SSL Certificates: What are they and why does your website need one?

Lock open
Dougall Winship

Dougall Winship

Senior AI & Software Engineer

Published:

SSL certificates are now a standard part of running a secure website. They protect information exchanged between a user's web browser and the website they're visiting, while helping visitors verify that they're connecting to the intended site.


When an SSL/TLS certificate is installed correctly, a website uses HTTPS rather than HTTP. This creates an encrypted connection that protects information such as login credentials, contact form submissions and payment details while they're being transmitted.


But how do SSL certificates actually work, which type do you need and are free certificates suitable for every website? Let's break it down.


What is an SSL certificate?


An SSL certificate is a digital certificate that helps verify a website's identity and enables an encrypted connection between a website and a user's browser.


Although they're still commonly called SSL certificates, modern secure connections actually use TLS (Transport Layer Security), the successor to SSL.


When a valid certificate is installed, the website can use HTTPS. Web browsers use the certificate to verify the website and establish an encrypted connection before information is exchanged.


How do SSL certificates work?


When someone visits a website using HTTPS, their browser checks the site's SSL/TLS certificate and establishes a secure, encrypted connection with the web server.


The certificate contains information that helps the browser verify the website's identity and the certificate authority (CA) that issued or validated the certificate.


Once the secure connection has been established, information exchanged between the browser and server is encrypted. This makes it much harder for an attacker to intercept and read sensitive information while it's being transmitted.


Why are SSL certificates important?


When you use a website http messages are flying around over the network.  When you fill in a contact form or simply click a link a small packet of information in text format gets sent over the network by your computer.  If you put your email address into a contact form and hit submit the packet of information (very similar to a plain text file) will contain your email address within it.  This packet will then get sent to every machine on the network. If you happen to be using wireless then this information will be sent over the air.  This means that anyone can sniff the air or plug into the network and read these unencrypted packets of information. If this information is simply a request to go to another webpage it’s probably not a problem, but if it happens to contain your credit card information then we could have a serious problem.


Unfortunately the internet and more specifically the http protocol is not secure by default, https however is secure because each of these packets gets encrypted before it is sent, meaning only the intended recipient can decrypt and read the message.


There are a number of reasons why SSL security is important:


  • Online payments: – A secure connection is required for websites that take any form of online payments, be it through credit card payments or third-party payment processors such as Worldpay or PayPal. In recent months, however, the web has also seen an increasing number of non-ecommerce websites using ssl encryption on their websites, with big players such as the BBC, Facebook and Google also endorsing the change, even though they do not directly sell through their websites.

  • Data security: It’s not just credit card details that are vulnerable to attacks online. Other personal information such as email addresses and social media messaging are also at risk. SSL encryption allows for the safe passage of this information, blocking it from any potential third-party access or unwanted hacks. If your website encourages its visitors to sign up to any memberships, or fill out any contact forms, then SSL encryption should be considered in order to safe guard this information.

  • Site verification: – SSL certificates authenticate and verify the owner of a website, preventing that site from any potential phishing attacks, where third-party hackers often impersonate a website in order to obtain personal information.

  • Verification of information: – SSL certificates also provide verification of the information that is listed on websites. This is particularly apparent on news sites such as the BBC or Guardian, and further prevents a users content from being altered by any third-parties.


What are the different types of SSL certificate?


SSL certificates can differ both in how the organisation behind a website is validated and in the number of domains or subdomains the certificate can secure.


Domain Validation (DV)


A Domain Validation certificate verifies that the applicant controls the domain. DV certificates can usually be issued quickly and are commonly used for websites where basic domain verification is sufficient.


Organisation Validation (OV)


Organisation Validation certificates involve additional checks to verify the organisation requesting the certificate. This provides a greater level of identity validation alongside the encrypted connection.


Extended Validation (EV)


Extended Validation certificates require more extensive checks of the organisation applying for the certificate. Like other SSL certificates, they enable an encrypted HTTPS connection, but involve a more rigorous validation process before the certificate is issued.


Wildcard SSL certificates


A wildcard certificate can secure a primary domain and multiple subdomains. For example, one certificate could cover example.com, shop.example.com and portal.example.com.


Multi-domain certificates


A multi-domain certificate can secure multiple domain names using a single certificate, which can be useful for organisations operating several websites or digital services.


The right certificate depends on your website, infrastructure and validation requirements rather than simply choosing the certificate with the highest level of validation.


Does every website need an SSL certificate?


Yes, websites should use HTTPS regardless of whether they process payments or collect sensitive personal information.


Modern web browsers expect secure HTTPS connections and can warn users when a website isn't secure. SSL/TLS also protects the integrity of information exchanged between a website and its visitors.


For ecommerce sites, customer portals and applications handling personal information, secure connections are particularly important. But HTTPS is now standard practice for brochure websites, blogs and other public-facing sites too.


The good news is that obtaining a certificate no longer needs to be expensive or complicated. Free certificate authorities such as Let's Encrypt have made HTTPS accessible to website owners of all sizes.


Can you get a free SSL certificate?


Yes. Free SSL/TLS certificates are widely available, with Let's Encrypt being one of the best-known providers.


Let's Encrypt is a nonprofit certificate authority (CA) that provides free TLS certificates to help make secure HTTPS connections accessible to website owners. Its certificates offer the same fundamental encryption needed to protect information travelling between a website and its users.


Certificate issuance and renewal can also be automated. Many web hosting providers and platforms now support Let's Encrypt directly, allowing certificates to be installed and renewed automatically before they expire.


For many websites, a free certificate from Let's Encrypt provides everything needed to enable HTTPS. However, the right certificate will still depend on your website, infrastructure and any specific validation or security requirements your organisation has.


Keeping your website secure


An SSL certificate is only one part of website security, but it's a fundamental one. Every modern website should use HTTPS to protect information exchanged with its users and provide a secure connection.


Certificates also need to remain valid and correctly configured, so renewal and certificate management should form part of the ongoing maintenance of your website and infrastructure.


Building secure software?


Security should be considered from the start, not added as an afterthought. We design and develop secure, scalable software around your business, users and technical requirements.


Explore our Software Development services →

Dougall Winship

Dougall Winship

Senior AI & Software Engineer

Dougall is a Senior AI & Software Developer at New Icon with extensive experience across software engineering, web and mobile development, and AI. He holds a first-class degree in Computer Science and has twice received recognition from the British Computer Society, bringing a strong technical foundation to building and evolving complex digital products and systems.

Reimagine your digital future today

Send us a message for more information about how we can help you and your business

Reimagine your digital future today

Send us a message for more information about how we can help you and your business

Reimagine your digital future today

Send us a message for more information about how we can help you and your business

Reimagine your digital future today

Send us a message for more information about how we can help you and your business

Services

Capabilities

About

Linebreak

New Icon is a Linebreak company

© Newicon Ltd. Registered in England and Wales. Company No: 05904359 | VAT: GB 993768447.

Designed and built by New Icon in Bristol, a Linebreak company.

Linebreak

New Icon is a Linebreak company

© Newicon Ltd. Registered in England and Wales. Company No: 05904359 | VAT: GB 993768447.

Designed and built by New Icon in Bristol, a Linebreak company.

Linebreak

New Icon is a Linebreak company

© Newicon Ltd. Registered in England and Wales. Company No: 05904359 | VAT: GB 993768447.

Designed and built by New Icon in Bristol, a Linebreak company.