Free initial consultation · Flexible ongoing and project-based services Speak to our team: 020 3048 4048

What Is an SSL Certificate? A Plain-English Guide for UK Business Owners

By Published 29 June 2026 9 min read
Quick answer: An SSL certificate is what puts the padlock and HTTPS in front of your web address. It encrypts the connection between your site and your visitors, it’s expected by browsers and Google, and it’s part of meeting UK GDPR if your site collects any personal data. As of 15 March 2026, certificates last a maximum of 200 days rather than 398, so renewal has to happen roughly twice a year instead of once, whether that’s you checking it or your hosting provider doing it automatically.

If your website address starts with HTTP rather than HTTPS, browsers are flagging it as “Not Secure” every time someone visits, before they’ve read a single word about your business. Fixing that is what an SSL certificate does. This guide covers what it actually is, why a UK business site needs one, what changed in March 2026, and what’s coming next.

200 daysmaximum certificate life since 15 March 2026
100 daysthe limit from March 2027
47 dayswhere validity ends up by March 2029
Freecost of a standard certificate via Let’s Encrypt

What Is an SSL Certificate?

SSL stands for Secure Sockets Layer, a security protocol that encrypts the connection between your website and anyone who visits it. When someone lands on your site, the certificate scrambles the data exchanged between their browser and your server, so it can’t be intercepted or read in transit.

You’ll also see the term TLS, Transport Layer Security, which is the modern, updated version of SSL. The two terms get used interchangeably in everyday conversation, and the technical distinction doesn’t matter much for a business owner. What matters is the result: a secure, encrypted connection visitors and browsers can trust.

How Can You Tell If a Website Has One?

Look at the address bar. A site with a valid certificate shows HTTPS at the start of the URL with a padlock icon next to it. Without one, Chrome, Firefox and most modern browsers show a “Not Secure” warning before a visitor has even reached your content, and in most cases, they leave rather than click through it.

Why Your Business Website Needs One

1. Visitors Don’t Trust a “Not Secure” Website

A browser security warning changes how people feel about your business before they’ve had a chance to engage with it. Research from DigiCert confirms that visitors are far less likely to trust websites displaying security warnings, which affects enquiries, sign-ups and sales directly. That’s potential customers leaving before you’ve had a chance to speak to them.

2. Google Uses HTTPS as a Ranking Signal

Google has confirmed HTTPS as a ranking factor, so a site still running on HTTP is at a disadvantage in search results even when everything else about its SEO is solid. If you’re competing for visibility against other UK businesses in your sector, going without a certificate hands them a head start for free.

3. UK GDPR Expects It Wherever Personal Data Is Collected

UK GDPR requires businesses to put appropriate technical safeguards in place to protect personal data. If your site has a contact form, an email signup, or a customer login, it’s collecting personal data, and a certificate is part of meeting that obligation. Businesses taking card payments online also need to meet PCI DSS, which requires an encrypted connection as a baseline. Neither of these is optional.

4. It Protects Visitors’ Data in Transit

Without SSL, data sent between your website and a visitor travels as plain text: names, email addresses, passwords, enquiry details, all readable if intercepted. SSL turns that into unreadable code, so even if someone does intercept it, they can’t use it.

What Changed for SSL Certificates in 2026, and What’s Coming Next

This matters most if your business manages its own certificate rather than leaving it to a hosting provider. Browser makers and certificate authorities agreed a staged reduction in maximum certificate lifetime, aimed at closing the window a compromised or outdated certificate can stay valid for.

15 March 2026200 daysDown from 398 days. Roughly six and a half months, so renewal now needs to happen about twice a year instead of once.
15 March 2027100 daysJust over three months. Manual renewal cycles get considerably tighter.
15 March 202947 daysThe final step in the schedule, confirmed by the CA/Browser Forum (DigiCert, TLS certificate lifetimes will officially reduce to 47 days). At this point, manual renewal stops being realistic for most businesses.

If your website is on managed hosting with automatic SSL renewal, your provider handles this and there’s nothing for you to do. If your team manages certificates manually, your renewal workload has already roughly doubled, and it’s going to keep shrinking from here. Miss a renewal and your site shows as insecure to every visitor until someone fixes it, which is lost traffic and lost trust while you scramble to sort it.

What Types of SSL Certificate Are There?

There are three main types, and the right one depends on what your website does.

Domain Validated (DV)

Confirms the certificate holder owns the domain. Quick to issue, low cost, and often free through providers like Let’s Encrypt. Adequate for the majority of UK small business websites.

Organisation Validated (OV)

The certificate authority checks that your organisation is legitimate before issuing it. A stronger trust signal, typically used by businesses handling more sensitive information.

Extended Validation (EV)

The highest level of checking on your organisation before issue. Typically used by financial institutions, healthcare providers, and businesses where maximum visible trust matters most.

For most UK small and medium-sized businesses, a DV or OV certificate covers everything needed.

Does a Free Certificate Do the Same Job?

