Web Performance · 11 August 2026
An SSL Certificate for a Business Website Is Not Optional
A customer taps your listing, and before your homepage has drawn a single pixel, their browser has already given them an opinion about you.
With no SSL certificate for a business website, that opinion is “Not secure”. Grey text and a small warning triangle, sitting exactly where your name should be.
That is the whole argument. The certificate is not something you add for the technically minded. It is the difference between arriving and being turned away at the door.
What an SSL certificate for a business website actually proves
It encrypts the connection between the visitor’s phone and the server your site sits on. Nobody in the middle, on the cafe wifi or the mobile network, can read what passes between them. That is the whole job.
It does not prove you are a real business. It does not prove your prices are fair or your work is any good. Certificates are issued automatically and for nothing, so a scam site has one too.
Owners get this backwards in both directions. Some treat the padlock as a trust badge worth pointing at. It is not, and nobody notices it when it is there. Others assume it only matters if you take card payments. Also wrong: any page with a contact form is sending somebody’s name, phone number and address across the wire.
The not secure warning ends the visit before anyone reads a word
A Northallerton cafe rang us last winter because bookings had dropped and nobody could work out why. The site looked fine on the laptop in the back office. On a phone, Chrome was putting “Not secure” next to the address, and repeating the warning under the booking form.
Nobody had reported it. People do not ring to say your website frightened them. They go back to the results page and click the next one.
This is the same shape of loss as a homepage that takes seven seconds to load. The visitor never becomes a visitor. There is no missing enquiry to count, because they left before the site said anything at all.
https for small business is free and often already half done
Almost every host now includes a certificate at no cost. The usual failure is not that nobody bought one. It is that one was issued and then something was left unfinished.
Three things go wrong. The certificate lapsed because auto renewal was never switched on. The site still answers on http and was never redirected, so two versions of it exist. Or a single image or script is still called over http, which drops the padlock on an otherwise healthy page: a website security warning caused by one line of code.
Checking takes ten seconds. Open your own site on your phone, not the office laptop, and read the address bar. Then click through to your contact page and read it again, because the warning often only shows where the form is.
If it is wrong, that is an afternoon for whoever looks after the site, not a rebuild. It also belongs on the short monthly list in website maintenance, because certificates expire quietly and nothing tells you when they do.
Not clever, just done.
More field notes
Web Performance
Click to Call: The Mobile Detail That Wins a Roofer More Jobs
A mobile site that makes customers copy your number instead of tapping it loses calls. Click to call is the fix most local sites skip.
Web Performance
The Enquiry You Never See: Contact Form Emails Going to Spam
A contact form that submits fine but sends its notification to junk loses work quietly, and nobody ever tells you.
Web Performance
Contact Number Placement: The Header Beats the Footer
The number sitting in your footer is the number nobody finds. Moving it to the header is the cheapest way to win more calls.