Sectigo PositiveSSL
- Covers one hostname (apex + www)
- Issued in minutes after DV
- $50,000 warranty
- Free unlimited reissues
- Trusted in every browser since 2002
A single-domain SSL certificate secures your site with the apex and www covered together. Choose the validation level and brand; we handle issuance and remind you before expiry.
Prices are the full cost for the chosen term. Longer terms lower the average yearly price.
Pick a billing period
No products match your filter.
Prices without VAT; Latvian VAT is 21% where it applies. Prices follow the certificate authorities daily.
From 24 February 2026 a public SSL certificate is issued for up to 199 days, so the file is shorter lived than before. It is a security win: short-lived certificates are much harder to abuse if a key ever leaks. Your multi-year price here does not change and there is no extra cost. At each interval you reissue the certificate yourself in the client panel, which shows how many days are left.
A certificate now lasts about 199 days, so a one-year order is reissued partway through the term. Every reissue within your paid term is included at no extra cost.
At each interval you reissue the certificate in the client panel in a single click. The panel shows how many days are left before you need to.
Reissues within the term you already paid for are free. You only pay again when the whole term ends and you renew for a new period.
We are rolling out a free agent you install on your server that fetches each reissue and reloads the web server automatically, so the certificate never lapses.
Proves control of the domain. Issued in minutes, ideal for websites, blogs and APIs.
Adds your verified company details to the certificate. Takes 1 to 3 days, fits business sites.
The strictest vetting and the highest warranties. For banks, fintech and e-commerce.
Every certificate chains to a root trusted by all mainstream browsers and operating systems.
Root trusted since 2002 and home of the PositiveSSL family, the best-value DV line on the market.
Premium DV, OV and EV certificates on a root trusted since 2007, favoured by enterprises.
DigiCert's budget DV brand: fast issuance and a low price for straightforward sites.
A DigiCert sub-brand with history back to 1995 and high warranty amounts across the range.
Pick the certificate and term, then paste the CSR from your server or let us generate one.
DV confirms by DNS record or email in minutes; OV and EV add company checks by the CA.
Install the issued bundle, or we install it for you on our hosting. We remind you before renewal.
New CA/Browser Forum rules cut the maximum validity of a public SSL certificate step by step, down to just 47 days by 2029.
A 47-day certificate means 8 or more renewals every year, so automation becomes the only practical way to stay secure. On our multi-year plans the price never changes. Today you reissue the certificate yourself in the client panel at each interval; if you want it hands-off, our ACME certificate renews automatically.
How-tos on certificates, validation, HTTPS and web security from our team.
Single-domain SSL certificates start at 7.31 EUR a year for Sectigo PositiveSSL, a domain-validated certificate issued within minutes of validation. The price you see in our table is the full cost for the whole term you choose, not a monthly figure, so there are no hidden charges later. OV and EV certificates cost more because the certificate authority verifies your company before issuing, which takes extra work on their side. Choosing a longer term, up to 5 years, lowers the average yearly price, so if you plan to keep the domain, a multi-year order is usually the cheaper route. If you are unsure which level you need, write to support and describe your site.
Yes. Every single-domain certificate in our range secures the apex domain and the www hostname together, so one order covers both addresses and visitors see a valid connection whichever form they type. You do not need to buy two certificates or set up redirects just to avoid a browser warning. Keep in mind that this pairing applies only to www: any other subdomain, for example mail or shop, is a separate hostname and needs its own certificate or a different certificate type. When you submit the CSR, use your main domain name and the paired coverage is applied automatically at issuance, with nothing extra to configure on your side.
DV certificates are usually issued within minutes, because the only check is that you control the domain, confirmed by a DNS record or an email to the domain. The clock starts once validation is complete, so responding quickly to the confirmation step is what actually decides the speed. OV takes 1 to 3 business days: the certificate authority verifies your company details before adding them to the certificate. EV can take up to a week, since the vetting is the strictest. If a launch date depends on the certificate, order OV or EV in advance and keep your company records consistent, as mismatched details are the most common cause of delay.
Browsers cap the lifetime of a single certificate at about 199 days, a limit set by CA/B Forum rules, so a 3-year order cannot be one long certificate. Instead we deliver it as consecutive certificates within the term you paid for. When each interval approaches, you reissue the certificate in the client panel with one click, and every reissue inside your paid term is free. The panel shows how many days remain, so you always know when action is due. You only pay again when the whole term ends. We are also rolling out a free agent for your server that fetches each reissue and reloads the web server automatically.
The warranty is insurance from the certificate authority: if the CA mis-issues a certificate and a relying party, for example a customer of the site, suffers a loss because of that mistake, the CA covers the damage up to the stated amount. Higher-end certificates carry warranties up to 1.25M USD. It is worth knowing what the warranty is not: it does not insure you against your own server being hacked or your site failing, it only covers CA error, which is rare in practice. That is why the amount is best read as a signal of how strict the CA's vetting is, and why OV and EV certificates carry the larger figures.
A single-domain certificate covers only the apex and www, so for anything beyond that you have two options. A multi-domain SAN certificate secures several different domains in one certificate, which is convenient when you run a few sites or services under separate names. A wildcard certificate covers unlimited subdomains of one domain, so shop, mail and any future subdomain are protected without new orders. We sell both, alongside ACME subscriptions for automated issuance where certificates are requested and renewed by software. Which one is cheaper depends on how many names you have and how often they change, so if the choice is not obvious, write to support with your list of hostnames.
Yes. Every certificate we sell chains to a root that all mainstream browsers and operating systems trust, on desktop and mobile alike. Sectigo roots have been trusted since 2002 and DigiCert roots since 2007, long enough that they are present in effectively every device your visitors use, so they see the padlock rather than a warning. The realistic caveat is installation, not trust: if the intermediate part of the bundle is missing on your server, some clients will still complain even though the certificate itself is fine. Install the full delivered bundle, and if a visitor reports a warning, contact our support and we will help you check the chain.
Yes, with one distinction. If your site runs on our hosting, we install the issued certificate for you and there is nothing to configure on your side. If the certificate is for your own server, you receive the full bundle after issuance and install it yourself, and our support can guide you through the steps for your specific web server. If you do not want to create a CSR yourself, we can generate one during the order. In both cases we remind you before renewal, so the certificate does not quietly lapse and take HTTPS down with it. If anything looks wrong after installation, write to support and we will look at it together.
Deploy in minutes or talk to an engineer about what fits your project.