“Great that I have a website, but do I have to buy an SSL certificate now?”
It’s a question many new website owners ask themselves. You click through to your own site and suddenly see a red exclamation mark in your browser with the message “Not secure.” Panic. An acquaintance of mine saw this and immediately spent 160 euros on a paid SSL certificate.
HTTPS ensures a safe, encrypted connection between your website and your visitors. Without this certificate, Chrome and other browsers display a warning that your site is unsafe. Not exactly something you want potential customers to see.
But here’s the good news: the idea that you need to pay for a secure connection is in most cases completely outdated. In this piece, I will explain why a free SSL certificate is the best choice in 99% of cases.
What is SSL again and why does your site need it?
SSL (Secure Sockets Layer) is the technology that encrypts all data between your website and your visitor. Think of login details, contact forms, or payment details – everything you don’t want hackers to be able to read when they eavesdrop on internet traffic.
The 3 major advantages of SSL are:
Security. It protects your visitors’ data against eavesdropping and manipulation during transport. Without SSL, hackers on public Wi-Fi networks can easily intercept passwords, credit card details, and other sensitive information.
Trust. A secure HTTPS connection gives visitors a sense of security. Browsers like Chrome and Firefox have been showing a clear “Not secure” warning for all HTTP sites since 2018. This warning usually sends visitors away immediately.
SEO. Google has been using HTTPS as a ranking factor since 2014 and has increasingly weighted it. Websites without an SSL certificate receive a lower position in search results, directly affecting your discoverability.
That SSL is a necessity is clear, but how much should it cost?
Paid vs. free SSL
What is actually the difference between a free certificate of €0 and a paid certificate of €50-€200 per year?
For the visitor and the technical encryption: absolutely no difference. Both use the same encryption strength (usually 256-bit AES encryption) and offer identical protection against man-in-the-middle attacks.
The free alternative is Let’s Encrypt – a non-profit certification authority founded by the Internet Security Research Group (ISRG). This initiative is supported by companies such as Google, Meta, Mozilla, Cisco, and Electronic Frontier Foundation. Their mission is simple: to encrypt the entire web, free and accessible for everyone.

Let’s Encrypt launched in 2015 and has since almost taken over the SSL market. Where SSL certificates were once reserved only for large companies that could pay hundreds of euros per year, Let’s Encrypt makes HTTPS accessible for every website owner.
Even the biggest names use free SSL
The best proof that free SSL has become the new standard is that the biggest and most well-known websites in the world rely on it.
According to recent statistics, Let’s Encrypt now has a market share of more than 63% of all SSL certificates worldwide. They secure over 700 million websites.
Interesting detail: in the Netherlands, the use of Let’s Encrypt is even higher. Research by SIDN Labs shows that no less than 75% of all .nl websites use Let’s Encrypt certificates.
An overview of well-known websites that use Let’s Encrypt:
Dutch websites:
- Many local news sites and blogs
- Thousands of SME websites with .nl extensions
- Almost every hosting provider offers Let’s Encrypt as standard
- Many Dutch webshops and portfolio sites
Information & news:
- Wikipedia.org
- The New York Times (nytimes.com)
- Reuters
- USA Today
Technology & development:
- Cloudflare.com (yes, even a company that sells SSL services uses Let’s Encrypt)
- WordPress.org (the platform running 43% of all websites)
- Mozilla (makers of Firefox)
- Stack Overflow
E-commerce & services:
- Shopify (for many of their subdomains)
Education & research:
- Stanford University
- Nature (prestigious scientific journal)
Government:
- National Security Agency (yes, even the NSA relies on free SSL)
What stands out is the diversity: from Dutch SME sites to international news media, from tech platforms to universities and government institutions. These are organizations with million-euro budgets and teams of cybersecurity experts.
If they choose free SSL, why would you pay?
Here’s why these organizations are massively opting for Let’s Encrypt:
Cost-effectiveness. No unnecessary expenses for essential security. Even large companies see no reason to spend money on something that works just as well for free.
Automation. Let’s Encrypt works fully automated via the ACME protocol. Certificates are automatically requested, installed, and renewed after 90 days. With traditional paid certificates, you often have to manually renew certificates, generate CSR codes, and keep up with emails.
