer than minutes, it's nearly always DNS propagation or a record in the wrong place — a TXT value under the wrong host, or a caching resolver still serving the old answer. If your order sits in "pending", re-check the exact record name and value the CA asked for before assuming anything is broken. Because DV proves only domain control, it's the level behind most automated and free certificates; if that fits your use, our guide on which SSL certificate you need walks through when DV is enough and when it isn't.
OV validation: 1–3 business days
OV validation typically takes 1–3 business days. After the automated domain check, a validation specialist at the CA confirms your organization is a real, registered legal entity — usually by looking it up in an official government registry or a trusted business directory such as Dun & Bradstreet — and confirms that you're authorized to request the certificate. It commonly finishes with a verification call to a phone number the CA can independently confirm belongs to your organization.
The reason OV usually lands inside three days is that the CA prefers to verify from sources it already trusts rather than documents you upload. That's also why the delays cluster around a single thing: a phone number it can't confirm. In our experience processing certificate orders through Certum, the paperwork is rarely the holdup — an unlisted or mismatched business number is. If OV fits your site, the organization-validated SSL certificates page shows what the issued certificate includes, and the OV vs EV comparison covers where the extra EV checks are worth the wait.
EV validation: days to two weeks
EV validation usually takes 3–7 business days and can reach about two weeks. It includes everything OV does, then adds verification of your organization's operational and physical existence, a stricter check that the person requesting the certificate has authority, and a verified phone callback made to a number the CA sourced independently. Newer companies feel this most, because "operational existence" can mean showing the business has been active for a set period or providing confirmation from a lawyer, accountant, or bank.
None of the EV steps is individually slow — the two-week cases happen when several checks each need a follow-up. A registry record that doesn't match your requested name, an address the CA can't confirm, or a callback that goes unanswered each add a round trip. If you know an EV order is coming, line up the supporting details before you buy. The extended-validation SSL certificates page lists what EV verifies, so you can gather it in advance rather than mid-order.
What to have ready before you order
For OV and EV, the fastest orders are the ones where the CA can confirm everything from sources it already trusts. You rarely need to upload a stack of documents; you need your organization's details to match those sources exactly. Get these lined up before you place the order and you remove most of the reasons an order stalls:
- Exact registered legal name. Match your government registration character-for-character, including "Ltd", "GmbH", or "LLC" — not your trading or brand name.
- Registered address. The one on file with your business registry, matching what the CA will find when it looks you up.
- A publicly listed business phone number. The single biggest time-saver. The CA needs to find it through an independent source — a registry, a phone directory, or a verified listing — not just on your own website.
- A valid CSR generated on your server. Its details should line up with your organization. If you're new to this, our guide to what a CSR is explains what goes in it and why the private key never leaves your server.
- For EV, proof of operational existence (sometimes). Newer organizations may be asked for confirmation from a lawyer or accountant, or evidence the business has been active for a set period. Check your CA's exact list before ordering.
Why validation stalls — and how to avoid it
Most stalled SSL orders come down to one of three things: the domain control check never completed, the CA can't find your organization in a source it trusts, or it can't confirm your phone number. The first is a DV-and-up problem; the last two are what push OV and EV past their normal windows. The good news is that all three are checkable before you order, not after.
The phone-number gate is worth a special mention because it fails quietly. Your number can be all over your own website and still not be verifiable to a CA that only trusts independent sources. Confirm it's listed in your business registry or a recognized directory before you order, and answer the verification call the same day it comes. When you do hit a wall, respond to the CA's request quickly — a same-day reply routinely turns a would-be week into a day.
One more timing note for renewals: with certificate lifetimes now capped at 199 days, OV and EV certificates come up for renewal far more often than they used to, and organization details are re-checked. Don't leave a renewal to the last day — build in a buffer, which is exactly the argument in our SSL certificate renewal guide.
FAQ
Order with the timeline in mind
My-SSL issues DV, OV, and EV certificates through Certum, a publicly trusted certificate authority, so each order runs the standard validation for its level. Match the level to how soon you need to be live — DV for minutes, OV for a couple of days, EV when the extra checks are required — on the SSL certificates page, and have your organization details ready so validation clears on the first pass.
Related reading
- Which SSL certificate do I need? — pick DV, OV, or EV based on what your site actually does.
- OV vs EV SSL in 2026 — cost, vetting, and when EV's extra days are worth it.
- 2026 domain validation changes — why email and phone control methods are being retired.
Sources worth checking directly
- CA/Browser Forum — TLS Baseline Requirements (domain control and OV organization validation)
- CA/Browser Forum — Extended Validation Guidelines (the EV verification checklist)
- CA/Browser Forum — Ballot SC-090 (sunset of email- and phone-based control methods)