🇦🇺 100% Australian owned, operated & hosted.

Do I Need to Buy an SSL Certificate in Australia?

There is a specific moment this question arrives. A renewal notice lands from a registrar or a reseller, and you are looking at an invoice for something you half suspect your hosting already provides for nothing.

Usually it does. The useful question is not whether free certificates are legitimate, because they are and they have been for years. It is whether anything about your particular situation genuinely calls for the paid version.

Short answer: Most Australian businesses do not need to buy an SSL certificate. Free domain validated certificates are issued and renewed automatically by most hosts and encrypt identically to paid ones. Paying is justified in narrow cases: when a policy requires vetted organisation details, when you need a warranty for a compliance file, or when one certificate must cover many unrelated domains.

What do you already get without paying?

On most modern hosting, a domain validated certificate that is issued automatically, installed for you and renewed on a schedule without anyone touching it. It produces the same padlock, the same encryption strength and the same browser trust as a certificate with a price tag. GoodHost cPanel plans include one, with automatic renewal.

The mechanism explains why the price fell to zero. Domain validation is fully automated: the authority checks you control the domain by looking for a file or a DNS record, and issues on that basis. No human in the loop means no labour cost to recover. Organisation and extended validation still involve a person reading documents, which is why those still cost money.

So “free” is not a stripped down tier here. It is the same product without the manual checking step. The background on what the file actually proves is in the guide to what an SSL certificate is and does.

Is a paid certificate more secure?

No, and this is the claim to be most sceptical about. Encryption strength is determined by the protocol version and cipher suite negotiated between browser and server, not by the certificate’s price. A free certificate on TLS 1.3 protects a connection better than an expensive one on an old protocol version.

If you want to improve the security of the connection itself, the levers are on the server: current protocol versions, a complete certificate chain, HTTP redirected to HTTPS. We go through those in the piece on what actually separates SSL from TLS. None of them are purchased.

When is buying a certificate actually justified?

Three situations, realistically. A contract or compliance document that specifically names organisation or extended validation. A need for the warranty that comes attached to commercial certificates. Or a technical requirement, such as one certificate covering many unrelated domains, that free automated issuance does not handle neatly.

Situation Free is fine Consider paying
Brochure site, blog, small business site Yes No reason to
Online store using a hosted payment gateway Yes Only if a contract names OV or EV
Many subdomains under one domain Usually, via per subdomain issuance or a free wildcard If your host cannot automate wildcards
Dozens of unrelated domains on one server Workable but fiddly A multi-domain certificate can be simpler to manage
Tender or insurance requirement naming a warranty No Yes, buy what the document specifies

Most of the genuine reasons are administrative rather than technical. That is not a criticism of paid certificates; managing a hundred domains by hand is a real problem and a multi-domain certificate is a real answer to it. It is just a different problem from the one most small businesses have.

What should you check before you pay for one?

Find out what your hosting already issues, and whether the renewal is automatic. Then read whichever document prompted the purchase and see if it actually names a validation level, or whether someone simply assumed a paid certificate was required. Those two checks resolve most of these invoices without spending anything.

  • Does your host issue and auto-renew a free certificate, and does it cover both example.com and www.example.com?
  • Does the compliance document name organisation validation, extended validation or a warranty amount, or does it just say “SSL”?
  • How many distinct domains and subdomains actually need covering, and can your control panel issue for each of them?
  • Who installs and renews the paid certificate, and what happens to that job when the person who bought it leaves?

That last one causes more outages than it should. A paid certificate with a long validity period is a diary entry nobody inherits, and an expired certificate takes a site down as effectively as a server fault. If you are chasing that symptom right now, start with why a site stops loading.

What does a certificate cost in Australia?

Free for domain validated certificates through your host. Paid certificates vary widely by authority, validation level and term, and any figure quoted here would be out of date quickly, so check the current price with the authority or reseller directly. GoodHost does not publish a separate SSL price because cPanel plans include a free certificate.

Be careful comparing renewal prices rather than first year prices. Introductory pricing on commercial certificates is common, and the number that matters is what you pay in year two and beyond, on a certificate somebody has to remember to reinstall. The GoodHost security page sets out what is included on hosting rather than sold separately.

What else should the money go on instead?

Backups you have tested, updates that actually get applied, and access control on admin logins. Those three prevent the incidents that damage a small business. A certificate protects data moving between browser and server; it does nothing about an outdated plugin or a shared admin password, which is how most sites are compromised.

Work through the security checklist for Australian businesses and see how many items are free but unticked. The rest of the security and backups section covers backups, restores and what to do if something has already gone wrong.

Frequently asked questions

Does an Australian business need an Australian certificate authority?

No. Certificate authorities are trusted globally by browser and operating system vendors, not per country, and there is no Australian requirement to use a local one. What matters is that the authority is in the trust stores your visitors use. Buying locally can simplify invoicing and support in your timezone, which is a business reason rather than a technical one.

Do free SSL certificates work with online payments?

Yes. Payment gateways care about the encryption and the protocol version, not about who issued the certificate or what it cost. A domain validated certificate on TLS 1.2 or above satisfies the usual requirements. If a compliance document specifically names organisation validation, that is a policy decision from that party rather than a technical limitation of free certificates.

Will a paid certificate improve my Google ranking?

No. Search engines look for HTTPS being present and correctly configured. They do not distinguish between a free domain validated certificate and an expensive extended validation one. Anyone selling a certificate on the promise of better rankings is describing something search engines have never said they do.

Can I get a refund if I bought a certificate I do not need?

Often, within a short window after purchase, though the terms are set by the certificate authority or reseller rather than by your host. Check the refund period on the order before you cancel, and do not revoke the certificate until you have a working replacement installed, or you will take the site down while you sort out the paperwork.

What happens to my certificate when I change hosts?

A free certificate does not move; the new host issues its own once the domain points at the new server. A paid certificate can be transferred if you have the private key and certificate files, but many people simply reissue instead. Either way, make sure a valid certificate exists on the new server before you switch DNS.

Before that renewal invoice falls due, log into your control panel and check whether a free certificate is already installed and renewing on its own. If it is, and no contract names a validation level, you can let the paid one lapse. The GoodHost security page lists what comes with a cPanel account, including the auto-renewed certificate, so you can see exactly what you would be paying twice for.

Got questions? Call us: 1800 931 000 Mon–Fri