Yes, every normal modern business website should use HTTPS. SSL/TLS is the technology that encrypts the connection between a visitor and the website, helping prevent third parties from reading or tampering with traffic in transit.
You may still hear people say "SSL certificate".
Strictly speaking, modern secure web connections use TLS, the successor to SSL.
But "SSL" remains the phrase most business owners and hosting companies use, so I will use it here too.
The practical outcome is the familiar:
https://
at the beginning of the website address.
What does SSL actually do?
When your browser connects securely to a website, encryption protects the information travelling between the browser and the server or edge network.
That matters even on a simple website.
It helps protect form submissions, browsing activity and other traffic from being casually intercepted or modified while it is in transit.
The certificate also helps the browser verify that it is connecting to the domain it expects.
So SSL/TLS is about two important ideas:
encryption and authentication.
Does the padlock mean the business is trustworthy?
No.
This is an important distinction.
HTTPS tells you the connection is encrypted and the certificate is valid for the connection.
It does not tell you that the company itself is reputable.
A scam website can use HTTPS.
A dishonest shop can have a valid certificate.
SSL protects the connection.
It does not perform due diligence on the business.
Do I need SSL if I do not take payments?
Yes.
The old idea was that SSL mattered mainly for e-commerce and login pages.
That is outdated.
A modern website should use HTTPS as the normal baseline.
Even a brochure site may contain a contact form.
And even if it does not, visitors should still receive the site through an encrypted connection.
There is very little reason to run an ordinary public business site without HTTPS now.
Does SSL cost money?
Basic SSL often does not.
This is another area where old hosting assumptions can persist long after the technology changes.
Cloudflare, for example, currently issues and renews free publicly trusted Universal SSL certificates for activated domains on all its plans.
Many other modern hosting platforms also include HTTPS.
That does not mean every certificate product is unnecessary.
Larger organisations can have more advanced certificate-management requirements.
But a local business with a straightforward site should not assume it needs to pay a large annual "SSL certificate fee" simply to get HTTPS.
Worth knowing
Basic HTTPS is now such a normal part of modern web infrastructure that I do not think a small business should be impressed by seeing "SSL certificate included" presented as a major premium feature. It matters enormously — but on an ordinary modern site it should be part of the baseline setup, not a mysterious technical extra.
Why do some hosts still sell SSL certificates?
There can be legitimate reasons.
A provider may offer specialist certificate types, support, advanced validation or enterprise management.
Older hosting environments may also package certificates differently.
But if somebody quotes a meaningful recurring fee for basic SSL on a normal small-business website, ask what exactly makes the paid product necessary.
Sometimes there is a good answer.
Sometimes it is simply a legacy upsell.
That fits a wider principle I use across Built by Gavin: separate genuine technical costs from charges that exist because clients assume they must.
SSL is sometimes bundled into larger hosting packages, so it is worth checking it alongside the broader list of hidden website costs.
What does Cloudflare do?
Cloudflare's current Universal SSL service automatically issues and renews publicly trusted certificates for domains added and activated on the platform.
For a standard full setup, Universal SSL covers the root domain and first-level subdomains such as www.
Cloudflare handles issuance, renewal and deployment.
That is one reason HTTPS can be almost invisible operationally for a normal business site.
I explain the broader platform in what Cloudflare does for a small-business website.
Does SSL make my website secure?
It makes the connection more secure.
It does not secure everything else.
A website can still have weak passwords.
A CMS can still have vulnerable software.
An administrator account can still be compromised.
A badly designed form can still create problems.
A third-party service can still have an issue.
SSL is one layer.
It is an essential layer, but it is not a complete security strategy.
Not by itself. For the broader risk picture, see can a business website be hacked?.
Does HTTPS help SEO?
Google has used HTTPS as a ranking signal for many years, but I would not sell SSL as an SEO tactic.
The better reason to use HTTPS is that it is the correct modern way to serve a website.
Search benefits are secondary.
If the site is still running over plain HTTP, the solution is not:
Buy an SEO SSL package.
It is:
Configure the website properly.
What happens if the certificate expires?
Browsers can display a security warning when the certificate is invalid or expired.
That can effectively make a website unusable to ordinary visitors.
Automatic certificate management greatly reduces that risk.
Cloudflare's Universal SSL is automatically renewed while the domain remains correctly configured and active.
This is exactly the kind of routine infrastructure work I prefer platforms to handle automatically rather than turning it into a recurring manual task.
What if I move hosting provider?
The HTTPS setup may change depending on the new platform.
Your domain is not permanently tied to one SSL certificate.
The new hosting or edge provider can issue/configure an appropriate certificate once the domain points to the new infrastructure.
That is another reason domain ownership matters more than becoming attached to a particular certificate vendor.
Moving a site often involves DNS changes as well as certificates; what DNS actually does explains that relationship without the jargon.
Gavin’s perspective
Built by Gavin's approach
HTTPS is a baseline technical requirement.
I do not think it should be presented as a premium feature in a normal web-design quote.
If I build a straightforward business website, I expect the public site to run securely over HTTPS.
The client should not need to understand certificate issuance just to get a professional website.
Good infrastructure should make the technical plumbing disappear.
Gavin's take
This is a good example of the kind of technical detail I think a client should not have to worry about. You should understand that your site uses HTTPS and that the connection is protected, but you should not need to become an expert in certificate renewal just to keep a five-page business website online.
The bottom line
SSL/TLS encrypts the connection between your visitors and your website and enables HTTPS.
Yes, your business website needs it.
No, basic SSL does not automatically need to cost you extra.
And no, the padlock does not guarantee that the business behind the site is trustworthy.
It means the connection is protected.
Need the technical setup handled without the jargon?
See my website options or tell me what you are building.
Things like HTTPS should be part of a properly configured website, not mysterious extras added to the invoice.
---