HTTPS / SSL
HTTPS is the web's secure communication protocol, switched on by an SSL/TLS certificate that encrypts the data exchanged between the user's browser and the server.
Why it matters
HTTPS is an absolute prerequisite for any website in 2026. Without it your site is penalised by Google, flagged 'Not secure' by browsers, and rejected by 82% of visitors. It is the basis of trust online and of protecting your users' data.
What are HTTPS and SSL?
HTTPS (HyperText Transfer Protocol Secure) is the secure version of the HTTP protocol used to load web pages. The difference with HTTP? Every piece of data exchanged between the user's browser and the server is encrypted, thanks to an SSL/TLS certificate (Secure Sockets Layer / Transport Layer Security). The padlock in the address bar tells the visitor the connection is secure.
In practice, when a visitor fills in a contact form or enters their card details on your site, HTTPS encryption stops an attacker reading that data. Without HTTPS, the data travels in plain text and can be read by anyone on the network. In 2026, 95% of web traffic runs over HTTPS, and every modern browser flags HTTP sites as "Not secure".
Why HTTPS is not optional
Google requires it. Since 2014, HTTPS has been a confirmed SEO ranking factor. HTTPS sites are favoured in search results. Since 2018, Chrome has shown a "Not secure" warning on every HTTP site, which scares visitors away. In 2026, an HTTP site is simply unacceptable.
Browsers enforce it. Chrome, Firefox, Safari and Edge all display warnings for sites that are not secure. Some modern web features (geolocation, push notifications, camera and microphone, service workers) are blocked on HTTP sites.
The law points that way. The GDPR requires "appropriate" security measures to protect personal data. Failing to encrypt data in transit with HTTPS can be treated as a breach of that requirement.
Users expect it. 82% of internet users leave a site that shows "Not secure". Trust is the foundation of trading online, and HTTPS is the bare minimum for building it.
How an SSL certificate works
When a user connects to an HTTPS site, a process called the SSL handshake happens in a few milliseconds. The server sends its SSL certificate to the browser. The browser checks that the certificate is valid (issued by a recognised certification authority, not expired, matching the domain). Once it checks out, a unique encryption key is generated for that session. Every piece of data exchanged after that is encrypted with that key.
SSL certificates are issued by certification authorities (CAs): Let's Encrypt (free and automatic), DigiCert, Comodo, GlobalSign. There are three levels of validation: DV (Domain Validation, confirms you own the domain, enough for most sites), OV (Organization Validation, checks the company), and EV (Extended Validation, in-depth checks, shows the company name in the address bar).
Getting and installing an SSL certificate
The simplest and cheapest route: Let's Encrypt. Most modern hosts (Vercel, Netlify, OVH, Cloudflare) include a free, automatic Let's Encrypt certificate. With Vercel (which is what we use at ConvertiLab), HTTPS switches on by itself as soon as the domain is connected, with no configuration at all.
On traditional hosting, installation happens through the host's control panel (cPanel, Plesk) in a few clicks. Let's Encrypt certificates renew themselves automatically every 90 days.
Free or paid certificate: which should you choose?
One question keeps coming up with small business owners: should you pay for an SSL certificate? In the overwhelming majority of cases, no. A free DV certificate (Let's Encrypt) encrypts data in exactly the same way as a paid one: the technical level of security is identical, and the padlock shows up just the same. For a brochure site, a blog, a restaurant or a tradesperson, that is plenty.
Paid certificates only make sense in specific cases. An OV or EV certificate adds a stronger check on the company's identity, which is useful for a bank, a payment platform or a large online shop that wants to display every possible guarantee. Some also come with financial cover and dedicated support. But for 95% of small businesses, the free certificate covers every real need without costing a penny.
Common security mistakes to avoid
Installing an SSL certificate is not always enough: a few classic mistakes cancel out part of the benefit.
- Mixed content: an HTTPS page that still loads images, scripts or fonts over HTTP. The browser then shows a crossed-out padlock and the security warning comes back. - No 301 redirect: without redirects, the old HTTP URLs stay reachable and create duplicate content that hurts your SEO. - An expired certificate: on manually managed hosting, forgetting to renew the certificate makes the site unreachable overnight. Automation avoids that trap. - Forgetting to declare the HTTPS version in Google Search Console, which skews your indexing data.
Checking these points makes sure the move to HTTPS fully benefits both your search visibility and your image.
Migrating from HTTP to HTTPS
If your site is still on HTTP, migrating to HTTPS takes a few steps. Install the SSL certificate. Update all your internal URLs (links, images, scripts) from HTTP to HTTPS. Set up 301 redirects from every HTTP URL to its HTTPS equivalent. Update the XML sitemap and robots.txt. Declare the new HTTPS domain in Google Search Console. Check that every page loads correctly with no mixed content (resources still loading over HTTP on an HTTPS page).
The effect on performance
HTTPS encryption used to add latency, but with TLS 1.3 and HTTP/2 (which requires HTTPS), HTTPS sites are often faster than HTTP ones. HTTP/2 brings multiplexing (loading several resources at once), header compression and server push. It is a performance argument, not a brake.
HTTPS and the trust of local customers
For a shop or a local service provider, HTTPS is not just a technical matter: it is a signal of seriousness that people see straight away. A customer hesitating between two tradespeople is reassured by the security padlock, especially when it comes to leaving a phone number or paying a deposit online. The opposite is just as true: the red "Not secure" warning Chrome shows on an HTTP site is enough to send a prospect to a competitor. Securing your site protects both your data and your brand.
At ConvertiLab, all our sites are secured with HTTPS from day one thanks to Vercel's automatic SSL certificate, with correct 301 redirects and a check that no mixed content remains. Security is not an option, it is a prerequisite.
Practical examples
An online shop on HTTP migrates to HTTPS: the bounce rate falls by 15% because visitors no longer see the 'Not secure' warning, and organic traffic rises by 8% thanks to the SEO boost.
A contact form on an HTTP site was being ignored by wary visitors: after the move to HTTPS, form submissions rise by 42%.
A brochure site switches on HTTPS for free with Let's Encrypt on Vercel in 2 minutes: no cost, no maintenance, and immediate compliance with Google's requirements and the GDPR.
Frequently asked questions
Is an SSL certificate free?
Yes. Let's Encrypt provides free SSL certificates that every browser recognises. Most modern hosts (Vercel, Netlify, OVH) include them automatically. Paid certificates (50-490€ a year) are only needed for extended validation (EV), which displays the company name in the address bar.
Does my site need HTTPS even without an online shop?
Yes, absolutely. HTTPS is needed on any website, even a simple blog or brochure site. Google penalises HTTP sites in search, browsers show a 'Not secure' warning, and the GDPR requires personal data to be protected (including data from a simple contact form).
How do I check whether my site is on HTTPS?
Look at your browser's address bar. A padlock and 'https://' mean the connection is secure. If you see 'http://' or a 'Not secure' warning, your site has no valid SSL certificate. Use the Qualys SSL test (ssllabs.com/ssltest) for a full diagnosis.
Need help with HTTPS / SSL?
Our experts work with you to put an effective strategy in place. Get a free, tailored quote within 24 hours.
Go further
Related terms
Other definitions
Last updated: 6 April 2026

