The short answer, for most small business websites: no. You almost certainly already have SSL, it came with your hosting, and it costs nothing.
That is worth saying plainly, because “buy an SSL certificate” is advice the internet gives out reflexively and it has been out of date for years. What follows is when it is still right.
What a certificate actually does
Two separate jobs, and conflating them is where most of the confusion starts.
It encrypts the connection. Everything travelling between your site and the person using it, form entries, logins, card details, is scrambled, so anyone intercepting the traffic sees nothing readable. Every certificate does this, and they all do it equally well.
It attests to an identity. The certificate says who the connection is with. At minimum that is “whoever controls this domain”. At most it is “this specific legally registered company”. This is the part you can pay more for, and the only part that differs between certificates.
The padlock in the address bar means the first thing. It has never meant the second, and it has never meant the site is trustworthy, well built, or free of malware. A phishing site can hold a valid certificate, because it does genuinely control its own domain.
Start here: check whether you already have one
Load your site and look at the address bar. A padlock and https:// means you have a working certificate and nothing needs buying.
If your site is on one of our hosting plans, you have one automatically. It is issued and renewed for you, there is nothing to install, and it is included on every shared and VPS plan. The same is true if your site is built on a hosted platform like Squarespace, Shopify, or Wix: each of those issues its own certificate once your domain points at them, as our guide to connecting a domain to a website builder covers.
One case that looks like a problem and is not: a site that shows a warning within the first half hour of connecting a domain. A certificate can only be issued once DNS resolves to the server, so a brand new site is briefly unencrypted while that catches up. An hour later it should be gone. If it is not, tell us.
The three reasons to buy one
A paid certificate earns its place in exactly three situations.
Your site is hosted somewhere that does not include one. A self-managed server, an older host, or an internal application. Our free certificate cannot be installed on infrastructure we do not run, so this is the most common reason customers buy.
You need to cover subdomains. If you run shop., app., staging. and docs. on the same domain, a wildcard certificate secures the domain and everything one level below it in a single certificate, rather than issuing and tracking one per name. Note the limit: a wildcard covers one domain, not two different ones.
You want your business name inside the certificate. An organization-validated certificate carries your verified legal company name, visible to anyone who inspects the certificate details. This matters to a certain kind of cautious buyer, and to some procurement processes, and to nobody else.
If none of those three describe you, stop reading and keep the free one.
DV or OV
The only real choice, once you have decided to buy.
Domain validation (DV) proves you control the domain. It is checked automatically, by email or by a DNS record you add, and the certificate is issued within minutes. This is the right choice for the large majority of small business sites.
Organization validation (OV) additionally verifies that your business is a real, registered entity. A human checks your company registration, which is why it takes one to three business days rather than minutes, and why it costs more.
Both produce the same padlock and the same encryption. OV adds verified identity, not stronger security. If you are choosing between them on the basis of how secure your site will be, they are the same product.
You may also see extended validation (EV) mentioned in older guides, usually alongside a promise of a green address bar with your company name in it. Browsers removed that treatment years ago, so EV no longer looks different to a visitor who is not deliberately inspecting the certificate.
Validating with a DNS record
Whichever you choose, validation usually means proving control of the domain, and the reliable way to do that is a DNS record the issuer asks you to add. That is a TXT record, the same type used for domain verification and email authentication, and our guide to DNS records explains how it works and how long it takes to take effect.
DNS management is free on every domain registered with us, and the records are editable from your client area. If you would rather not touch DNS at all, send us the record and we will add it.
What changes at renewal
Certificates are issued for a one-year term and billed annually. Auto-renew is on by default and we email before the renewal date.
The part people are caught by: renewing the certificate and installing the renewed certificate are two different things. On our hosting it is handled for you. If your site is hosted elsewhere, a renewed certificate still has to be re-validated and re-installed on that server, so the renewal email is not a receipt to ignore. An expired certificate does not take the site down, but it puts a full-page browser warning in front of every visitor, which amounts to the same thing.
So which one do you need?
- Site on our hosting, one domain: nothing, you already have it
- Site on Squarespace, Shopify, or Wix: nothing, the platform issues one
- Site hosted elsewhere, one domain: a basic DV certificate
- Several subdomains on one domain: a wildcard DV certificate
- You need your verified company name in the certificate: an OV certificate
Current pricing for all three sits on the pricing page, and our SSL page compares them side by side.
Need help?
If you are not sure which of the rows above you are in, that is a two-minute question rather than a purchase decision. Tell us where your site is hosted and what it runs on, and we will tell you which certificate you need, including when the answer is the free one you already have.