How to Get an SSL Certificate in 8 Simple Steps

We may receive a commission from our partners if you click on a link and purchase a product or service on their website. Learn more

Owain Wiliams headshot smiling at camera
Written By
Updated on August 4, 2023

Before your website can turn visitors into loyal readers, leads, or customers, it has to look professional, secure, and credible. With this goal in mind, one of the best ways to secure your website is to obtain an SSL (Secure Sockets Layer) certificate.

An SSL certificate is a piece of code on your web server that creates an encrypted connection, which keeps any data submitted by your website users safe and secure. In fact, if you don’t have an SSL certificate, popular web browsers will alert people who visit your website that the website is not secure.

In this article, we’ll discuss how to acquire an SSL certificate, keeping everything as simple and as jargon-free as possible – promise!

SSL certificates are issued by an entity known as a Certificate Authority (CA). The process of acquiring any website security certificate can be really easy, especially if you’re prepared in advance with the right information required by the CA. This information includes:

A Unique IP Address

Based on how SSL protocol works, each certificate you want to obtain will require a separate IP address. Otherwise, people using certain older devices and web browsers will not be able to use your website. You can use this tool to find out your website’s IP address.

An Accurate WHOIS Record

When you request an SSL certificate for a domain, the certificate authority will need to verify that you own the domain name. To do that, it will check the domain’s WHOIS record.

Domain Lookup tool by NameCheap
Domain Lookup tool by NameCheap

You can use a domain lookup tool to check your WHOIS record. If the information you find is obsolete, make sure to update it!

Business/Organization Validation

If you are requesting a high-assurance certificate, the certificate authority may check government databases to validate your business. In addition, the CA may also ask you to provide the government registration document associated with your business.

There are many different types of SSL certificates, and they can be categorized based on:

  • Validation level: Domain Validation, Organization Validation, and Extended Validation
  • Secured Domains: Single Domain, Wildcard, and Multi-Domain

Let’s look at a brief overview of each type:

Domain Validation: This is the cheapest and lowest level of validation, which just makes sure that your company has control over the domain. It’s best suited for small businesses that generally don’t exchange any information with users.

Organization Validation: This is the medium level of validation. It checks not only domain ownership, but also details of the organization, such as name and location. This level is ideal for business websites with forms and lead-capturing features.

Extended Validation: This is the most expensive and thorough level of validation. As well as domain ownership and organization details, it verifies the company’s physical location and legal existence. It’s a good fit for websites that handle sensitive information, such as financial transactions.

Single Domain: Provides protection for a single subdomain. An SSL certificate purchased for johndoe.com, for instance, cannot be used for subdomains, such as blog.johndoe.com

Wildcard: Offers protection for unlimited subdomains of a single domain. For example, an SSL certificate purchased for johndoe.com can be applied to any subdomains, such as blog.johndoe.com or shop.johndoe.com.

Multi-Domain: Provides protection for up to 100 domains with a single SSL certificate. An SSL certificate purchased for johndoe.com, for example, can be applied to other domains, such as janedoe.com.

Which type of SSL is right for you will depend on several factors and your unique business position.

For example, a single page website for a local coffee shop that’s used to communicate simple information such as their location and opening times would likely only require Domain Validation. This is especially true if they aren’t collecting or using any visitor data or information.

On the other hand, an ecommerce website that requires visitors to input information such as personal addresses and credit card details, would need to demonstrate a higher level of security and trust with an Extended Validation. In contrast to the last example, an ecommerce store may collect customer data for use in marketing campaigns, making it better suited for Extended Validation.

Whether your website is best suited to a single, wildcard or multi-domain SSL will depend on its structure. For example, the single page cafe website wouldn’t need anything beyond a single domain. On the other hand, the ecommerce store is likely to have multiple product pages, category pages, and blog – making a wildcard or multi-domain SSL much more suitable.

It’s also important to consider cost. SSL certificate costs vary depending on the type you choose, so make sure you can afford the SSL certificate you want to install.

A Certificate Authority (CA) is an entity that issues SSL certificates. There are dozens of CAs operating around the world, but only a few of them own the majority of the global SSL market share. These bigger players include GoDaddy and GlobalSign.

Pie chart showing CA market share
Pie chart showing CA market share

Image Source: About SSL

You want to pick a reputable CA that can provide the type of SSL certificate you need, while also aligning with your budget and business objectives.

Acertificate signing request(CSR) is a file to be generated on your web server before you request an SSL certificate from a CA. The CA will then use the information in this file to issue your SSL certificate.

The process of generating a CSR depends on the web server and hosting that your website is using. We’d recommend contacting your web host to find out if they have instructions in their knowledge base about generating a CSR.

Now that you’ve generated a CSR, the next step is to head over to the website of the CA you picked, and purchase the type of SSL certificate you’ll need.

After completing the checkout process, the CA will ask you to submit the CSR file you generated in the previous step.

Depending on the type of SSL certificate you purchase, the CA can take anywhere between a couple hours and a few days to validate your details, and issue your site’s SSL certificate.

For example, obtaining a domain validation certificate typically takes a couple of minutes, while an extended validation can take a few days.

