If your website still runs on http:// rather than https://, your browser is actively warning visitors away from it. Chrome, Firefox, Safari — they all flag it. Not buried in settings. Right there in the address bar, before anyone reads a word.
An SSL certificate fixes that. Here’s what it actually is, why it matters, and what you need to do about it.
What Is an SSL Certificate?
SSL stands for Secure Sockets Layer. It’s a digital certificate that does two things: it confirms your website is who it claims to be, and it encrypts the data travelling between your site and anyone visiting it.
The practical result is https:// in your URL instead of http://, and a padlock in the address bar. That padlock is the browser’s way of telling visitors the connection is secure.
Technically, SSL has been replaced by something called TLS — Transport Layer Security — which is what every website actually runs on now. The term SSL stuck anyway, so that’s what everyone calls it, including your hosting provider and most of the internet. The ICO’s updated guidance (November 2025) specifically warns businesses away from old SSL protocols and requires TLS for any online application handling personal data. Same padlock, better technology underneath.
The plain-English version: an SSL certificate is proof your site is legitimate, and a guarantee that anything a visitor submits — a contact form, login credentials, a business enquiry — can’t be read by anyone intercepting the connection between them and you.
How It Actually Works
When you visit a website, your browser and that site exchange a quick, invisible check before anything loads. The site presents its SSL certificate — issued by a trusted third party called a Certificate Authority — your browser verifies it’s legitimate and hasn’t expired, then an encrypted connection opens. All of this happens in milliseconds before the page appears.
Think of it as showing ID at a door before being let into a private room. The ID doesn’t tell you anything about what’s in the room — it just confirms you’re in the right place and nobody else is listening at the door.
Once that connection is established, everything passed through it is encrypted. That means contact form submissions, login details, payment information, business enquiries — none of it can be read in transit, even if someone intercepts it.
If there’s no certificate, or it’s expired, the browser refuses to open the door quietly. It puts a warning in the way instead.
Why It Matters for B2B Websites
The browser warning is the most visible consequence. Chrome, Firefox, and Safari all flag sites without a valid certificate — not as a footnote, but as a message in the address bar before a visitor has read anything. For a B2B site asking potential clients to fill in a contact form or share business details, that warning is a hard stop.
Research consistently shows the majority of users won’t engage with a site flagged as insecure. That’s not a conversion problem — that’s a credibility problem, and no amount of good copy or strong case studies fixes it if visitors leave before they reach them.
Beyond trust, there are two practical considerations:
Search visibility. Google confirmed HTTPS as a ranking signal in 2014 and it remains active. It’s a lightweight factor — it won’t rescue a weak page — but in competitive search results, it counts.
UK GDPR compliance. The ICO’s updated guidance (November 2025) is unambiguous: organisations must use TLS encryption for online applications handling personal data. A contact form without HTTPS isn’t a technical oversight — it’s a compliance exposure. The ICO’s position is that running without it “may result in noncompliance with UK GDPR security obligations.”
All three of these — trust, search, compliance — are solved by the same certificate.
Types of SSL Certificate
There are three. Most articles make this more complicated than it needs to be.
Domain Validation (DV) confirms you own the domain, nothing more. It’s the most common type, it’s what Let’s Encrypt issues for free, and it’s what the majority of websites run on. For a blog or a basic informational site, it’s fine.
Organisation Validation (OV) goes a step further — the Certificate Authority verifies your domain ownership and confirms you’re a legitimate registered business. The connection is encrypted the same way, but the certificate contains verified company information. For a B2B site where you’re asking people to trust you with an enquiry or a budget conversation, OV is worth considering.
Extended Validation (EV) was once the gold standard — it triggered a green address bar in browsers showing your company name. Browsers removed that in 2019. EV certificates still exist and still carry the most rigorous identity checks, but the visual payoff that made them worth the premium is gone. Unless you’re in financial services or enterprise, you don’t need one.
For most B2B businesses: OV if you want the verified business identity in the certificate, DV if your host includes it and you want to get moving without the cost.
How to Get One and What It Costs
Start by checking your hosting provider. Most major hosts — 20i, SiteGround, WP Engine, Kinsta, and others — include a free SSL certificate and handle renewal automatically. If yours does, you may already have one and just need to make sure it’s active.
If your host doesn’t include one, Let’s Encrypt is the place to start. It’s a free Certificate Authority used by millions of websites worldwide. Certificates are valid for 90 days and renew automatically if your host supports it — which most do.
For a paid certificate, DV starts at around £8 per year. OV — with verified business identity — starts at around £100 per year. You can buy directly from a Certificate Authority like Sectigo, or through your hosting provider.
One thing worth getting right: renewal. Certificates expire, and an expired certificate throws a full-page browser warning — more alarming to visitors than no certificate at all. If you’re managing renewal manually, set a reminder at least 30 days out. If you’re on Let’s Encrypt through a managed host, it handles itself.
The short version: if your host includes SSL, turn it on. If it doesn’t, Let’s Encrypt costs nothing and takes minutes to set up. Paid options are there if you need OV validation — but free covers most B2B sites without issue.
What to Do Now
SSL certificates aren’t a technical nice-to-have. They’re the baseline expectation for any website asking visitors to trust it with their time, their details, or their business.
Check your address bar. If it shows http:// rather than https://, or if there’s a warning where the padlock should be, this is fixable today — and in most cases, free.
Our web design clients never have to bother about there SSL certificate, as we keep them updated automatically.