

Sometimes developments on the internet happen extremely quickly. When I originally wrote this blog in 2017, SSL certificates were often expensive, the options were confusing and many website owners were still questioning whether they really needed one.
Things have changed considerably since then.
Today, an SSL certificate is essential for every website, not merely those that accept card payments or collect sensitive information. The good news is that most reputable hosting providers now include a free SSL certificate from Let’s Encrypt, so securing your website should not cost you anything extra.
If you have found this article by searching for “what is an SSL certificate?”, here is what it does, why your website needs one and why you should probably not be paying £150 a year for something that a decent hosting provider will supply and renew automatically.
SSL originally stood for Secure Sockets Layer. Strictly speaking, modern websites now use TLS, or Transport Layer Security, which replaced the older SSL technology. However, almost everyone still calls it an SSL certificate, so that is the term I will use throughout this article.
An SSL certificate is a digital certificate that helps confirm the identity of a website and allows information to be transmitted securely between the website and the person visiting it.
When an SSL certificate has been installed and configured correctly, the website address begins with https:// rather than http://. Modern browsers may also display an icon next to the website address that allows you to view information about the connection and the certificate.
The important part is the “s” in HTTPS. It tells you that the connection between your browser and the website is encrypted.
This means that information passing between you and the website cannot easily be read or altered by someone attempting to intercept it. This includes information entered into contact forms, login details, personal information and payment details.
No. This is one of the most common misunderstandings about SSL certificates.
An SSL certificate secures the connection between the visitor and the website. It does not guarantee that the website itself is safe, trustworthy or protected from every possible attack.
A website with an SSL certificate can still be hacked if its software is out of date, its passwords are weak or its hosting environment is insecure. Equally, a fraudulent website can have a valid SSL certificate. The certificate confirms that the connection is encrypted, but it does not necessarily prove that the people running the website are honest.
Think of it as sending something through a locked delivery system. The lock protects the contents while they are being transported, but it does not tell you whether the person at the other end is someone you should trust.
This distinction matters. An SSL certificate is an essential part of website security, but it is not a replacement for secure hosting, properly maintained software, strong passwords, backups and ongoing website maintenance.
Yes. There is no longer a meaningful argument for running a public website without one.
In 2017, people often suggested that SSL certificates were only necessary for websites accepting payments. That is no longer sensible advice.
Your website should use HTTPS if it has:
In reality, even a simple website without any of these features should still have an SSL certificate. Modern browsers expect websites to use HTTPS and may warn visitors when a connection is not secure.
Those warnings undermine confidence. If someone visits your website and their browser suggests that it may not be secure, they are unlikely to stop and investigate the technical details. They may simply leave.
Your website still needs an SSL certificate.
It is true that payment services such as PayPal, Stripe and Worldpay normally process sensitive card information on secure systems rather than passing it directly through your website. This helps reduce the security and compliance burden placed upon you.
However, this does not mean that the rest of your website can safely remain on HTTP.
Your visitors may enter personal information before reaching the payment provider. They may also return to your website after completing their payment. Moving between a secure payment service and an insecure website can cause warnings, create uncertainty and make the entire transaction feel less trustworthy.
People are understandably cautious when making payments online. Giving them a consistently secure experience throughout the process is essential.
Yes. In most cases, you should be able to get one without paying anything extra.
Let’s Encrypt is a widely trusted, non-profit certificate authority that provides free SSL certificates. Many reputable hosting providers include Let’s Encrypt certificates within their hosting packages and configure them to renew automatically.
This has transformed the situation since this article was first written.
You no longer need to spend approximately £150 each year simply to give an ordinary website a secure HTTPS connection. A free Let’s Encrypt certificate provides the encryption required by the vast majority of business, charity and personal websites.
The word “free” does not mean the certificate is less secure or less trusted by browsers. Free and paid certificates can use the same modern encryption standards. The main differences usually relate to how the identity of the organisation is validated, the number of domains covered, the support provided and any warranties offered by the certificate supplier.
Some larger organisations may have particular technical or administrative reasons for purchasing a specialist certificate. However, for most ordinary websites, a properly configured and automatically renewed Let’s Encrypt certificate is perfectly adequate.
If your hosting provider still wants to charge you a large annual fee for a basic SSL certificate, it would be reasonable to ask exactly what you are receiving for that money.
The way encryption was commonly described in the past created a lot of confusion.
You may still see references to 128-bit or 256-bit encryption and 2048-bit keys. These numbers do not form a simple ladder where paying for a certificate with a larger number automatically makes your website more secure.
A 2048-bit figure will commonly refer to the size of an RSA public key, while 128-bit and 256-bit figures may refer to the symmetric encryption used during the secure connection. These are different parts of the process and cannot be compared directly.
For most website owners, there is no need to choose a certificate based upon the largest number used in its marketing. Your hosting provider should configure the server to use current TLS protocols, suitable cryptographic keys and modern security settings.
The quality of the hosting configuration and the reliable renewal of the certificate are far more important than an impressive-looking number on a sales page.
HTTPS has been used by Google as a ranking signal since 2014. However, Google described it as a lightweight signal rather than one of its strongest ranking factors.
This means that installing an SSL certificate will not suddenly send your website racing to the top of Google. Content quality, relevance, authority, usability and the overall experience offered by the website remain much more influential.
However, this does not make HTTPS optional.
Google expects websites to provide a secure experience. Browsers warn people about insecure connections, and visitors are less likely to trust or use a website that does not have an SSL certificate. HTTPS is also required for several modern browser features and web technologies.
Therefore, while an SSL certificate is not an SEO magic wand, it is an essential technical foundation for a modern website. If 2 otherwise similar websites were competing for the same position, it would make little sense to be the one still using an insecure connection.
Firstly, check whether your website address begins with https://.
You should then confirm that the certificate is valid, covers the correct version of your domain and renews automatically. You should also make sure that visitors using an old http:// address are redirected automatically to the secure https:// version.
Every page, image, script and stylesheet should load securely. If an HTTPS page attempts to load some of its content over an insecure HTTP connection, this is known as mixed content. Browsers may block that content or continue to display security warnings.
You should also ensure that:
A good hosting provider should handle the certificate installation, server configuration and automatic renewal for you.
An SSL certificate enables an encrypted HTTPS connection between a website and its visitors. It protects information while it is being transmitted and helps visitors feel confident that their connection is secure.
It does not prevent every type of hacking and it does not prove that the owner of a website is trustworthy. It is nevertheless an absolutely essential part of running a modern website.
Most importantly, an ordinary business website should not need to pay a substantial annual fee for one. A reputable hosting provider should be able to supply and automatically renew a trusted Let’s Encrypt SSL certificate as part of its hosting service.
If your website is still running on HTTP, now is the time to get it sorted.
Clive Loseby
Access by Design. Accessible web design, website accessibility audits and managed hosting.
Whether you are planning a new website, reviewing an existing platform or trying to understand your accessibility obligations, we would love to help.
Please get in touch to discuss your project, accessibility goals or digital challenges.