HTTPS is the encrypted version of the connection between a browser and a server, and an SSL certificate is what makes that encryption possible. Without it the browser shows the visitor a warning that the connection is not secure. With most hosting the certificate is free today and renews automatically every 3 months.
Without encryption everything a visitor sends travels as readable text - name, phone number, the message from a form, a password, card details. Anyone intercepting the traffic can read it.
With HTTPS that content is unreadable to an interceptor. It also confirms you are talking to the real server rather than someone impersonating your site.
This applies even to sites that "have nothing to protect". Even an ordinary contact form transmits personal data, and protecting it is not merely good practice but a legal obligation if you deal with the EU market.
The browser shows a warning. Chrome and Firefox mark the site as not secure, and on forms they can display an explicit warning before sending. Most visitors give up there.
Google has used HTTPS as a ranking signal since 2014. The signal is weak but present - and in practice it is impossible to find a competitive page without it.
Analytics become unreliable. When a visitor moves from an encrypted site to an unencrypted one, the referrer is lost, so the traffic shows as direct when it is not.
With most hosting the certificate is enabled from the control panel in a few clicks and renews itself. Charging HTTPS as a separate line has no justification today, except for special certificate types that verify company identity.
After enabling it, redirection must follow. All traffic from the unencrypted address has to go to the encrypted one, with a permanent redirect. Without that the site exists at two addresses and the signals split.
Then check that no page calls unencrypted resources - images, scripts or stylesheets from old addresses. The browser blocks or flags such mixed content even when the certificate itself is valid.
Open the site and confirm the padlock appears on every page, not only the home page. One sub-page with an unencrypted image breaks the indicator across the whole site.
In Search Console add the encrypted version as a separate property, because data does not carry over automatically. Submit a new sitemap with encrypted addresses.
Check internal links and canonical tags. If they still point at old addresses, every click passes through an unnecessary redirect, which slows loading.
Finally, make sure the old address no longer appears in the sitemap, in ads, or on profiles where you listed it previously.
If personal data passes through the site - a name, a phone number, an address, and especially card details - encryption is not a choice but an obligation. GDPR explicitly requires appropriate technical safeguards, and an unencrypted connection is certainly not one.
For companies in Bosnia working with EU clients this is a practical question, not a theoretical one. A single contact form collecting personal data is enough for the obligation to apply.
HTTPS is also one of the signals by which a site is ranked in search, though a weak one. Its real value lies in trust: a visitor who sees a warning about an insecure connection rarely continues, however good the offer is.
If you accept card payments, the card data itself is handled by the payment provider and never passes through your server. But the page where payment begins must be encrypted, or the process is cut short before it starts.
Last updated: 17 August 2026
Send the address and we will tell you where you stand - no obligation.
Send an enquiry