What Is an SSL Certificate?
An SSL certificate (Secure Sockets Layer certificate) is a small digital file issued by a Certificate Authority (CA) that authenticates a website's identity and enables the encrypted HTTPS protocol. Despite the name, modern certificates use TLS (Transport Layer Security) rather than the original SSL protocol, though the term "SSL certificate" remains the common industry term.
When a browser connects to a website with a valid SSL certificate, it initiates a TLS handshake. During this process, the server presents its certificate, the browser verifies it against trusted CAs, and both parties establish an encrypted session.
All data exchanged after this point, including form submissions, login credentials, and payment details, is encrypted in transit and cannot be read by third parties.
There are three main validation levels for SSL certificates. Domain Validation (DV) certificates simply verify that the applicant controls the domain. They are fast to obtain (often minutes) and free via Let's Encrypt. Organisation Validation (OV) certificates require verification of the business's legal identity.
Extended Validation (EV) certificates involve the most thorough verification and historically displayed a green address bar, though most browsers no longer show this distinction prominently. For most South African small and medium businesses, a DV certificate is sufficient.
SSL certificates are directly connected to technical SEO. Google has used HTTPS as a ranking signal since 2014. Sites without valid certificates display browser warnings that deter visitors, reduce conversion rates, and signal poor technical hygiene.
Under South Africa's POPIA legislation, businesses collecting personal information are required to implement appropriate technical security measures, and HTTPS via a valid SSL certificate is a baseline expectation.
Certificates expire, typically after one year for free certificates and up to two years for paid ones. An expired certificate causes browsers to block access to the site entirely, showing a full-screen security error. Enabling auto-renewal on your hosting account prevents this from happening.
SSL Certificate In Practice
The scenario below is an illustrative example, not a Juicy Designs client result. It indicates the kind of effect that SSL certificate work typically produces, so treat it as indicative rather than measured.
Picture a Pretoria-based estate agency that builds a new website on WordPress hosted by a local South African provider. The developer enables a free Let's Encrypt SSL certificate through the hosting control panel and configures the WordPress settings to force HTTPS across all pages. The certificate installs automatically and renews every 90 days without manual intervention.
Visitors to the estate agency's site would see the padlock icon in their browser. When potential buyers fill in the contact form requesting property viewings, their personal details (name, phone number, email) are transmitted over an encrypted connection. This helps satisfy the agency's POPIA obligations for data security in transit.
Six months later, the agency might notice that a competitor's website shows "Not Secure" in Chrome. A technical SEO consultant would typically point out that this is likely hurting the competitor's rankings and conversion rate.
The estate agency's own site, correctly configured with HTTPS and a valid SSL certificate, would keep a clean bill of health in Google Search Console and be well placed to rank for property search terms in Pretoria and Centurion.
What an SSL certificate is
An SSL certificate (more accurately an SSL/TLS certificate) is a digital certificate installed on a web server that enables an encrypted, secure connection between the server and visitors' browsers, and verifies the identity of the website, allowing the site to be served securely over HTTPS. The certificate is the credential that makes the encryption possible: with a valid SSL/TLS certificate installed, the connection between the visitor and the site is encrypted (protecting data in transit from interception or tampering), and the browser shows the secure padlock and the https:// prefix, indicating a secure connection. The certificate also serves an identity function, confirming (to varying degrees depending on the certificate type) that the site is what it claims to be. SSL certificates are what a site needs to move from insecure HTTP to secure HTTPS: without a valid certificate, a site cannot serve over HTTPS and browsers mark it as not secure, whereas with one properly installed, the site is secure and trusted. Certificates come in different types and validation levels (from basic domain validation to more rigorous organisation or extended validation), and they are issued by certificate authorities, with many available free (such as through Let's Encrypt) and often provided by hosting providers, as well as paid options. Certificates have an expiry date and must be renewed to remain valid. Understanding SSL certificates matters because they are the credential that enables the HTTPS security now expected of all websites: a valid, current SSL/TLS certificate is what secures a site's connections, earns the trusted padlock, and avoids the not-secure warning, so knowing what an SSL certificate is, and that a valid one is needed and must be kept current, is essential to running a secure, trustworthy website.
SSL certificates in practice: cost and expiry
Two practical questions about SSL certificates are whether a paid certificate is needed and what happens if a certificate expires, both relevant to keeping a site securely and continuously served over HTTPS. On cost: a paid SSL certificate is not necessary for most websites to be secure, because free SSL/TLS certificates (notably from Let's Encrypt, and often provided automatically by hosting providers) offer the same strong encryption and the secure padlock as paid ones, so for the great majority of sites, a free certificate fully secures the site over HTTPS at no cost. Paid certificates exist and can offer additional identity validation (organisation or extended validation, which involve more rigorous verification of the organisation's identity) or additional features, warranties or support, which some businesses (for example, in sensitive sectors) may choose for the extra identity assurance, but the encryption itself is equally strong with a free certificate, so a paid certificate is a choice for extra validation or features rather than a requirement for basic security. For most South African websites, a free certificate (such as one provided by the host or via Let's Encrypt) is sufficient to be secure. On expiry: SSL certificates have a validity period and expire, and when a certificate expires and is not renewed, the site's HTTPS becomes invalid, so browsers will warn visitors that the connection is not secure or the certificate is invalid (often with a prominent security warning that can block or deter access), which damages trust, can drive visitors away, and undermines the site's security and credibility until the certificate is renewed. An expired certificate is a common, avoidable problem that makes a site appear untrustworthy and insecure, so certificates must be renewed before they expire; many free certificates (like Let's Encrypt) and hosting setups auto-renew, which prevents lapses, and it is important to ensure renewal is handled (automatically or with reminders) so the certificate never lapses. For a South African business, the practical guidance is that a free SSL certificate (from the host or Let's Encrypt) is sufficient to secure the site over HTTPS for most needs, with paid certificates being an optional choice for extra identity validation or features rather than a necessity; and, crucially, that the certificate must be kept current, ideally through auto-renewal, since an expired certificate triggers browser security warnings that harm trust and access. Ensuring a valid, current SSL certificate is in place, and stays in place through renewal, is what keeps the site continuously secure and trusted, which is the essential practical requirement.
FAQ
Do South African websites need a paid SSL certificate?
Not necessarily. Free SSL certificates from Let's Encrypt are trusted by all major browsers and are sufficient for most South African business websites. Paid certificates offer additional validation levels (OV or EV) and commercial warranties, which may be worthwhile for large e-commerce or financial services sites.
What happens when an SSL certificate expires?
When an SSL certificate expires, browsers display a full-page security warning preventing visitors from accessing your site. This causes immediate traffic loss and damages trust. South African business owners should set calendar reminders or enable auto-renewal on their hosting panel to avoid expiry.