Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Types of SSL certificates and how to choose: Explaining free vs. paid options

Table of contents · 8 items

"Is it okay if our site URL stays as http://?" "Is free SSL really safe enough?"—We are increasingly receiving questions like these from small and midsize business owners managing websites.

SSL certificates serve as the foundation protecting website security, yet it is quite common to hear people say, "There are too many types to understand," or "I can't tell the real difference between free and paid options." In this article, we explain everything from the fundamentals of SSL certificates to their types, costs, and selection criteria so that anyone can understand without prior technical knowledge.


What is an SSL certificate?

SSL stands for "Secure Sockets Layer," which is a mechanism that encrypts communication between a web server and a browser. Today, its successor standard, "TLS (Transport Layer Security)," is actually used, but it is still conventionally referred to as "SSL."

When you install an SSL certificate, the URL changes from http:// to https://, and a padlock icon appears in the browser's address bar. This indicates that "communication with this website is encrypted and protected from eavesdropping or tampering by third parties."

Why implementing SSL is essential

  • Preventing data breaches: Encrypts personal information entered into forms, such as names, email addresses, and credit card numbers
  • Impact on SEO: Google has explicitly stated since 2014 that HTTPS adoption is a ranking signal, putting non-HTTPS sites at a disadvantage
  • Browser security warnings: Major browsers such as Chrome display "Not Secure" warnings on http:// pages, prompting visitors to bounce
  • Establishing trustworthiness: Proves that a site meets baseline corporate security measures

The 3 types of SSL certificates | DV, OV, and EV

SSL certificates are broadly classified into three types based on their validation levels. This classification reflects differences in "who and what is validated, and to what extent, before issuance."

DV certificates (Domain Validation)

Short for Domain Validation. A certificate authority issues these after verifying only ownership of the domain.

  • Ease of acquisition: Easiest (issued in minutes to a few hours)
  • Cost: Free to a few thousand yen per year
  • Suitable sites: Personal blogs, informational websites, and small corporate sites
  • Points to note: Can verify that "this domain belongs to the applicant," but does not verify "what kind of company the applicant is"

Let’s Encrypt issues this type of certificate free of charge and comes standard with many shared and rental hosting servers.

OV certificates (Organization Validation)

Short for Organization Validation. Issued after verifying domain ownership as well as the legal existence of the company (corporate registry information, physical address, phone number, etc.).

  • Ease of acquisition: Requires document screening, taking several days to about a week
  • Cost: Approximately 20,000 to 50,000 yen per year
  • Suitable sites: General corporate websites, recruitment sites, and B2B service portals
  • Points to note: The company name is included in the certificate details, but is not displayed directly in the browser's address bar

EV certificates (Extended Validation)

Short for Extended Validation. Issued only after passing the most rigorous verification process (corporate registration, physical location, telephone verification, applicant employment status, etc.).

  • Ease of acquisition: Involves strict vetting and can take 1 to 2 weeks or more
  • Cost: Approximately 60,000 to 120,000 yen per year
  • Suitable sites: Financial institutions, e-commerce sites, medical organizations, and other services requiring high trust
  • Points to note: In the past, company names were highlighted in green in the address bar, but major browsers discontinued this display format after 2019

Comparison of the 3 certificate types

ItemDV (Domain Validation)OV (Organization Validation)EV (Extended Validation)
Validation scopeDomain ownership onlyDomain + company existenceDomain + company existence + in-depth vetting
Issuance timeMinutes to several hoursSeveral days to 1 week1 to 2+ weeks
Annual costFree to several thousand yen20,000–50,000 JPY60,000 to 120,000 yen
Primary use casePersonal & small-scale websitesStandard corporate websitesFinance, e-commerce & healthcare
Encryption strengthIdenticalIdenticalIdentical

As a key point, encryption strength is completely identical across all three types. While higher validation levels demonstrate "how thoroughly the identity of the site operator is verified," there is no difference in the technical quality of data encryption.


