TL;DR: EV certificates are less about encryption alone and more about brand protection, with CA checks, certificate transparency, and disputed-name handling shaping whether identity claims can be trusted in practice, according to DigiCert. That makes certificate policy, ownership, and disclosure part of identity governance, not just PKI administration.
At a glance
What this is: This is DigiCert’s argument that EV certificates should be judged as identity and brand controls, not only encryption mechanisms, because browser-trusted proof, CAA checks, and certificate transparency determine whether name claims hold up in practice.
Why it matters: IAM, PAM, and NHI teams should care because certificate issuance now intersects with ownership evidence, disputed-name handling, and lifecycle governance, all of which shape how trust is established and revoked.
Context
EV certificates are X.509 certificates intended to bind a website to a verified legal entity, but that promise only works if the identity proof behind issuance is something browsers and users can trust. In practice, EV depends on browser expectations, CA validation processes, and dispute handling around names that may already be in use.
For identity programmes, this is not only a PKI question. Certificate issuance, named-entity validation, and ongoing policy enforcement are governance controls that affect brand protection, phishing resistance, and operational accountability when multiple parties can claim the same name or domain context.
DigiCert’s position is that the control surface should extend beyond encryption to include the evidence used to justify identity claims. That makes EV relevant to certificate lifecycle management, domain ownership, and the broader problem of proving who is authorised to speak for a brand online.
Key questions
Q: What breaks when EV certificate issuance relies on legal identity alone?
A: The control breaks when a requester can satisfy registration checks without proving authority over the brand being represented. EV can then validate a legal entity that is not the rightful identity holder for the name users recognise. That gap weakens phishing resistance because the certificate still appears legitimate in a browser.
Q: Why do CAA checks and Certificate Transparency both matter for EV governance?
A: CAA states who may issue, but CT shows what was actually issued. If a CA does not retain CAA verification evidence, or if organisations do not review CT logs, policy becomes difficult to prove and mis-issuance becomes harder to spot. The two controls only work together when intent and outcome are both observable.
Q: How should organisations handle duplicate or disputed brand names in certificate requests?
A: They should treat duplicate names as an identity governance problem, not a helpdesk issue. The decision needs documented authority for who represents the brand, a clear challenge process for conflicting requests, and evidence retention for why one applicant was accepted and another denied. Without that, EV can create name squatting risk.
Q: When does EV add more value than ordinary encryption?
A: EV adds value when the risk is brand impersonation, phishing, or disputed site ownership rather than simple transport security. In those cases, the certificate has to carry a trustworthy identity claim, and the surrounding governance has to make that claim defensible. Without that governance layer, EV behaves more like ordinary TLS than a brand-control mechanism.
Technical breakdown
How EV identity proof works in the certificate lifecycle
Extended Validation ties a certificate request to a legal entity by checking registration details, contactability, and authority to use the claimed name. The trust model depends on whether the CA can reliably distinguish one organisation from another, not just whether the requester can prove control of a domain. If the same name already appears in an existing EV certificate, the request can be flagged for name resolution or dispute handling. That means EV is partly a naming-control system, not just an encryption workflow. The operational weakness is that validation can still be technically correct while being socially ambiguous, especially when different entities share a brand-like name.
Practical implication: Treat EV issuance as a governed identity assertion process, with explicit ownership evidence and dispute workflow, not as a routine certificate order.
CAA records and certificate transparency as control evidence
Certificate Authority Authorization, or CAA, lets a domain publish which CAs may issue certificates, but the article argues that point-in-time checking is not enough if compliance evidence is not retained. Without durable records, a CA can claim a timeout or an incomplete check and the public has little way to verify whether policy was respected. Certificate Transparency closes that evidence gap by making issued certificates observable in public logs, so organisations can monitor for unauthorised issuance and misuse of their names. Together, CAA and CT create a control-and-evidence pair: one expresses policy, the other exposes whether issuance matched that policy.
Practical implication: Require both policy enforcement and retained proof of validation, then monitor Certificate Transparency logs for certificates issued under your names.
Why brand protection changes the meaning of EV certificates
DigiCert’s argument reframes EV as a trademark and reputation control in PKI clothing. The point is not simply that a browser encrypted a connection, but that a user can rely on identity claims attached to a brand they recognise. That introduces governance questions around who can register a name, how duplicate names are handled, and whether smaller or newer organisations can obtain the same identity treatment as established firms. The result is a broader trust model in which identity, naming, and brand legitimacy become part of the certificate’s value proposition. When those elements are weak, encryption still works, but identity assurance does not.
Practical implication: Align certificate policy with brand ownership and naming governance so EV issuance reflects who is authorised to represent the organisation.
Threat narrative
Attacker objective: Obtain browser-trusted identity claims that make a fraudulent or unauthorised site look legitimate enough to support phishing or brand impersonation.
- Entry occurs when a phishing actor or unauthorised requester attempts to obtain an EV certificate for a trusted brand name that users would recognise.
- Credential or authority checks are bypassed when the requester satisfies legal registration and contactability requirements but lacks legitimate trademark or brand control.
