"Is it okay if our site URL stays as http://?" "Is free SSL really safe enough?"—We are increasingly receiving questions like these from small and midsize business owners managing websites.
SSL certificates serve as the foundation protecting website security, yet it is quite common to hear people say, "There are too many types to understand," or "I can't tell the real difference between free and paid options." In this article, we explain everything from the fundamentals of SSL certificates to their types, costs, and selection criteria so that anyone can understand without prior technical knowledge.
What is an SSL certificate?
SSL stands for "Secure Sockets Layer," which is a mechanism that encrypts communication between a web server and a browser. Today, its successor standard, "TLS (Transport Layer Security)," is actually used, but it is still conventionally referred to as "SSL."
When you install an SSL certificate, the URL changes from http:// to https://, and a padlock icon appears in the browser's address bar. This indicates that "communication with this website is encrypted and protected from eavesdropping or tampering by third parties."
Why implementing SSL is essential
- Preventing data breaches: Encrypts personal information entered into forms, such as names, email addresses, and credit card numbers
- Impact on SEO: Google has explicitly stated since 2014 that HTTPS adoption is a ranking signal, putting non-HTTPS sites at a disadvantage
- Browser security warnings: Major browsers such as Chrome display "Not Secure" warnings on
http://pages, prompting visitors to bounce - Establishing trustworthiness: Proves that a site meets baseline corporate security measures
The 3 types of SSL certificates | DV, OV, and EV
SSL certificates are broadly classified into three types based on their validation levels. This classification reflects differences in "who and what is validated, and to what extent, before issuance."
DV certificates (Domain Validation)
Short for Domain Validation. A certificate authority issues these after verifying only ownership of the domain.
- Ease of acquisition: Easiest (issued in minutes to a few hours)
- Cost: Free to a few thousand yen per year
- Suitable sites: Personal blogs, informational websites, and small corporate sites
- Points to note: Can verify that "this domain belongs to the applicant," but does not verify "what kind of company the applicant is"
Let’s Encrypt issues this type of certificate free of charge and comes standard with many shared and rental hosting servers.
OV certificates (Organization Validation)
Short for Organization Validation. Issued after verifying domain ownership as well as the legal existence of the company (corporate registry information, physical address, phone number, etc.).
- Ease of acquisition: Requires document screening, taking several days to about a week
- Cost: Approximately 20,000 to 50,000 yen per year
- Suitable sites: General corporate websites, recruitment sites, and B2B service portals
- Points to note: The company name is included in the certificate details, but is not displayed directly in the browser's address bar
EV certificates (Extended Validation)
Short for Extended Validation. Issued only after passing the most rigorous verification process (corporate registration, physical location, telephone verification, applicant employment status, etc.).
- Ease of acquisition: Involves strict vetting and can take 1 to 2 weeks or more
- Cost: Approximately 60,000 to 120,000 yen per year
- Suitable sites: Financial institutions, e-commerce sites, medical organizations, and other services requiring high trust
- Points to note: In the past, company names were highlighted in green in the address bar, but major browsers discontinued this display format after 2019
Comparison of the 3 certificate types
| Item | DV (Domain Validation) | OV (Organization Validation) | EV (Extended Validation) |
|---|---|---|---|
| Validation scope | Domain ownership only | Domain + company existence | Domain + company existence + in-depth vetting |
| Issuance time | Minutes to several hours | Several days to 1 week | 1 to 2+ weeks |
| Annual cost | Free to several thousand yen | 20,000–50,000 JPY | 60,000 to 120,000 yen |
| Primary use case | Personal & small-scale websites | Standard corporate websites | Finance, e-commerce & healthcare |
| Encryption strength | Identical | Identical | Identical |
As a key point, encryption strength is completely identical across all three types. While higher validation levels demonstrate "how thoroughly the identity of the site operator is verified," there is no difference in the technical quality of data encryption.
Differences between free SSL vs. paid SSL
It is completely natural to wonder, "If it can be used for free, why choose a paid option?" Let us break down the differences between the two.
Pros and cons of free SSL
Pros
- Incurs no cost (such as Let’s Encrypt)
- Frequently included as standard on hosting servers, making setup simple
- Encryption strength is equivalent to paid certificates
Cons
- Limited to DV validation (cannot prove the legal existence of a company)
- Short validity period (Let’s Encrypt certificates last 90 days)
- Requires automated certificate renewal configuration
- Includes no warranty or financial guarantee from the issuer
Pros and cons of paid SSL
Pros
- Can verify corporate legal existence via OV or EV validation
- Often includes a financial warranty backed by the certificate authority
- Provides access to dedicated technical support
- Offers flexible options like multi-domain and wildcard coverage
Cons
- Incurs recurring costs (approx. 20,000 to 120,000 yen annually)
- Takes longer to obtain (for OV and EV)
Decision criteria for small businesses
While we recommend paid OV or EV certificates for e-commerce sites and services handling payments, for informational corporate sites or recruiting sites, a free DV certificate (Let’s Encrypt) presents virtually no practical issues.
The crucial factor is whether the site is served over HTTPS; prioritizing implementing SSL itself is far more urgent than debating certificate types.
Crucial 2026 change | Shortening certificate validity periods
In April 2025, the CA/Browser Forum (the industry body setting standards for SSL certificates) officially approved a policy to progressively shorten the maximum validity period of certificates. Major browser vendors including Google, Apple, Mozilla, and Microsoft all voted in favor.