Reliability. The technology is proven and widely supported by all modern browsers. Let’s Encrypt runs on the same technical infrastructure as paid alternatives and is audited by external auditors.
For comparison: with traditional paid certificates, you encounter various practical issues. You have to manually renew certificates (and websites often go offline because webmasters forget to do this on time), you have to generate CSR codes using command line tools, and you depend on email communication with the certificate authority. Let’s Encrypt automates this entire process.
Is there never a reason for a paid certificate then?
For the sake of completeness: there are scenarios where a paid certificate can make sense. But this concerns less than 1% of all websites.
Extended Validation (EV) Certificates
Extended Validation certificates were for years the gold standard for large companies. These certificates cost €200-€800 per year and displayed the company name in a green bar in the browser.
The problem: browsers have largely abolished these visual indicators.
Chrome discontinued the green company name already in 2019. Firefox and other browsers followed. The visual value for which companies paid hundreds of euros no longer exists.
Where are EV certificates still used?
Large banks sometimes still use EV certificates, but this is more a matter of compliance than technical necessity. The European Payment Services Directive (PSD2) prescribes, for example, that payment service providers must use “strong authentication,” which some legal departments interpret as EV certificates.
The irony is that modern phishing attacks exploit the fact that most users can no longer see the difference between EV and regular certificates. Cybercriminals register domain names like “paypa1.com” (with the number 1 instead of the letter l) and simply use free SSL for it. To the visitor, this looks just as secure as the real PayPal site.
Why SSL insurance is worth little
Many paid SSL certificates come with a “guarantee” or “insurance” ranging from €10,000 to €1,750,000. This sounds impressive, but in practice, this is money you will never see.
What does the guarantee actually cover?
SSL guarantees only cover damage caused by the Certificate Authority (CA) itself making an error in issuing a certificate. For example: if DigiCert accidentally issued a certificate for google.com to a hacker, and this hacker caused damage with it, then the guarantee would theoretically apply.
What does the guarantee NOT cover?
- Phishing attacks (by far the most common form of online fraud)
- Malware on your website
- DDoS attacks
- Theft of credit card data from other causes
- Hacking of your website
- Mistakes by yourself or your visitors
Why do you never see claims?
In the more than 10 years that these guarantees have existed, there have been virtually no publicly known payouts. The reason is simple: CAs almost never make mistakes when issuing certificates. Modern validation procedures are so strict that misissuance practically never occurs.
Moreover, it is extremely difficult for those afflicted to prove that their damage was directly caused by a CA error. You must demonstrate that:
- The CA made a mistake
- This mistake was the direct cause of your damage
- You made no other mistake that led to the damage
For website owners, it also applies that only end-users can make a claim. Not the owner of the certificate itself. So you pay for insurance that only your visitors can use, for scenarios that practically never occur.
Organization Validated (OV) certificates
Organization Validated certificates are priced between Domain Validated (such as Let’s Encrypt) and Extended Validation certificates. They cost €50-€150 per year and the CA checks if your company actually exists.
The problem: modern browsers no longer display this to visitors. An OV certificate looks exactly the same to users as a free DV certificate. So you pay for validation that no one can see.
OV certificates still have limited value in B2B environments where APIs communicate and parties programmatically check certificate details. For regular websites, they are redundant.
The reality for Dutch SME websites
For a typical business website, webshop, blog, or portfolio site, the added value of a paid certificate is negligible to completely absent. You’re paying for benefits that modern browsers no longer show, guarantees that are never paid out, and validation that no one can see.
The only thing paid certificates offer is a warm feeling and maybe impressing your IT supplier. But your visitors and Google see no difference.
The encryption of a free Let’s Encrypt certificate is technically identical to that of a €200 certificate. Both use the same 256-bit AES encryption, both are trusted by all browsers, and both offer the same protection against man-in-the-middle attacks.
The difference is not in the technology, but in outdated business models. Certificate Authorities that have made a lot of money for years from selling SSL certificates try to justify their existence by selling features that modern browsers no longer support.
At my.host, security is included
If you do need a paid SSL certificate, you can simply get one through my.host.
But all my.host hosting packages come standard with a free Let’s Encrypt SSL certificate. And for the vast majority of websites, these are more than sufficient.



Leave a Reply