What SSL Should Cost
An SSL certificate costs nothing for the vast majority of websites. Let's Encrypt, a nonprofit certificate authority, issues domain-validated certificates at no charge, and most hosting providers include automated Let's Encrypt installation. You only pay for SSL when you need organisation validation or extended validation, which verify your legal entity and are relevant for financial institutions and large enterprises.
Closest fit
Every class, ranked
This is a category, not a company. Any host selling that category can serve you well or badly; the checks below are how you tell them apart.
Before you pay, check these four things
Free SSL Covers Almost Everyone
Let's Encrypt launched in 2016 with the goal of encrypting the entire web. It issues domain-validated (DV) certificates that prove you control the domain name. DV certificates encrypt the connection between visitor and server identically to paid alternatives. Every major browser trusts them. There is no difference in encryption strength between a free DV certificate and one that costs money.
Most hosting control panels automate the entire process: issuing the certificate, installing it, and renewing it every 90 days before it expires. You do not need to touch a command line or remember renewal dates. If your hosting provider supports Let's Encrypt, your SSL cost is zero and your site runs on HTTPS with no manual effort.
For a small business, a personal site, a blog, a portfolio, or an ecommerce store using a third-party payment processor, a DV certificate is all you need. The padlock icon appears in the browser, the connection is encrypted, and search engines treat the site the same as one with a paid certificate.
When Paid SSL Certificates Make Sense
Organisation validation (OV) certificates verify that a registered legal entity controls the domain. The certificate authority checks business registration documents before issuing. Extended validation (EV) certificates go further, confirming the legal entity's physical address and operational status through a more rigorous process.
Neither OV nor EV provides stronger encryption. The difference is in identity assurance. OV and EV certificates display the verified organisation name in certificate details, which can matter for banks, insurance companies, government services, and large enterprises where visitors need assurance that the legal entity behind the site is who it claims to be.
For everyone else, the cost of an OV or EV certificate buys trust signals that most visitors never check. Browser behaviour has evolved: the green address bar that once distinguished EV certificates is no longer displayed in most browsers. The wizard on this page asks what your site does, who your visitors are, and whether your industry has specific certificate requirements, then tells you whether free DV from your existing setup is enough or a paid certificate adds genuine value.
Let's Encrypt certificates expire every 90 days and must be renewed. Most hosting panels automate this. If yours does not, set a calendar reminder to avoid a lapsed certificate.
Next in this cluster
Related guides and tools
- What a Website Really Costs
- Best Hosting Type for Ecommerce
- Do I Need Premium DNS? 2026 Cost-Benefit Guide
Sources
-
Let's Encrypt as a nonprofit certificate authority per letsencrypt.org. DV/OV/EV validation levels per CA/Browser Forum Baseline Requirements. Browser trust of Let's Encrypt per Mozilla, Google, Apple, and Microsoft root programs.
- Every figure in the calculators on this site is typed in by you. No price, allowance or renewal rate is stored in the page.