If your website address starts with HTTP rather than HTTPS, browsers are flagging it as “Not Secure” every time someone visits, before they’ve read a single word about your business. Fixing that is what an SSL certificate does. This guide covers what it actually is, why a UK business site needs one, what changed in March 2026, and what’s coming next.
What Is an SSL Certificate?
SSL stands for Secure Sockets Layer, a security protocol that encrypts the connection between your website and anyone who visits it. When someone lands on your site, the certificate scrambles the data exchanged between their browser and your server, so it can’t be intercepted or read in transit.
You’ll also see the term TLS, Transport Layer Security, which is the modern, updated version of SSL. The two terms get used interchangeably in everyday conversation, and the technical distinction doesn’t matter much for a business owner. What matters is the result: a secure, encrypted connection visitors and browsers can trust.
How Can You Tell If a Website Has One?
Look at the address bar. A site with a valid certificate shows HTTPS at the start of the URL with a padlock icon next to it. Without one, Chrome, Firefox and most modern browsers show a “Not Secure” warning before a visitor has even reached your content, and in most cases, they leave rather than click through it.
Why Your Business Website Needs One
1. Visitors Don’t Trust a “Not Secure” Website
A browser security warning changes how people feel about your business before they’ve had a chance to engage with it. Research from DigiCert confirms that visitors are far less likely to trust websites displaying security warnings, which affects enquiries, sign-ups and sales directly. That’s potential customers leaving before you’ve had a chance to speak to them.
2. Google Uses HTTPS as a Ranking Signal
Google has confirmed HTTPS as a ranking factor, so a site still running on HTTP is at a disadvantage in search results even when everything else about its SEO is solid. If you’re competing for visibility against other UK businesses in your sector, going without a certificate hands them a head start for free.
3. UK GDPR Expects It Wherever Personal Data Is Collected
UK GDPR requires businesses to put appropriate technical safeguards in place to protect personal data. If your site has a contact form, an email signup, or a customer login, it’s collecting personal data, and a certificate is part of meeting that obligation. Businesses taking card payments online also need to meet PCI DSS, which requires an encrypted connection as a baseline. Neither of these is optional.
4. It Protects Visitors’ Data in Transit
Without SSL, data sent between your website and a visitor travels as plain text: names, email addresses, passwords, enquiry details, all readable if intercepted. SSL turns that into unreadable code, so even if someone does intercept it, they can’t use it.
What Changed for SSL Certificates in 2026, and What’s Coming Next
This matters most if your business manages its own certificate rather than leaving it to a hosting provider. Browser makers and certificate authorities agreed a staged reduction in maximum certificate lifetime, aimed at closing the window a compromised or outdated certificate can stay valid for.
If your website is on managed hosting with automatic SSL renewal, your provider handles this and there’s nothing for you to do. If your team manages certificates manually, your renewal workload has already roughly doubled, and it’s going to keep shrinking from here. Miss a renewal and your site shows as insecure to every visitor until someone fixes it, which is lost traffic and lost trust while you scramble to sort it.
What Types of SSL Certificate Are There?
There are three main types, and the right one depends on what your website does.
Domain Validated (DV)
Confirms the certificate holder owns the domain. Quick to issue, low cost, and often free through providers like Let’s Encrypt. Adequate for the majority of UK small business websites.
Organisation Validated (OV)
The certificate authority checks that your organisation is legitimate before issuing it. A stronger trust signal, typically used by businesses handling more sensitive information.
Extended Validation (EV)
The highest level of checking on your organisation before issue. Typically used by financial institutions, healthcare providers, and businesses where maximum visible trust matters most.
For most UK small and medium-sized businesses, a DV or OV certificate covers everything needed.
Does a Free Certificate Do the Same Job?
For encryption, yes. A free certificate from Let’s Encrypt provides the same level of encryption as a paid one. The differences sit in validation level, warranty protection and support: free certificates are DV only and auto-renew if set up correctly through your hosting provider, while paid options add OV or EV validation, dedicated support, and sometimes a financial warranty.