- Impact follows when a browser-trusted certificate can support a deceptive site, making brand impersonation harder for users and defenders to detect.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- GitHub code signing certificate theft 2022: A machine account's compromised token cloned GitHub's Desktop and Atom repos, exposing encrypted signing certificates later revoked.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
EV certificates are really identity assertions about brand control, not just encrypted transport. The browser trust model depends on whether the name on the certificate maps to a legal entity that actually has authority over the brand. That is why EV sits closer to identity governance than to pure PKI operations, and why ownership evidence matters as much as cryptographic strength.
Certificate lifecycle governance must include dispute handling, not only issuance and rotation. When one entity can register a name that another entity already uses, the control problem is no longer simply validation failure. The governance challenge is deciding which name-holder is authoritative, then preserving evidence that the decision was made consistently and defensibly.
Certificate Authority Authorization and Certificate Transparency form a paired control pattern. CAA expresses intent, while CT exposes reality after issuance. If the check is not retained and the log is not monitored, organisations lose the ability to prove that certificate policy was followed or detect when it was ignored.
EV squatting is a naming-control problem that PKI alone cannot solve. First-come issuance can lock up identity claims before the rightful brand holder is involved, which means the certificate system can create a governance conflict instead of resolving one. The practical conclusion is that naming policy, trademark authority, and certificate issuance need to be governed together.
Brand protection is now part of the trust architecture around certificates. Users rarely distinguish between technically valid certificates and trustworthy identity claims, so the governance burden falls on CAs and domain owners to make those claims evidentially defensible. That makes EV a test of identity assurance maturity, not just browser compatibility.
From our research library:
- 48% of organisations cite cloud-based services as a driver for PKI deployment, according to the 2023 State of Machine Identity Management report.
- Read next: Machine Identity, PKI and Certificate Lifecycle Guide
What this signals
Identity proof has become the real control plane for EV. Browsers do not merely need a certificate that encrypts traffic. They need a certificate issuance process that can prove who is authorised to use the name, which is why ownership evidence and dispute handling now belong inside certificate governance.
EV squatting shows why naming policy and lifecycle policy cannot be separated. First-come issuance can freeze a brand claim before the rightful holder notices, which means the lifecycle problem starts at request time rather than revocation time. Teams that manage certificate risk should review where brand authority is decided, recorded, and challenged.
Certificate Transparency gives security teams a detection mechanism for identity misuse. If your programme cannot see which certificates were issued under your domains or brands, it cannot reliably distinguish legitimate issuance from impersonation attempts. That visibility gap is what makes monitoring as important as approval.
For practitioners
- Define certificate ownership evidence Document which legal, trademark, and operational records justify issuing EV certificates for each brand or business unit. Make that evidence part of the approval path so issuance reflects authority, not only contact details.
- Retain CAA validation proof Keep auditable records of CAA lookup results, timeouts, and issuance decisions so you can show how policy was applied at the time of request.
- Monitor Certificate Transparency logs Set a regular review process for CT entries involving your domains and brand names, then triage unknown or duplicate certificates as possible abuse or mis-issuance.
- Build a dispute workflow for duplicate names Create an internal process for resolving competing certificate claims when another party requests an EV certificate using a name already tied to your organisation.
Key takeaways
- EV certificates are not just encryption artefacts. They are identity claims that only work when the legal entity, brand authority, and browser-trusted proof line up.
- The article shows that duplicate names, disputed ownership, and weak disclosure create a governance problem that can outlive the certificate itself.
- Organisations should manage EV issuance with the same discipline they apply to lifecycle controls, evidence retention, and name authority decisions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-57 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Certificate issuance evidence and name control are central to this EV governance discussion. |
| NHI-10 — Human Use of NHI | EV certificates are human-recognisable identity claims used to represent organisations on the web. | |
| Recommendation — Track certificate issuance evidence and revoke any policy path that exposes unauthorised identity claims. Govern EV issuance so human-facing identity claims are approved and evidenced before certificates are issued. | ||
| NIST SP 800-57 | Part 1 — Key Management Lifecycle | The article discusses issuance, validation evidence, and lifecycle governance around certificates and trust anchors. |
| Recommendation — Apply key lifecycle governance to certificate issuance, evidence retention, and revocation handling. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Brand-authorised issuance is an entitlement problem: who is allowed to speak for the identity. |
| GV.OC-01 — Organizational Context | The article frames EV as part of business identity, brand protection, and organisational legitimacy. | |
| Recommendation — Align certificate approvals with explicit authorisation for the represented identity. Document which brands, legal entities, and domains each certificate policy is meant to protect. | ||
Key terms
- Extended Validation Certificate: An Extended Validation certificate is a public certificate that links a website or service to a verified legal entity. In practice, it is meant to strengthen trust by connecting technical encryption with organizational identity, but its value depends on how well issuance, naming, and dispute controls are enforced.
- Certificate Authority Authorization (CAA): CAA is a DNS record that tells certificate authorities which entities may issue certificates for a domain. Its governance value depends on the CA proving it checked the record and on the domain owner being able to evidence that policy was respected during issuance.
- Certificate Transparency: Certificate Transparency is a public logging system for certificates issued by major certificate authorities. It helps investigators link public keys to issued certificates, but it is a discovery layer, not a remediation control, and it does not revoke compromised material by itself.
- Brand Protection: Brand protection in certificate governance means using identity controls to prevent misleading or unauthorised use of a company’s name online. In this article’s context, it is the practical reason EV certificates matter, because the trust goal is not only encryption but defensible identity claims.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org