What SSL does and does not do
SSL, more accurately TLS, encrypts what travels between browser and server, so passwords and card details cannot be read along the way. What SSL does not do: it does not guarantee the company behind the site is honest. The padlock means the connection is encrypted, not that the seller is reliable. Fraudsters have padlocks too, because it is free for them as well.
Do you have to pay
Usually not. Let's Encrypt issues free certificates supported by every browser, and most hosts include them at one click. A paid certificate makes sense in two situations: when you need multiple subdomains covered under particular terms, or when a business partner explicitly requires a certificate with legal entity validation. For an ordinary business site or store, free is entirely sufficient.
Why it is mandatory
Browsers mark sites without SSL as not secure, and every visitor sees that before reading anything. Google has used HTTPS as a signal since 2014. And if you receive any data through a form, working without encryption is a legal problem as well as a technical one.
Common problems
- An expired certificate, because free ones last ninety days and must renew automatically.
- The site runs on https but some images and scripts load over http, so the padlock disappears.
- The certificate covers the domain without www while the site opens with www, or the reverse.
With us certificates and their renewal are part of hosting and maintenance.