Home / Guides

Do you need to pay for SSL? No. Here's why.

You need SSL — every site does. But paying for it is a different question, and for almost everyone the honest answer is: the thing being sold to you for $50–$100 a year has been free since 2016.

The short answer

Yes, your site needs SSL. No, you should not be paying for it. Free certificates from Let's Encrypt and the ones bundled by every serious host provide identical encryption to the $99 versions. If there's an "SSL certificate" line on your hosting or domain bill, you're paying a markup on something the modern web gives away. Check your site free → — the grader flags HTTPS problems automatically.

Get your exact price in 60 seconds → Free calculator · itemized · no email required
01 · What it is

SSL in one paragraph

SSL (technically TLS these days, but everyone still says SSL) is what puts the padlock in the address bar and the s in https. It encrypts the traffic between your visitor's browser and your site, so passwords, form submissions, and card details can't be read in transit. Without it, Chrome and Safari stamp your site "Not secure" right where your phone number should be earning trust.

So the "do I need it" half of the question is settled: every website needs it — brochure sites included. It's been a lightweight Google ranking signal since 2014, and more importantly, that browser warning quietly costs you visitors who never tell you why they left.

02 · Why it's free now

The $100 product that stopped existing in 2016

For years, certificates genuinely cost money — issuing them involved manual checks, and a handful of certificate authorities charged accordingly. Then Let's Encrypt launched: a nonprofit certificate authority (backed by Mozilla, the EFF, Cisco, and others) that automated the whole process and issues certificates free, to anyone, forever. It now secures hundreds of millions of websites.

The rest of the industry followed. Cloudflare bundles free SSL with every account. Modern hosts — Netlify, Vercel, Cloudflare Pages, most quality shared hosting — provision certificates automatically. Site builders like Squarespace, Wix, and Shopify include it in the subscription. The certificate itself has become plumbing: invisible, automatic, and free.

Every site we build ships with SSL configured from day one — it's part of the build, not a line item. If someone quotes you a website and SSL appears as a separate charge, ask what else on the quote works that way.

03 · Who still charges

So why is it on your bill?

Because checkout upsells work. Some registrars and legacy hosts still sell "Positive SSL," "Standard SSL," or "SSL Certificate" products at $30–$100 per year. Here's the part they don't put on the pricing page: those are domain-validated certificates — the exact same validation level Let's Encrypt issues free. Same encryption strength, same padlock, same everything the visitor ever sees.

The traditional justifications, examined honestly:

  • "Higher validation levels." OV and EV certificates verify your business identity on paper. Browsers used to reward EV with a green company-name bar; they removed it years ago. Visitors can no longer tell the difference without six clicks into certificate details.
  • "It comes with a warranty." The warranty covers a certificate-authority failure scenario so rare there's no meaningful record of small businesses ever collecting. It exists to make the invoice feel justified.
  • "Free certificates expire every 90 days." True — and they renew themselves automatically. That's the design, not a flaw. You never touch it.

Legitimate reasons to pay do exist at the edges — certain compliance regimes and enterprise policies require OV/EV certificates. If that's you, you already know. If you're a local business with a marketing site, it isn't you.

04 · Getting it free

How to stop paying, by situation

  • On Squarespace, Wix, or Shopify: you already have free SSL — it's in the subscription. If you're also paying a registrar for a certificate, that money is doing nothing. Cancel the add-on.
  • On shared hosting (GoDaddy, Bluehost, etc.): look for "Let's Encrypt" or "free SSL" in your control panel — many hosts support it while advertising only the paid product. If yours truly doesn't, that's a host worth leaving; see our domain transfer guide for the companion move.
  • Any site, any host: putting Cloudflare (free plan) in front of your site gives you SSL plus a global CDN, regardless of what your host supports.
  • Our clients: SSL is included in every build and in Hosting & Care. It isn't a product. It's a default.

While you're auditing that bill: SSL is rarely the only padding on it. The companion guide — domain add-ons you shouldn't pay for — covers the rest of the checkout upsells.

Free — the 1-page version

The Domain-Bill Audit Checklist

Ten line-by-line checks to run against your registrar bill — the whole guide condensed to one page you can finish in five minutes. Drop your email and it unlocks right here.

No spam, no calls unless you ask. We'll only email you if you reply first.

The Domain-Bill Audit — 10 checks

Run these against your registrar account and last invoice.

  1. Renewal price: a .com should renew at $10–16. Above $20? Plan a transfer.
  2. SSL line item: any charge for a certificate = cancel it; free SSL is identical.
  3. WHOIS/domain privacy: if it's a paid line, your registrar charges for what good ones include free.
  4. "Protection" or "lock" bundle: transfer lock is a free standard feature. Cancel the paid version.
  5. Premium DNS: cancel; Cloudflare's free DNS outperforms it.
  6. Security scanner add-on: cancel; it mostly notifies you after problems on sites that shouldn't have them.
  7. Email upsell: if you pay your registrar for mailboxes, price Google Workspace instead.
  8. Auto-renew: ON. This is the one that prevents catastrophe.
  9. Card + contact email current: most lost domains are expired cards and unread warnings.
  10. Registered to YOU: not your designer, not an old agency. It's the deed — hold it.

Common questions

The things people ask us

Is free SSL as secure as paid SSL?

Yes — identical encryption. A free Let's Encrypt certificate and a $99 "Positive SSL" both provide the same TLS encryption, the same padlock, the same browser treatment. What you're paying for with the paid one is the invoice.

Will Google rank my site lower without SSL?

HTTPS has been a lightweight ranking signal since 2014, but the bigger cost is the browser itself: Chrome marks plain HTTP "Not secure" in the address bar, and visitors bail. Every site should be on HTTPS — it just shouldn't cost anything.

My host charges $79/year for SSL. Should I switch?

It's a strong signal about the rest of their pricing. Ask them to enable a free certificate first — many hosts quietly support Let's Encrypt while advertising only the paid option. If they refuse, that $79 usually has cousins elsewhere on your bill.

What about the warranty on paid certificates?

It pays out only if the certificate authority itself mis-issues in a way that directly causes provable loss — a scenario with no meaningful record of ordinary businesses ever collecting. Warranty theater.

Is it different for online stores?

You need HTTPS everywhere, but a free domain-validated certificate satisfies that. Card data almost never touches your server anyway — Stripe, Square, and Shopify Payments handle it on their own infrastructure.

Check yours in 30 seconds

Is your site secure — and fast?

The free grader checks HTTPS, real load speed, and SEO fundamentals with Google's own data.