Back to blog

SSL certificates: why every website needs one

SSL certificate and website data protection with a padlock in deep navy and cyan

A client wrote to us worried because Chrome was showing a red "Not secure" warning right above the checkout form on his online store. Sales had dropped sharply over the previous week, and the cause turned out to be an expired SSL certificate nobody had renewed on time. The fix took an hour, but the trust lost from customers who saw that warning does not come back nearly as quickly.

An SSL certificate is a small technical detail with a large impact. It is the reason your site's address starts with https instead of http, and the reason the browser shows a padlock next to it. Without one, every modern browser actively warns visitors before they even see the content of the site.

What an SSL certificate is

SSL, short for Secure Sockets Layer, is technology that encrypts the connection between a visitor's browser and the site's server. In practice this means the data being exchanged, passwords, card numbers, personal information from forms, travels encrypted and cannot be read by a third party even if intercepted along the way.

The certificate is issued by a trusted authority that confirms the domain genuinely belongs to the applicant. That chain of trust is exactly why browsers show a padlock instead of a warning.

One clarification worth making: the modern standard is technically called TLS, the successor to the older SSL protocol, but the terms SSL certificate and SSL are used everywhere in practice as a synonym for TLS.

What happens without an SSL certificate

Since the middle of the previous decade, Chrome, Firefox and Safari have actively flagged sites without SSL as "Not secure", showing a warning right in the address bar. For a visitor seeing that for the first time, the reaction is almost always distrust and leaving the page.

The effect is especially strong on forms and online stores, where personal data gets entered. A customer ready to pay who sees a security warning right before the payment button abandons the purchase in a huge share of cases. The loss is not abstract, it is directly measurable in abandoned orders.

Types of SSL certificates

TypeLevel of verificationBest suited for
Domain Validation (DV)Verifies only domain ownershipBlogs, small brochure sites, most business sites
Organization Validation (OV)Also verifies company registrationBusiness sites wanting extra trust signals
Extended Validation (EV)Full legal verification of the organisationBanks, financial institutions, high risk sites
WildcardCovers the main domain and all subdomainsSites with multiple subdomains, e.g. a store and a blog

For most small and mid-sized businesses, a plain DV certificate is entirely sufficient. The price difference against the benefit of OV or EV rarely pays off outside finance and healthcare.

SSL and SEO: does it really affect rankings

Google officially confirmed years ago that https is a ranking factor, though a weak one compared with content and backlinks. The bigger effect is indirect: a site without SSL shows a warning, visitors leave quickly, and the resulting high bounce rate itself hurts rankings over time.

There is also a practical barrier. Many modern features, like browser autofill for forms or integration with certain advertising platforms, require the site to run on https. Without SSL, some tools simply refuse to work correctly.

Encrypted data protection and an SSL certificate for a secure website

How to install SSL on your site

Step 1: check whether hosting already includes SSL

Most modern hosting providers include a free SSL certificate through Let's Encrypt in the standard package. Checking this is the first and fastest step.

Step 2: activate the certificate

On shared hosting, activation is usually one click from the control panel. On custom servers it requires manual installation by a developer.

Step 3: redirect all traffic from http to https

A technically mandatory step, so part of the site does not remain accessible on the insecure address alongside the new one.

Step 4: check for mixed content

After the switch, some old images or scripts may still point to http addresses, which breaks the padlock even with an active certificate.

Step 5: update Google Search Console

Add the new https version of the site to Search Console so ranking tracking continues without interruption. If you have not set up the tool yet, see our guide to Google Search Console.

Common SSL problems

Mixed content. Part of the page loads over an insecure path even though the main connection is protected, which the browser flags with a warning icon.

Expired certificate. Free certificates usually renew automatically every 90 days, but a misconfiguration can make renewal fail silently until it is too late.

Wrong certificate coverage for subdomains. A main domain with SSL but an uncovered subdomain leaves a whole part of the site unprotected.

Cached old versions. Sometimes the browser shows a warning for a while after the switch because of caching, which misleads the owner into thinking the problem still exists.

SSL for online stores and payments

For an online store, SSL is not a recommendation, it is a mandatory requirement. Processing card data requires compliance with the PCI DSS standard, and a baseline condition for that is an encrypted connection everywhere payment data is entered. Payment providers in most markets simply refuse to integrate with a site that lacks a valid SSL certificate. If you run or are planning an online store, SSL is the first thing that needs to be in place before you even discuss payment methods.

Maintenance and renewal

Free certificates require automatic renewal that should be checked regularly, not assumed. Paid OV and EV certificates require manual renewal once a year, and a calendar reminder is good practice, because a missed deadline means going back to the "Not secure" warning for every visitor.

Frequently asked questions

Is an SSL certificate free?

Standard DV certificates through Let's Encrypt are completely free and included in most modern hosting packages. Paid options exist for companies wanting extra legal verification through OV or EV.

How do I know if my site has SSL?

Check your browser's address bar. If the address starts with https and shows a padlock, the certificate is active. Clicking the padlock shows details about the issuer and expiry date.

Does an SSL certificate really improve Google rankings?

It has a direct but weak effect, and an indirect one through lower bounce rates and visitor trust. It is not a magic SEO fix, but its absence is a real obstacle.

How often does an SSL certificate need renewing?

Free certificates through Let's Encrypt renew every 90 days, usually automatically. Paid annual certificates require manual renewal once a year.

Can I have SSL on only certain pages of my site?

Technically possible, but not good practice. The modern standard is for the entire site to run on https, including all subdomains, to avoid mixed content and warnings.

What to do next

Open your site right now and check the address bar. If the padlock is missing or you see a warning, that is a priority ahead of nearly everything else in your marketing, because it directly scares off potential customers.

We can check the current state of your SSL certificate, install or renew it, and review the site for mixed content. Get in touch with your site's address for a free check.

Ready to get started?

Contact us for a free consultation and a quote within 24 hours.