Deep dive

How Extended Validation Certificates Rose and Fell

Extended Validation certificates were introduced in 2007 by a coalition of CAs and browser vendors working through the newly formed CA/Browser Forum, exactly to address growing concern about phishing — the idea being that a much more rigorous identity verification process, paired with a distinctive, hard-to-fake browser UI treatment, would give users a reliable way to distinguish legitimate organizations from impersonators.

The original design: rigor plus visibility

EV validation required verifying a business's legal existence, physical address, and operational status through much more thorough checks than DV or even standard OV validation — and in exchange, browsers displayed a distinctive green address bar showing the verified company name, a visual treatment no other certificate type received.

Early adoption and enthusiasm

Banks, financial institutions, and major e-commerce sites adopted EV certificates relatively quickly in the years following introduction, and the green bar became a recognizable trust signal actively promoted in security awareness training — "look for the green bar" was common security advice for consumers well into the 2010s.

The research that undermined the premise

The original EV thesis What usability research found • A distinct green bar would bea strong, visible trust signal • Most users didn't notice orunderstand the green bar atall • Users would notice its absenceon phishing sites • Its absence didn't changeclick-through behavior onphishing tests • This would meaningfully reducesuccessful phishing • The signal wasn't achievingits intended security effect
A decade of usability studies gradually undermined EV's core rationale

Over the following decade, a series of usability studies — including research conducted or cited by browser vendors themselves — found that the green bar's actual effect on user behavior was far weaker than its designers had hoped. Most users either didn't notice the distinction between EV and standard HTTPS, or didn't understand what the green bar was supposed to signify even when asked about it.

The removal

Chrome removed the distinct EV UI treatment in 2019, folding EV certificates into the same general "Secure" padlock treatment as any other valid certificate; other major browsers made similar changes around the same period. This wasn't framed as EV certificates becoming worthless — rather, as the visible UI distinction no longer being justified by the evidence of its actual effectiveness.

What EV certificates offer today, post-UI-removal

EV certificates still undergo the same rigorous validation process as before, and organizations still purchase them — the underlying verified-identity audit trail retains real value for compliance purposes, internal trust requirements, or specific industry expectations (some financial or legal contexts still specify EV in their own internal policy), even though that verification no longer translates into a distinctive browser-visible badge.

The specific usability studies that mattered most

Several independent research efforts contributed to the case against EV's visual treatment, but two kinds of study were particularly influential: eye-tracking research showing that a large share of users simply never looked at the address bar closely enough to register the color difference in the first place, and simulated-phishing studies where researchers built convincing fake sites and measured whether the presence or absence of the EV green bar changed how many participants proceeded to enter sensitive information. Across multiple such studies, the difference in participant behavior with and without the EV indicator was consistently smaller than EV's original designers had hoped, and in several cases not statistically distinguishable from no effect at all.

Why the signal failed even though the underlying idea was reasonable

In hindsight, security researchers have offered a few explanations for why a seemingly sensible idea — give users a strong visual signal for verified identity — underperformed so consistently. One is simple unfamiliarity: without dedicated user education (which never happened at meaningful scale), most people had no reason to know what a green address bar signified even if they noticed it. Another is that phishing attacks increasingly moved away from vectors where an address bar would even be visible or relevant — a fraudulent email or social media message often leads a victim through a click path where the address bar receives far less scrutiny than a security designer might assume, particularly on mobile devices where the address bar is frequently minimized or hidden entirely during scrolling.

Mobile browsing and EV's declining relevance

The shift toward mobile browsing specifically undermined EV's core premise in a way its original 2007 design didn't fully anticipate — many mobile browsers minimize or hide the address bar during normal scrolling to maximize content viewing area, meaning even a user who might have noticed and understood a green bar on desktop would frequently never see it at all on a phone. As mobile traffic grew from a minority to the majority of web browsing through the 2010s, this alone was enough to substantially erode whatever practical value the visual treatment still had, independent of the broader usability research findings.

What other browser vendors did, and the (near) industry consensus

Chrome's 2019 removal is the most frequently cited milestone, but other major browsers made similar changes around the same broad period, reflecting what became something close to industry consensus rather than one vendor acting alone. This kind of coordinated-but-independent movement across competing browser vendors — each running their own research, reaching broadly similar conclusions, and each making their own removal decision on a similar timeline — is a pattern that's recurred at other points in TLS/browser security history when a genuinely settled body of evidence accumulates against a previously well-intentioned design choice.

EV's parallel history in the certificate industry itself

Independent of the browser UI story, EV certificates carry their own separate significance within the certificate industry: they were the first widely adopted attempt to formalize a really rigorous, standardized identity-verification process across multiple competing CAs through the CA/Browser Forum, going well beyond what any individual CA had previously done unilaterally. In that sense, EV's lasting legacy may be less about the browser badge that's now gone, and more about having established a detailed, cross-industry template for rigorous organizational validation that continues to inform how OV and EV validation processes are structured today, even without the visual payoff that originally motivated the tier's creation.

What this episode teaches about security UI design generally

Beyond its specific relevance to certificates, the EV green-bar story has become a frequently cited case study in broader security UX (user experience) design discussions — an illustration of how a security feature that seems intuitively correct to its designers (more validation should mean a more visible, more trusted signal) can fail in practice if it isn't grounded in actual measured user behavior. The lesson security UX researchers commonly draw from it is that visual security indicators need to be validated with real usability testing against realistic threat scenarios, rather than assumed effective based on face-value design logic alone — a principle that's since influenced how browser vendors approach other user-facing security signals, including the broader simplification of the padlock icon itself discussed in our companion history article.

Where EV stands today, several years after the change

As of today, EV certificates remain available from every major CA and continue to be purchased, primarily by larger financial institutions, e-commerce platforms, and organizations with specific compliance or contractual reasons to want the highest validation tier — but the certificate-buying calculus has shifted meaningfully compared to the pre-2019 era. Where EV was once marketed heavily on its visible trust-signal benefit, current buying guidance (including our own coverage in the Buy a Certificate category) treats EV primarily as a compliance and audit-trail decision rather than a customer-facing trust investment, reflecting the genuine, lasting change in what EV actually delivers today versus what it was originally designed to deliver in 2007.

One counterfactual worth considering

It's reasonable to ask what might have happened had EV's visual treatment been paired with sustained public education about what it meant, rather than launched with the assumption that visibility alone would be self-explanatory. Some researchers have argued the underlying idea wasn't necessarily flawed so much as under-supported — but since that education effort never happened at meaningful scale, the question remains hypothetical, and the industry's practical conclusion was simply that the feature as actually deployed didn't earn its keep.

Where you can still see the underlying signal

Even without the address bar treatment, the verified organization name embedded in an EV certificate remains visible if you actively click into a browser's certificate details — the information EV always provided didn't disappear, it just stopped being surfaced automatically to an average visitor.

The short version: EV certificates were introduced with a clear, well-intentioned thesis about visible trust signals reducing phishing — a decade of usability data didn't support that thesis, and browsers removed the distinct UI accordingly, even though the underlying validation rigor remains unchanged.

How this affected EV certificate sales figures over time

Industry reporting following the UI removal generally indicated a gradual decline in EV certificate purchases relative to OV and DV, consistent with the loss of EV's main customer-facing selling point — while EV hasn't disappeared as a product category, its relative share of the overall certificate market has shifted further toward DV and OV in the years since the visual treatment was removed.

Comments

Loading comments…