How it works
TLS (Transport Layer Security) is the encryption behind HTTPS; SSL is its retired predecessor, but the old name stuck. A certificate ties a domain name to a public key and is signed by a certificate authority (CA) that browsers trust. On each connection the browser checks the signature, the name and the expiry date, then agrees keys with the server so the rest of the conversation is private and tamper-proof.
Let's Encrypt, a non-profit CA, issues free domain-validated (DV) certificates automatically, and hosts such as Vercel, Netlify and Cloudflare set them up for you. Paid organisation-validated (OV) and extended-validation (EV) certificates also check the business behind the site, but browsers no longer display that difference prominently, and the encryption is the same.
Lifetimes are shrinking by industry rule: public certificates have been capped at 200 days since March 2026, falling to 100 days in 2027 and 47 days in 2029. Renewing by hand stops being practical, so automatic renewal through the ACME protocol, which Let's Encrypt pioneered, is effectively required.
SSL/TLS certificates pricing
Free
Free from Let's Encrypt and most hosts. Paid certificates run from a few dollars a year through resellers to a few hundred dollars a year for OV or EV bought direct from a CA such as Sectigo.
SSL/TLS certificates pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Related terms
More in How the web works
Requests and responses