Skip to content
codecollab.pl
§ Blog free ssl certificate

Free or paid SSL certificate - which to pick for a business site

For a business site and the vast majority of stores, a free SSL certificate is entirely enough, because it encrypts exactly the same as a paid one

Krystian Kacik 9 min read
Contents

For a business site and the vast majority of stores, a free SSL certificate is entirely enough, because it encrypts exactly the same as a paid one. The browser shows the same padlock, Google treats both sites identically, and the customer has no way of checking what you paid. What the extra money buys is three things: company verification written into the certificate, technical support from the issuer, and a formal financial guarantee. Below I break down when those three things make sense and when they are money with nothing behind it.

What an SSL certificate actually is

An SSL certificate is a file issued by a trusted certificate authority confirming that a given domain belongs to whoever is using it, and allowing an encrypted connection between browser and server. Thanks to it the address starts with https, and data from a form or a cart does not travel across the network in plain text.

The key distinction people trip over: a certificate does not check whether a site is safe or whether a company is honest. It confirms only the domain’s identity and turns encryption on. A hacked site with a padlock is still a hacked site, only the encryption works.

Is a free certificate technically weaker

No. Encryption strength does not depend on the price of the certificate but on the algorithm and the server configuration. A free certificate from Let’s Encrypt uses the same standards as one costing several hundred zloty a year, and is trusted by default in every browser and operating system that matters.

The differences that genuinely exist:

FeatureFree (Let’s Encrypt)Paid
Encryption strengththe samethe same
Browser trustfullfull
Padlock in the address baryesyes
Company verification in the certificatenowith OV and EV
Issuer technical supportnone, only docs and communityyes, usually included
Financial guaranteenoneyes, but it covers an injured third party, not you
Renewalautomatic, every few dozen daysmanual or semi-automatic

The last row matters more than it looks. A free certificate has a short validity precisely to force automation, and with correct configuration it renews itself without your involvement. A paid one is often renewed by hand, off a reminder email somebody misses. What happens next I covered separately in the piece on what to do when an SSL certificate expires.

Certificate types: DV, OV, EV, wildcard

The types differ in what the issuer checks before releasing the file, and how many domains a single file covers.

TypeWhat is verifiedFor whom
DV (Domain Validation)control over the domain only, issued in minutescompany sites, blogs, most stores
OV (Organization Validation)additionally the company’s existence in registers, a few daysinstitutions, large brands, tender requirements
EV (Extended Validation)extended legal verification of the companybanks, insurers, finance
Wildcardthe domain plus all subdomains at one levelmany subdomains, e.g. store, blog, panel
Multi-domain / SANseveral different domains in one certificatea site with several brands or languages

Free certificates are always DV, though a wildcard version is available for free too - it just needs verification through a DNS record instead of the simpler file method. OV and EV can only be bought, because there you are paying for a human checking company documents.

One thing worth saying plainly, because it still shows up in sales pitches: EV no longer gives you a green bar with the company name. Browsers retired that indicator years ago, because in practice users did not notice it and it did not affect their decisions. Today only somebody who opens the certificate details sees the company name - which is practically none of your customers.

What you really pay for with a paid certificate

You pay for three things, none of which concerns encryption.

  1. Company identity verification written into the certificate. It matters where somebody actually checks it: in tenders, in audits, in conversations with a large counterparty, sometimes in a payment provider’s requirements.
  2. Issuer support. When something will not install on the server, there is somebody to write to and get an answer from within a reasonable time. With a free certificate you have documentation and forums, so in practice you are buying peace of mind or paying somebody for the setup.
  3. A financial guarantee, usually described as a dollar amount. It sounds serious, but it protects a party harmed by a mis-issued certificate, not the site owner. For a small company it is a dead letter and not worth deciding on.

What it costs

Issuer and reseller price lists change several times a year, so treat the figures below as an order of magnitude on the Polish market, to be verified on the day of purchase.