Shortening schedule
| Issuance period | Maximum validity period |
|---|---|
| Through March 14, 2026 | 398 days (approx. 13 months) |
| March 15, 2026 to March 14, 2027 | 200 days (approx. 6.5 months) |
| March 15, 2027 to March 14, 2028 | 100 days (approx. 3 months) |
| March 15, 2029 and later | 47 days |
Let’s Encrypt has operated with a short 90-day lifespan from the start, relying widely on automated renewals via tools like certbot. However, organizations managing paid certificates manually will see their renewal workload increase substantially.
Actions companies should take
- Adopt automated renewal workflows: If your certificate renewals are handled manually, consider migrating to automation tools supporting the ACME protocol
- Consult your development or hosting partner: If website maintenance is outsourced, verify their policy for handling certificate lifecycle management
- Monitor certificate expiration dates: Having a "Security Warning" displayed to visitors due to an expired certificate severely undermines trust
Major SSL certificate providers and estimated costs
When purchasing an SSL certificate, it helps to understand where to acquire one. Here are some representative providers.
Free (DV certificates)
Let’s Encrypt is a non-profit certificate authority operated by the Internet Security Research Group (ISRG). Currently protecting hundreds of millions of websites globally, it represents the de facto industry standard. Its certificates have a 90-day validity period and are designed to be paired with automated renewals. Many rental and shared hosting providers (such as Xserver, Sakura Internet, and ConoHa) provide it out of the box, allowing one-click activation from their admin panels.
Paid (OV and EV certificates)
| Provider | OV certificate (annual) | EV certificate (annual) |
|---|---|---|
| GMO GlobalSign | From approx. 28,500 yen | From approx. 74,000 yen |
| DigiCert | From approx. 30,000 yen | From approx. 123,300 yen |
| XServer SSL | From approx. 26,400 yen | From approx. 66,880 yen |
*Prices reflect reference rates as of April 2026. Please check each provider's official website for current pricing.
Note that GMO GlobalSign has shortened the validity period of certificates issued on or after March 14, 2026 to 199 days, meaning renewal tasks will occur during your contract period.
Frequently asked questions about SSL
Q. How can I check my website's SSL status?
You can check it directly in your browser's address bar. If the URL starts with https:// and displays a padlock icon, SSL is configured. Clicking the padlock icon displays "Connection is secure," where you can inspect certificate details. In Chrome, clicking the padlock icon → "Connection is secure" → "Certificate is valid" allows you to view the certificate type, issuer, and expiration date.
Q. Can I protect multiple domains with a single certificate?
Yes, by using "Multi-Domain Certificates (SAN certificates)" or "Wildcard Certificates," you can secure multiple domains and subdomains under one certificate.
- Multi-domain certificate: Covers distinct domains such as
example.com,example.co.jp, andexample.netwith a single certificate - Wildcard certificate: Secures all subdomains under the same domain in the format
*.example.com, coveringshop.example.com,blog.example.com, etc.
For companies operating multiple services, this approach can often reduce costs compared to purchasing individual certificates.
Q. What happens when an SSL certificate expires?
Browsers display an interstitial warning stating "Your connection is not private," preventing visitors from reaching the website. Especially for e-commerce sites or pages with inquiry forms, an expired certificate leads directly to immediate lost business opportunities. It can also harm your Google search performance. Be sure to audit expiration dates regularly or configure automated renewals.
Q. What precautions should be taken when migrating a WordPress site to HTTPS?
When migrating an existing http:// site to HTTPS, simply installing an SSL certificate is not enough; the following steps are also required.
- Update the site URL in WordPress settings to
https:// - Batch-replace internal links and image URLs with
https:// - Add HTTP to HTTPS redirect rules in
.htaccess - Add the new property and resubmit sitemaps in Google Search Console
- Update destination URLs in Google Analytics tracking configurations
Overlooking these steps can cause "Mixed Content" errors, preventing the padlock icon from appearing.
Summary: How to choose an SSL certificate
Here is a concise summary of how to choose an SSL certificate according to your website's intended purpose.
Cases where free SSL (DV) is sufficient
- Informational corporate websites
- Blogs and owned media outlets
- Recruitment website
- Websites featuring only standard contact forms
Cases where paid SSL (OV) should be considered
- When demonstrating verified credibility to business partners and investors is necessary
- B2B services where verified corporate identity impacts sales deals
- Sites featuring forms processing sensitive personal data or user accounts
Cases where paid SSL (EV) is required
- E-commerce stores and services with payment features
- Finance, healthcare, legal, or regulated industries where high trust is mandatory
- High-profile brand websites exposed to severe phishing risks
Conclusion
To summarize SSL certificates, these three points represent the core decisions.
- Prioritize HTTPS first: Free or paid, any site remaining on
http://requires immediate remediation - Select validation levels matching your purpose: Standard small business corporate sites are well served by free DV certificates. Consider paid OV or EV for e-commerce, payments, or finance
- Automating certificate management becomes virtually essential from 2026: With shortened validity lifespans, manual renewal operations are rapidly becoming impractical
If you would like to verify whether your current website SSL configuration is correct, or if you need end-to-end web production including certificate lifecycle management, feel free to contact GleamHub.
For typical website production pricing, explore How Much Does a Website Cost?, and for advice on revamps, see How to Plan a Corporate Website Revamp: Tips for a Successful RFP.
If you have any questions regarding SSL certificate setup or website security measures, contact GleamHub. We provide comprehensive web production and maintenance support for small and midsize businesses.
Free consultation hereReferences
- GMO GlobalSign — Types and Applications of SSL Server Certificates
- Let’s Encrypt — About Let’s Encrypt
- DigiCert — TLS Certificate Validity Periods Officially Shortened to 47 Days
- Council of Anti-Phishing Japan — Variations in SSL/TLS Server Certificate Displays Across Browsers
- LAC WATCH — The Optimal Solution for Overcoming the 47-Day SSL/TLS Certificate Rule