For a standard UK business website with a contact form and service pages, a free certificate is entirely adequate. For e-commerce at scale, or a business handling sensitive client data in volume, it’s worth a conversation about whether a higher validation level makes sense.
What Happens If Your Certificate Expires?
Your website becomes inaccessible in any practical sense. Browsers show a full-screen warning before visitors can even reach the page, and most people don’t click past it. Search rankings can drop quickly too, since search engines take note once a certificate lapses.
This is exactly why the 2026 renewal changes matter more than they might first seem. A business used to renewing once a year now needs to do it roughly twice, and that gap keeps closing over the next few years. One missed reminder and you’ve got a site actively turning visitors away until it’s fixed. Having a professional manage this as part of a wider website maintenance service removes that risk; you won’t be the one watching expiry dates.
Getting and Keeping Your SSL Certificate Sorted
- Type your website address into a browser and confirm it shows HTTPS and a padlock, not a “Not Secure” warning
- Check your hosting control panel for a certificate that’s included and set to auto-renew
- If certificates are managed manually, confirm the renewal date is diarised against the current 200-day limit, not the old annual cycle
- If the padlock shows but a warning still appears, check for mixed content, page elements still loading over HTTP
- Put SSL monitoring under a maintenance plan so renewal is automatic rather than dependent on someone remembering
Most UK hosting providers include a free certificate as part of their package; if yours doesn’t, that’s worth addressing at your next renewal. If an agency or developer built your site, check whether they installed one at all, HTTPS and a padlock means you’re covered, HTTP or a “Not Secure” warning means action is needed. Our team manages SSL certificates and security monitoring as part of our website maintenance plans, including WordPress websites, where we also cover security hardening beyond the certificate itself.
Frequently Asked Questions
Do I need an SSL certificate if my website doesn’t take payments?
Yes. Any website collecting personal data, including a standard contact form, falls under UK GDPR requirements that a certificate helps you meet. Browsers flag sites without SSL regardless of whether payments are involved, and even a simple brochure website benefits from HTTPS for credibility and search rankings.
How often do I need to renew my SSL certificate now?
Since 15 March 2026, certificates are valid for a maximum of 200 days, roughly six and a half months. If your host handles renewals automatically, there’s nothing extra to do. If certificates are managed manually, plan for at least two renewals a year, tightening to four a year from March 2027, and roughly every seven weeks from March 2029.
What’s the difference between HTTP and HTTPS?
HTTP is the standard protocol for web browsing, but the connection is unencrypted. HTTPS adds SSL/TLS encryption, securing the data exchanged between a visitor and your website. Every UK business website should be on HTTPS; there’s no good reason to still be on HTTP.
Will an SSL certificate improve my Google ranking?
It won’t push you to the top of results on its own, but HTTPS is a confirmed Google ranking signal. Running without it puts you at a disadvantage against competitors who have it. Think of it as a baseline you can’t afford to be missing, not a boost.
My website shows a padlock but still has a security warning. What’s happening?
That’s usually mixed content: some elements on the page, images or scripts, are still loading over HTTP rather than HTTPS. The page has a certificate, but not everything on it is being served securely. A developer or website maintenance provider can identify and fix the specific elements causing the conflict.
Can I install an SSL certificate myself?
If you’re comfortable in your hosting control panel, yes, many providers offer one-click installation for Let’s Encrypt certificates. If you’re unsure, it’s worth having a professional set it up correctly alongside a broader website security review, so nothing else gets missed.
Not Sure Your Website Is Properly Secured?
Get a free consultation and find out whether your SSL certificate, and the rest of your site’s security, is actually covered.
An SSL certificate is one of the smaller things a website needs and one of the easiest to overlook once it’s set up. With renewal cycles now shrinking every year or so, checking who is actually responsible for yours, and how automatically it renews, is worth five minutes today rather than an emergency later.


