Almost every business site in India needs a free certificate and nothing more. Paid ones encrypt no better. What actually matters is that http:// redirects to https:// on its own, that renewal is automated rather than a calendar reminder, and that two people get the expiry alert. From March 2026 certificates last 200 days instead of a year, so manual renewal stops working.
Open your own website right now on your phone. Look at the address bar. If it says http:// and not https://, or if Chrome has put the words Not secure next to your name, you have a problem that is costing you customers today and will cost you more from October.
Most people who search for an SSL certificate for website security are not researching. They have already been told something is wrong. A customer sent a screenshot. A payment gateway refused to connect. Search Console flagged something. The certificate stopped working on a Sunday and nobody noticed until Tuesday.
This is the version we wish people read before that happens.
What an SSL Certificate Actually Does
When somebody types their phone number into your contact form, that text travels from their phone to your server. Without a certificate it travels as readable text. Anyone on the same public wifi can read it.
A certificate does two separate jobs, and most people only know about the first.
- Encryption. The data is scrambled before it leaves the phone and unscrambled when it arrives. Anyone intercepting it sees noise.
- Identity. A certificate authority has checked that you control the domain. It is the browser confirming that yoursite.com really is yoursite.com and not a copy sitting on somebody else's server.
One naming point. Everyone says SSL, but the protocol running today is TLS. SSL was retired years ago and the name only stuck because that is what people type into Google. If a provider quotes you a TLS certificate, it is the same product.
The Padlock You Were Told to Look For Is Gone
For twenty years the advice was the same. Look for the padlock.
Chrome removed that padlock in September 2023 and replaced it with a small settings icon. Google's reasoning was that people had learned the wrong lesson from it. Most users thought the padlock meant the business was trustworthy, when all it ever meant was that the connection was encrypted. Phishing sites had padlocks too, because a free certificate takes four minutes to get.
So if you still tell customers to look for the padlock, stop. And if you assumed your site was fine because you saw one once, check it properly.
Five Reasons to Get Your Website SSL Certified
1. Chrome Is About to Warn People Before They Reach You
Since 2018 Chrome has labelled plain HTTP pages as Not secure. Most people scroll past it. That changes soon.
Google has said it plans to turn on Always Use Secure Connections by default in Chrome 154, scheduled for October 2026. A visitor heading to an HTTP site will get a full warning screen first, not a small grey label. They have to click through a page telling them your site is not safe.
Chrome is roughly two thirds of browser traffic in India. Picture a first-time visitor who found you on Google and has never heard of your business. They won't click through. They will go back and pick the next result.
2. It Is a Google Ranking Signal, Small but Free
Google confirmed HTTPS as a ranking signal in 2014 and has never walked it back. It is a light signal. It won't take you from page four to page one on its own, and anybody promising that is selling something.
What it does is remove a reason to hold you back. Two useful side effects:
- Referrer data survives. Traffic from an HTTPS site to an HTTP site loses its referrer in most browsers, so visits from a partner site or a directory show up in Analytics as direct. You stop being able to see what is working.
- It is permanent. Of all the SEO fixes available to you, this is one of the few that takes an afternoon, costs nothing, and never needs doing again.
3. Your Data Stops Travelling in Plain Text
This is the original reason and it still holds. Login details, contact forms, enquiry forms, anything a customer types. Without a certificate, all of it moves in the clear.
People assume this only matters for banking sites. It doesn't. If you collect any of the following, you are handling personal data:
- Name and phone number on a contact form
- Email address for a newsletter
- Address for a quote or a delivery
- Appointment or booking details
- Any login, including your own admin login
That last one catches people. If your own admin panel sits on HTTP, your password crosses the network in plain text every time you log in from a cafe or an airport.
India's Digital Personal Data Protection Act puts obligations on anyone handling personal data of Indian residents. Sending it unencrypted across the open internet is hard to defend if anyone asks.
4. Payments and Modern Features Simply Will Not Work
This one isn't a recommendation. It's a wall.
Razorpay, PayU, Stripe, PayPal and every other gateway require HTTPS. PCI DSS requires it. No certificate means no online payments.
It goes past payments. Browsers now refuse to give an insecure page access to:
- Location
- Camera and microphone
- Push notifications
- Service workers, which is what makes a site work offline
- HTTP/2 and HTTP/3, where most of the last decade's speed improvement came from
That final point is worth repeating. An HTTP site is also a slower site, because browsers only offer the modern faster protocols over TLS. If you are planning an ecommerce website at any point, this is settled before you start.
