The Complete Guide To SSL Certificates (2026 Refresh)
What is SSL, and what is TLS?

SSL is one of those terms every website owner hears within their first week online, yet it rarely gets explained properly. We will cover what SSL and TLS actually are, how a certificate protects your visitors, which certificate type fits your site, and how to get one free. We will also explain the single change that matters most in 2026, because from 15 March certificates can no longer be issued for longer than 200 days.
SSL stands for Secure Sockets Layer. It was the original encryption protocol, built by Netscape in the 1990s to protect early web traffic. TLS, short for Transport Layer Security, replaced SSL in 1999 after serious weaknesses were found in its predecessor. Every modern certificate uses TLS.
So why do we still say SSL? Habit, mostly. The name stuck long after the underlying technology moved on, rather like the way we still say dial when we mean connect. When you buy an SSL certificate today, you are buying a TLS certificate. For practical purposes the two names mean the same thing, but knowing the difference helps you sound confident when a colleague or a supplier mentions either one. If you want the wider business case first, our post on why SSL certificates are essential is a good starting point.
How an SSL certificate works
An SSL certificate is a small data file that does two jobs. It proves your domain is genuine, and it enables the encrypted connection your visitors rely on. The technology behind it is public key cryptography.
Here is what happens when someone visits your site. The browser asks your server for its certificate, then checks three things:
- Whether a trusted certificate authority issued it
- Whether it is still valid
- Whether it belongs to your domain.
If all three checks pass, the browser and server complete what is called a TLS handshake. They agree on a temporary session key, and from that moment every byte passing between them is encrypted.
The handshake happens in a fraction of a second, and your visitor sees none of it. They simply see the padlock. The maths stays hidden, but it is what stops anyone in the middle from reading passwords, card numbers or private messages.
The three types of certificate: DV, OV and EV
Certificates come in three levels of validation, and understanding the difference can save you money as well as time.
- Domain validation (DV) is the entry level. The authority checks that you control the domain, then issues the SSL certificate, often within minutes. DV covers the vast majority of websites, and it is the type issued free by Let’s Encrypt.
- Organisation validation (OV) adds a check on your business identity. The authority verifies your registered company details before issuing, which makes OV a sensible choice for shops and service businesses that want visitors to see a verified organisation name.
- Extended validation (EV) is the strictest tier and involves the most thorough vetting. Historically it also displayed a green address bar with your company name, but those green bars are gone. Every major browser removed them years ago, so EV no longer offers the visual signal it once did. For almost every site, a DV certificate provides the same padlock and the same encryption for free.
Why HTTPS matters for SEO and trust
Google and Bing both treat HTTPS as a ranking signal. It is not the heaviest factor in their algorithms, but when two otherwise equal pages compete for the same position, the secure one tends to win. Repeated across many pages and many months, those small advantages add up.

There is a trust angle too. Visitors rarely read a privacy policy, but they do notice a padlock. Plain common sense agrees with the data. People are far more comfortable entering an email address, a postcode or a card number on a page that looks secure.
Security and speed also work together. Encryption adds a little overhead, yet modern TLS and HTTP/2 keep that overhead negligible, and the trust it earns outweighs the cost.
What happens without an SSL certificate
Run an insecure site in 2026 and visitors will see the consequences before they even click. Browsers have flagged http pages as Not secure since 2017, and that warning sits right next to your domain in the address bar.
The effect is blunt. A modern visitor who sees Not secure may simply leave, and they may not come back. The data you collect is at risk as well. Without encryption, anything sent over the connection travels in plain text, readable by anyone who intercepts it. For a site that handles enquiries, logins or payments, that is simply not acceptable.
There is a search cost too. Google has confirmed that it prefers secure pages. The good news is that fixing it is free, and it takes minutes on most modern hosting.
How to get a free SSL certificate
Free does not mean inferior. Let’s Encrypt is a widely trusted certificate authority that issues domain validation certificates at no cost, and those certificates provide exactly the same encryption as any paid DV certificate. Millions of sites rely on it every day.
If you host with UK2 web hosting, you do not even need to install one. Every plan includes unlimited Let’s Encrypt SSL certificates, issued and renewed automatically. You pick your plan, we handle the certificate, and your site runs over https from day one. That includes the Essential plan, our most affordable option, where the first month costs £1 and renewal is £3.99 a month. If you have not moved your domain yet, transferring it to UK2 is straightforward.
If your site runs on WordPress, SSL is only one part of staying safe online. Our guide to WordPress security covers the rest.
2026 change: certificate lifespans drop to 200 days
Here is the update that touches every certificate on the web. On 15 March 2026, the maximum lifespan of an SSL certificate dropped from 398 days to 200 days. The change came from the industry body that sets the baseline requirements all certificate authorities must follow, and it continues a long push towards shorter lifespans.
Why does a shorter lifespan matter? It shrinks the window in which a stolen or compromised certificate can be misused, and it forces the whole ecosystem to rotate keys more often. The trade-off is that renewal becomes a more frequent chore. A certificate that used to last just over a year now needs attention roughly every six months.
That is exactly why automated renewal matters. Manage certificates by hand and you now have more renewal dates to remember. Let certificates renew themselves and the change becomes invisible. On UK2 hosting our Let’s Encrypt certificates renew automatically, so the 200-day SSL rule passes you by completely.
Frequently Asked Questions
SSL (Secure Sockets Layer) was the original encryption protocol, created by Netscape in the 1990s. TLS (Transport Layer Security) replaced it in 1999, and every modern certificate uses TLS. The name SSL stuck, which is why we still talk about SSL certificates today.
Since 15 March 2026, the maximum lifespan of any SSL certificate is 200 days, down from the previous 398-day limit. UK2 hosting plans include unlimited Let’s Encrypt certificates that renew automatically, so you do not need to track renewal dates yourself.
For most websites, yes. Free certificates from Let’s Encrypt are full domain validation (DV) certificates that provide the same encryption and the same padlock as paid DV certificates. UK2 includes unlimited free Let’s Encrypt SSL on every web hosting plan.
No. Extended validation (EV) certificates once showed a green address bar, but browsers removed that indicator years ago. Today EV mainly offers a slightly higher level of vetting, and for most sites a DV certificate is all you need.
Look for the padlock icon next to your domain in the browser address bar, and check that the address starts with https rather than http. For a deeper check, you can test your certificate using SSL Labs.
On 15 March 2026 the industry shortened the maximum certificate lifespan from 398 days to 200 days. Shorter lifespans reduce the window in which a compromised certificate can be misused. With automated renewal, the change is invisible to most site owners.
Get your website online
Every UK2 web hosting plan includes unlimited free SSL, automatic renewal and everything else you need to launch securely. Start with the Essential plan at £1 for the first month, or talk to our UK-based support team if you would like advice first.
The Company
Popular This Week
Recent posts
-
What Is Web Hosting? A Beginner’s Guide to Hosting Your Website
-
How to Start an Online Store in the UK
-
Business Email Hosting: Why Free Gmail Isn’t Enough
-
How to Choose a Web Hosting Provider for Your Business Website
-
Getting online just got easier: what’s new in your UK2 Website Builder and Online Shop