Differences between free SSL vs. paid SSL

It is completely natural to wonder, "If it can be used for free, why choose a paid option?" Let us break down the differences between the two.

Pros and cons of free SSL

Pros

  • Incurs no cost (such as Let’s Encrypt)
  • Frequently included as standard on hosting servers, making setup simple
  • Encryption strength is equivalent to paid certificates

Cons

  • Limited to DV validation (cannot prove the legal existence of a company)
  • Short validity period (Let’s Encrypt certificates last 90 days)
  • Requires automated certificate renewal configuration
  • Includes no warranty or financial guarantee from the issuer

Pros and cons of paid SSL

Pros

  • Can verify corporate legal existence via OV or EV validation
  • Often includes a financial warranty backed by the certificate authority
  • Provides access to dedicated technical support
  • Offers flexible options like multi-domain and wildcard coverage

Cons

  • Incurs recurring costs (approx. 20,000 to 120,000 yen annually)
  • Takes longer to obtain (for OV and EV)

Decision criteria for small businesses

While we recommend paid OV or EV certificates for e-commerce sites and services handling payments, for informational corporate sites or recruiting sites, a free DV certificate (Let’s Encrypt) presents virtually no practical issues.

The crucial factor is whether the site is served over HTTPS; prioritizing implementing SSL itself is far more urgent than debating certificate types.


Crucial 2026 change | Shortening certificate validity periods

In April 2025, the CA/Browser Forum (the industry body setting standards for SSL certificates) officially approved a policy to progressively shorten the maximum validity period of certificates. Major browser vendors including Google, Apple, Mozilla, and Microsoft all voted in favor.

Shortening schedule

Issuance periodMaximum validity period
Through March 14, 2026398 days (approx. 13 months)
March 15, 2026 to March 14, 2027200 days (approx. 6.5 months)
March 15, 2027 to March 14, 2028100 days (approx. 3 months)
March 15, 2029 and later47 days

Let’s Encrypt has operated with a short 90-day lifespan from the start, relying widely on automated renewals via tools like certbot. However, organizations managing paid certificates manually will see their renewal workload increase substantially.

Actions companies should take

  • Adopt automated renewal workflows: If your certificate renewals are handled manually, consider migrating to automation tools supporting the ACME protocol
  • Consult your development or hosting partner: If website maintenance is outsourced, verify their policy for handling certificate lifecycle management
  • Monitor certificate expiration dates: Having a "Security Warning" displayed to visitors due to an expired certificate severely undermines trust

Major SSL certificate providers and estimated costs

When purchasing an SSL certificate, it helps to understand where to acquire one. Here are some representative providers.

Free (DV certificates)

Let’s Encrypt is a non-profit certificate authority operated by the Internet Security Research Group (ISRG). Currently protecting hundreds of millions of websites globally, it represents the de facto industry standard. Its certificates have a 90-day validity period and are designed to be paired with automated renewals. Many rental and shared hosting providers (such as Xserver, Sakura Internet, and ConoHa) provide it out of the box, allowing one-click activation from their admin panels.

Paid (OV and EV certificates)

ProviderOV certificate (annual)EV certificate (annual)
GMO GlobalSignFrom approx. 28,500 yenFrom approx. 74,000 yen
DigiCertFrom approx. 30,000 yenFrom approx. 123,300 yen
XServer SSLFrom approx. 26,400 yenFrom approx. 66,880 yen

*Prices reflect reference rates as of April 2026. Please check each provider's official website for current pricing.

Note that GMO GlobalSign has shortened the validity period of certificates issued on or after March 14, 2026 to 199 days, meaning renewal tasks will occur during your contract period.


Frequently asked questions about SSL

Q. How can I check my website's SSL status?

You can check it directly in your browser's address bar. If the URL starts with https:// and displays a padlock icon, SSL is configured. Clicking the padlock icon displays "Connection is secure," where you can inspect certificate details. In Chrome, clicking the padlock icon → "Connection is secure" → "Certificate is valid" allows you to view the certificate type, issuer, and expiration date.