OptionRough annual costNotes
Free DV0 PLNLet’s Encrypt and similar issuers, one click on most hosting
Paid DVa few dozen up to about 200 PLN netmainly for support and a convenient reseller panel
OVseveral hundred PLN netcompany verification, a few days of waiting
EVseveral hundred to over a thousand PLN netjustified in finance and under hard requirements
Paid wildcardseveral hundred PLN net and upa free equivalent exists, it just needs DNS access

Add implementation time to the bill if your hosting has no one-click handling. A certificate that costs 0 PLN can still cost a few hours of work on a badly chosen server, which is why when picking hosting it pays to look straight away at whether it has built-in automatic SSL. I go into that in the piece on which WordPress hosting to choose. If you want the pure cost-benefit case, I have a separate piece on SSL certificate pricing and when it is worth paying.

When free is enough and when to pay

A free DV certificate is enough if you run a company site, a blog, a portfolio, a landing page or a store that hands payments to an external provider - PayU, Przelewy24, Stripe or BLIK through a gateway. In that setup you never process card data yourself and there is nothing to add.

Paying is worth considering in four situations:

  1. Your counterparty or a tender requires it and you have it in writing in the specification.
  2. You work in finance, insurance or healthcare, where company verification can be part of regulatory compliance.
  3. You have an environment where automatic renewal is impossible, for example devices or internal systems with no internet access.
  4. You want support on the phone and prefer to buy peace of mind rather than learn the configuration.

Outside those cases the extra money buys neither better security nor a better Google position. Google has treated https as a signal for years, but it does not distinguish certificate types, so EV will not lift you above DV.

What breaks more often than the certificate itself

The most common SSL problems come not from the choice of issuer but from the implementation. Three classics I see on sites that come in for repair:

  • Mixed content. The certificate is there, but some images, scripts or fonts still load over http, so the padlock disappears or a warning shows up. The fix is replacing addresses in the database and in theme settings.
  • No redirect. The site runs in parallel on http and https, which duplicates URLs for search engines and dilutes signals. You need one permanent redirect to the encrypted version plus the correct address in WordPress settings.
  • A certificate that expired quietly. Renewal did not fire, the email went to an old mailbox, and the browser greets customers with a full-screen warning. Customers do not read those messages, they close the tab.

Those three cost more than any certificate, because they hit conversion and the technical foundations of visibility at the same time.

How to sort this out on your side

If you are not sure exactly what is running on your server and whether renewal is genuinely automatic, I start with a free diagnosis: I check the certificate type and expiry date, how renewal works, the redirects and mixed content, and say plainly whether there is anything to do or not. For bigger work - tidying URLs after a migration, or configuring a wildcard for several subdomains - you get a written quote before the start, not a bill after the fact. If you would rather not think about expiry dates at all, that watching duty falls under ongoing technical support together with updates and backups.

Frequently asked questions

Is an SSL certificate free? Yes, you can have a fully trusted SSL certificate for free. The most popular free issuer is Let’s Encrypt, and its certificates are accepted by default in every browser. Most hosting has the option built into the panel and it is enabled with one click.

Is a free SSL certificate safe? Yes, the level of encryption is identical to paid certificates. The difference concerns only the depth of entity verification, technical support and the financial guarantee - not the protection of the data being transmitted.

Where do I buy an SSL certificate most cheaply? The cheapest is a free DV from your hosting panel, provided the host supports it. If you need a paid one, reseller prices are often noticeably lower than buying direct from the issuer for the same certificate. Just check whether installation support is included.

Does an SSL certificate need renewing every year? More often than that. The maximum validity period is being steadily shortened across the industry and is heading towards a few dozen days, so manual renewal is ceasing to make sense. Set up automatic renewal and expiry monitoring, whether the certificate is free or paid.


Would rather not watch over it every month yourself? I take sites and stores under ongoing care - backups, updates, monitoring, and priority when something breaks. Tell me what you run and I will send back scope and price.

§ Quote in 24h

Your website is not bringing in enquiries or looks dated, and you do not know where to start?

Describe the scope in two sentences or send a link to your site. I tell you what to fix first, and you get a fixed bid in writing within 24 hours - no "from X" pricing.

Send your scope - quote in 24h