For encryption, yes. A free certificate from Let’s Encrypt provides the same level of encryption as a paid one. The differences sit in validation level, warranty protection and support: free certificates are DV only and auto-renew if set up correctly through your hosting provider, while paid options add OV or EV validation, dedicated support, and sometimes a financial warranty.

For a standard UK business website with a contact form and service pages, a free certificate is entirely adequate. For e-commerce at scale, or a business handling sensitive client data in volume, it’s worth a conversation about whether a higher validation level makes sense.

What Happens If Your Certificate Expires?

Your website becomes inaccessible in any practical sense. Browsers show a full-screen warning before visitors can even reach the page, and most people don’t click past it. Search rankings can drop quickly too, since search engines take note once a certificate lapses.

This is exactly why the 2026 renewal changes matter more than they might first seem. A business used to renewing once a year now needs to do it roughly twice, and that gap keeps closing over the next few years. One missed reminder and you’ve got a site actively turning visitors away until it’s fixed. Having a professional manage this as part of a wider website maintenance service removes that risk; you won’t be the one watching expiry dates.

Worth checking now: If nobody in your business can say with confidence when your certificate next expires, or who’s responsible for renewing it, that’s the gap most likely to catch you out under the new shorter renewal cycle.

Getting and Keeping Your SSL Certificate Sorted

  • Type your website address into a browser and confirm it shows HTTPS and a padlock, not a “Not Secure” warning
  • Check your hosting control panel for a certificate that’s included and set to auto-renew
  • If certificates are managed manually, confirm the renewal date is diarised against the current 200-day limit, not the old annual cycle
  • If the padlock shows but a warning still appears, check for mixed content, page elements still loading over HTTP
  • Put SSL monitoring under a maintenance plan so renewal is automatic rather than dependent on someone remembering

Most UK hosting providers include a free certificate as part of their package; if yours doesn’t, that’s worth addressing at your next renewal. If an agency or developer built your site, check whether they installed one at all, HTTPS and a padlock means you’re covered, HTTP or a “Not Secure” warning means action is needed. Our team manages SSL certificates and security monitoring as part of our website maintenance plans, including WordPress websites, where we also cover security hardening beyond the certificate itself.

Frequently Asked Questions

Do I need an SSL certificate if my website doesn’t take payments?

Yes. Any website collecting personal data, including a standard contact form, falls under UK GDPR requirements that a certificate helps you meet. Browsers flag sites without SSL regardless of whether payments are involved, and even a simple brochure website benefits from HTTPS for credibility and search rankings.

How often do I need to renew my SSL certificate now?

Since 15 March 2026, certificates are valid for a maximum of 200 days, roughly six and a half months. If your host handles renewals automatically, there’s nothing extra to do. If certificates are managed manually, plan for at least two renewals a year, tightening to four a year from March 2027, and roughly every seven weeks from March 2029.

What’s the difference between HTTP and HTTPS?

HTTP is the standard protocol for web browsing, but the connection is unencrypted. HTTPS adds SSL/TLS encryption, securing the data exchanged between a visitor and your website. Every UK business website should be on HTTPS; there’s no good reason to still be on HTTP.

Will an SSL certificate improve my Google ranking?

It won’t push you to the top of results on its own, but HTTPS is a confirmed Google ranking signal. Running without it puts you at a disadvantage against competitors who have it. Think of it as a baseline you can’t afford to be missing, not a boost.

My website shows a padlock but still has a security warning. What’s happening?

That’s usually mixed content: some elements on the page, images or scripts, are still loading over HTTP rather than HTTPS. The page has a certificate, but not everything on it is being served securely. A developer or website maintenance provider can identify and fix the specific elements causing the conflict.

Can I install an SSL certificate myself?

If you’re comfortable in your hosting control panel, yes, many providers offer one-click installation for Let’s Encrypt certificates. If you’re unsure, it’s worth having a professional set it up correctly alongside a broader website security review, so nothing else gets missed.

Not Sure Your Website Is Properly Secured?

Get a free consultation and find out whether your SSL certificate, and the rest of your site’s security, is actually covered.

Get a Free Consultation

An SSL certificate is one of the smaller things a website needs and one of the easiest to overlook once it’s set up. With renewal cycles now shrinking every year or so, checking who is actually responsible for yours, and how automatically it renews, is worth five minutes today rather than an emergency later.

About the author

Kevin Marshal

Kevin Marshal is a content writer at UK IT Services, a UK-based IT support, cyber security and digital agency. He turns complex technology topics into clear, practical guidance that business owners and decision-makers can actually use. Drawing on the expertise of the wider UK IT Services team, Kevin writes about managed IT support, cyber security, Microsoft 365, web design and development, and digital marketing, always with a focus on what works for small and medium-sized UK businesses. His goal is simple: help organisations make smarter, safer technology decisions without the jargon.

Latest insights

Talk to a UK-based IT specialist

Managed IT support, cyber security and digital services for businesses across the UK.

Get a Free Consultation
Call Us Free Consultation