Q. Can I protect multiple domains with a single certificate?

Yes, by using "Multi-Domain Certificates (SAN certificates)" or "Wildcard Certificates," you can secure multiple domains and subdomains under one certificate.

  • Multi-domain certificate: Covers distinct domains such as example.com, example.co.jp, and example.net with a single certificate
  • Wildcard certificate: Secures all subdomains under the same domain in the format *.example.com, covering shop.example.com, blog.example.com, etc.

For companies operating multiple services, this approach can often reduce costs compared to purchasing individual certificates.

Q. What happens when an SSL certificate expires?

Browsers display an interstitial warning stating "Your connection is not private," preventing visitors from reaching the website. Especially for e-commerce sites or pages with inquiry forms, an expired certificate leads directly to immediate lost business opportunities. It can also harm your Google search performance. Be sure to audit expiration dates regularly or configure automated renewals.

Q. What precautions should be taken when migrating a WordPress site to HTTPS?

When migrating an existing http:// site to HTTPS, simply installing an SSL certificate is not enough; the following steps are also required.

  1. Update the site URL in WordPress settings to https://
  2. Batch-replace internal links and image URLs with https://
  3. Add HTTP to HTTPS redirect rules in .htaccess
  4. Add the new property and resubmit sitemaps in Google Search Console
  5. Update destination URLs in Google Analytics tracking configurations

Overlooking these steps can cause "Mixed Content" errors, preventing the padlock icon from appearing.


Summary: How to choose an SSL certificate

Here is a concise summary of how to choose an SSL certificate according to your website's intended purpose.

Cases where free SSL (DV) is sufficient

  • Informational corporate websites
  • Blogs and owned media outlets
  • Recruitment website
  • Websites featuring only standard contact forms

Cases where paid SSL (OV) should be considered

  • When demonstrating verified credibility to business partners and investors is necessary
  • B2B services where verified corporate identity impacts sales deals
  • Sites featuring forms processing sensitive personal data or user accounts

Cases where paid SSL (EV) is required

  • E-commerce stores and services with payment features
  • Finance, healthcare, legal, or regulated industries where high trust is mandatory
  • High-profile brand websites exposed to severe phishing risks

Conclusion

To summarize SSL certificates, these three points represent the core decisions.

  1. Prioritize HTTPS first: Free or paid, any site remaining on http:// requires immediate remediation
  2. Select validation levels matching your purpose: Standard small business corporate sites are well served by free DV certificates. Consider paid OV or EV for e-commerce, payments, or finance
  3. Automating certificate management becomes virtually essential from 2026: With shortened validity lifespans, manual renewal operations are rapidly becoming impractical

If you would like to verify whether your current website SSL configuration is correct, or if you need end-to-end web production including certificate lifecycle management, feel free to contact GleamHub.

For typical website production pricing, explore How Much Does a Website Cost?, and for advice on revamps, see How to Plan a Corporate Website Revamp: Tips for a Successful RFP.

If you have any questions regarding SSL certificate setup or website security measures, contact GleamHub. We provide comprehensive web production and maintenance support for small and midsize businesses.

Free consultation here

References

Share this articleXFacebook
Rui Teruya

Former corporate league baseball player and founder of an IT venture. Founded the company with the drive to ride the fast-moving waves of the world and deliver truly valuable services to society.

Turn this article's theme into your company's next step

Concrete steps forward for your organization.

We organize your desired architecture, legacy systems, and operational requirements to formulate your next steps toward execution.

  • Desired architecture
  • Integration with existing environments
  • Operational requirements
Consult on development & operations initiatives

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles via email · Read the web production guide
Free download

Complete Guide to Web Production: Costs, Vendor Selection & Traffic Acquisition [2026 Edition]

We have compiled cost benchmarks, vendor selection criteria, and traffic acquisition strategies into a PDF.

The PDF and newsletter emails are currently in Japanese.

You will also be subscribed to our newsletter. You can unsubscribe at any time.