5. Trust, and What It Does to Your Bounce Rate
The old version of this post quoted a survey about people not trusting sites without a padlock. That survey is a decade old and the padlock is gone, so here is the honest version.
Nobody in 2026 sees HTTPS and thinks "what a trustworthy business". It's invisible when it works. It's only visible when it's missing, and then it is loud: a browser warning, a red strikethrough, a full interstitial page.
The trust argument is not about gaining anything. It is about not handing a visitor a reason to leave in the first two seconds, before they have read a word you wrote.
How to Check Your Own Certificate in Thirty Seconds
Do not rely on the icon. Run these four checks.
- Open the certificate. In Chrome on desktop, click the icon left of your address, then Connection is secure, then Certificate is valid.
- Check the name. It should match your domain, including the www or non-www version people actually visit.
- Check the expiry date. Write it in a calendar before you close the window.
- Test the redirect. Type your address with http:// at the front and press enter. It should jump to https:// on its own.
That fourth check is the one people skip and the one that usually fails. If the page loads and stays on http://, you have a certificate but no redirect, which means old links and a good share of your visitors still land on the insecure version.
Then test for mixed content. A page can be served over HTTPS while still pulling an image, a font or a script over HTTP, and browsers block or flag that. Right-click, Inspect, open the Console tab and reload. Mixed content warnings appear there in yellow. This is common on sites moved from HTTP years ago, where the CMS still has old image paths saved in the database.
Free or Paid: Which One You Actually Need
Most small business sites in India need a free certificate and nothing more. Here is the honest split.
| Type | What is checked | Who it suits |
|---|---|---|
| Domain Validated (DV) | That you control the domain. Automatic, minutes. | Brochure sites, blogs, most small business sites, most ecommerce. |
| Wildcard DV | Same, but covers every subdomain at once. | Sites running blog, shop and app on separate subdomains. |
| Organisation Validated (OV) | That your company is real and registered. Takes days. | Banks, insurers, anyone whose compliance team asks for it. |
| Extended Validation (EV) | Full legal and operational check. Takes weeks. | Rarely worth it now. Browsers stopped showing the green company name in 2019. |
Two things worth knowing before you spend anything:
- Encryption strength is identical across all four. A free Let's Encrypt certificate encrypts exactly as well as one costing forty thousand rupees. You pay for the identity check and the warranty, not for a stronger connection.
- EV certificates lost their only visible benefit in 2019. They used to put your company name in green in the address bar. Chrome and Firefox both removed that display, so you now pay a large premium for something no visitor will ever see.
What an SSL Certificate Costs in India
Typical yearly ranges. Providers vary, and the first-year price is usually a discount that jumps on renewal, so check the renewal figure before you buy.
| Certificate | Typical cost per year | Worth paying for when |
|---|---|---|
| Let's Encrypt, or free with hosting | Free | Almost always. This is the right answer for most businesses. |
| Paid DV, single domain | ₹500 to ₹2,500 | You want a support number to call when something breaks. |
| Wildcard DV | ₹3,000 to ₹9,000 | You run several subdomains and want one certificate for all. |
| Organisation Validated | ₹4,000 to ₹15,000 | A client or compliance team has asked for it in writing. |
| Extended Validation | ₹12,000 to ₹40,000 | Rarely. The visible benefit was removed in 2019. |
If your hosting company charges you every year for a basic DV certificate, ask why they are not giving you the free one. Most control panels have Let's Encrypt built in with a one-click install, and some hosts switch it off so they can sell you the paid version instead.
At GIT Infosys we check the certificate, the redirect and the mixed content on every site we take on, before anybody talks about design. It is the cheapest fix on the list and it is the one most often left undone.
The 2026 Change That Is Going to Catch People Out
Here is the part almost nobody in Indian small business has heard about yet.
Certificates used to last years. Then the industry cut it to one year. In 2025 the CA/Browser Forum, the group of browser makers and certificate authorities that sets these rules, voted to shorten it much further, in stages.
| From | Maximum life | Renewals per year |
|---|---|---|
| 15 March 2026 | 200 days | About 2 |
| 15 March 2027 | 100 days | About 4 |
| 15 March 2029 | 47 days | About 8 |
The reasoning is sound. A stolen certificate is dangerous for as long as it stays valid, so shorter lives limit the damage. But it changes what you have to do.
Manual renewal is finished. If somebody in your office has a yearly calendar reminder to renew the certificate, that approach breaks in March. By 2029 it would mean renewing eight times a year by hand, and somebody will forget.
The answer is automated renewal, which is what Let's Encrypt has done from the start with 90-day certificates that renew themselves. If you are on paid certificates, ask your provider now whether they support automated renewal through ACME. If the answer is no, move.
What Happens the Day It Expires
Worse than people expect, because there's no grace period. The moment it lapses:
- Every visitor gets a full-page warning saying the connection is not private
- Online payments stop
- Any app or service connecting over an API stops
- Links in your marketing emails now land on a warning screen
- Google may drop the affected pages from results if it persists
You find out from an angry customer rather than from a monitor. Set up expiry alerts at 30, 14 and 7 days, and put at least two people on that list. The one person who gets it will be on leave the week it matters.
The Short Version
Six things, and none of them take long:
- Get a certificate. Use the free one unless something specific requires otherwise.
- Make sure http:// redirects to https:// on its own.
- Check the Console for mixed content and fix the old image paths.
- Turn on automated renewal, not a calendar reminder.
- Put two people on the expiry alert.
- Check it again after any site migration or host change.
That is an afternoon of work. It protects your customers' data, keeps your payments running, removes a small drag on your rankings, and means the Chrome change in October 2026 arrives as a non-event instead of a bad week.
If you are not sure whether your site is set up correctly, send us the address. We will check the certificate, the redirect and the mixed content and tell you what needs doing, even if the answer is nothing. Our web development team runs this check as standard, and if the site is old enough that the certificate is the least of its problems, a website redesign usually costs less than people expect.
Frequently Asked Questions
Is a free SSL certificate as safe as a paid one?
For encryption, yes. A free Let's Encrypt certificate uses the same encryption as one costing forty thousand rupees. The difference is the identity check behind it and the warranty the certificate authority offers, not the strength of the connection.
Paid certificates make sense when you need organisation validation for a compliance requirement, or a single wildcard covering many subdomains with support attached. For a normal business website, free is the right answer.
How do I check if my website has an SSL certificate?
Open the site in Chrome, click the icon left of the address, then Connection is secure, then Certificate is valid. Check that the name matches your domain and note the expiry date.
Then type your address starting with http:// and press enter. It should move to https:// by itself. If it stays on http://, the certificate is installed but the redirect is missing, which leaves a good share of your traffic on the insecure version.
What does an SSL certificate cost in India?
Free if you use Let's Encrypt or the certificate included with most hosting plans. A paid single-domain DV certificate usually runs ₹500 to ₹2,500 a year, a wildcard ₹3,000 to ₹9,000, and organisation validated ₹4,000 to ₹15,000.
Watch the renewal price rather than the first-year price. Introductory discounts are common and the second year is often double.
Does SSL help SEO?
A little. Google confirmed HTTPS as a ranking signal in 2014 and it still counts, but it is a light one. It will not move you up several pages on its own.
The bigger benefit is indirect. Visitors who hit a browser warning leave immediately, and referral data from other HTTPS sites is lost when it points at an HTTP page, so you stop being able to see where your traffic comes from.
Why did the padlock disappear from my browser?
Chrome replaced it with a settings icon in September 2023. Google found that people read the padlock as a sign the business was trustworthy, when it only ever meant the connection was encrypted. Since anyone can get a free certificate in minutes, phishing sites had padlocks too.
Your certificate is still there and still working. Only the icon changed.
What happens if my SSL certificate expires?
Every visitor gets a full-page warning saying the connection is not private, with no grace period. Online payments stop working, and any service connecting to your site over an API stops too.
Set up expiry alerts at 30, 14 and 7 days and put at least two people on the list. Better still, move to automated renewal, which matters more from March 2026 when the maximum certificate life drops to 200 days.
Is SSL the same as TLS?
In practice yes. SSL was the original protocol and was retired years ago. Everything running today is TLS. The name SSL stuck because that is what people search for, so providers kept using it in their product names.
If a provider quotes you a TLS certificate, it is the same thing you were asking for.