Once the CA has processed your SSL certificate request, it will send you an email allowing you to access your SSL certificate. Alternatively, you can download it from the user account you created when purchasing the certificate.

The process of installing an SSL certificate depends on the OS (operating system) of the web server on which your site is hosted. Contact your web host for more info about this, or check if it has provided any online instructions on how to install your SSL certificate.

Great, so you now have your SSL certificate installed. The hard work is done. But it isn’t over.

Best practice dictates that website owners should test their SSL certificate and create a schedule for maintenance. This will help provide you with peace of mind and ensure that your certificate doesn’t go wrong or run out without you knowing.

The first step is test your SSL. This can be done using SSL verification tools such as Digicert or SSL Shopper. These tools will provide you with essential information such as whether all the pages on your website are loading securely.

Next, you should create a schedule (and set a reminder) to regularly monitor your SSL certificate expiration and renewal dates. Typically an SSL will last 13 months, but you need to check the specific details of your certificate to ensure you do not miss the expiry.

It is best practice to renew your SSL certificate and update its installation on your website or server before it expires. This can save a lot of hassle and ensure there is no period where your site does not have an SSL.

Yes, you can. Most of the top hosting providers, including Bluehost, HostGator, and InMotion, provide you with a free SSL certificate as part of your hosting package.

Case in point: Bluehost. When you sign up for a hosting account with Bluehost, you’ll find a Let’s Encrypt SSL automatically included in your package. To activate your SSL certificate, simply:

  1. Go to your Bluehost control panel
  2. Navigate to My Sites > Manage Site
Site option in Bluehost Control Panel
Site option in Bluehost Control Panel

3. Under the Security tab, toggle on the SSL certificate switch

Switching on SSL certificate in Bluehost Security tab
Switching on SSL certificate in Bluehost Security tab

That’s all it takes! Once you’ve turned on the SSL switch, it can take a few hours to activate, so don’t worry if it doesn’t happen instantly.Find Out More

As we discussed, obtaining an SSL certificate involves the following steps:

  1. Ensure you have the correct website information
  2. Decide the type of SSL certificate you need
  3. Choose a Certificate Authority (CA)
  4. Generate a Certificate Signing Request (CSR)
  5. Submit the CSR to a Certificate Authority (CA)
  6. Await validation by the CA
  7. Install your SSL certificate
  8. Test and maintain your SSL certificate

An SSL certificate goes a long way towards providing a great user experience, boosting SEO, and helping your business align with industry standards. So go ahead and put these steps into action – and good luck!

Written By

Owain Wiliams headshot smiling at camera

I’m a freelance content writer at Website Builder Expert. I’m a bit of a business and marketing nerd and love sharing my knowledge and experience to help others achieve their business goals.

From complex engineering and brewing to international events and brand design agencies, I’ve worked in marketing roles for well over 10 years now. During this time I have set up my own content marketing consultancy and launched my own ecommerce business on Shopify.

Throughout my career, I have been lucky enough to contribute to the marketing space in many ways. This has ranged from speaking at top marketing events and contributing to industry whitepapers, to writing content for leading websites such as MarketingProfs, Small Business Bonfire, Digital Doughnut, Neal Schaffer, and Social Pros.

I have also written for top brands including RedBull, Nestle, and Dr. Jackson.

You can find me on LinkedIn here.Owain started his marketing career as an apprentice for an international engineering consultancy – this is where he developed a skill for turning complex (and occasionally dull) information into exciting, easy-to-understand, and actionable content. Since then he has gained extensive experience in various business leadership and marketing roles in several areas ranging from brand design to ecommerce.

In 2017, Owain decided to pursue his passion for content and helping businesses grow. Roughly 12 months later he launched MAKE IT MANA – his content strategy and writing business. Since then Owain has managed several large-scale content projects and researched and written hundreds (possibly thousands) of pieces of content.

Specializing in topics surrounding business and marketing, Owain has worked with many marketing agencies, business software providers, and media sites to help them create content that is both high-value and actionable. He has also worked with several top B2C brands.

Owain was offered the opportunity to work with Website Builder Expert in 2019 and jumped at the chance – sharing in their vision to bring well-researched, high-quality, easy-to-understand, and actionable content to businesses that want to grow online. Since then he has written several of their most popular guides and articles, as well as consistently contributed to the research and briefing process for other pieces of content across the site.

Meticulous in his approach to research and writing, Owain delivers quality content on a huge range of topics for Website Builder Expert. However, you will notice that his passion for key marketing areas such as influencer marketing, social media, and content truly shines through.

More about

10 comments

Your email address will not be published. Required fields are marked *

  • vorbelutrioperbir

    Just wish to say your article is as astounding. The clarity for your submit is simply great and that i could suppose you are knowledgeable in this subject. Fine with your permission let me to grasp your feed to stay updated with impending post. Thank you 1,000,000 and please carry on the gratifying work.

  • Magis TV

    Great post! I really appreciate the clear step-by-step instructions. SSL certificates can be confusing, but your guide makes it seem so manageable. I feel more confident tackling this now. Thanks for sharing!

  • 91 club

    Great guide! I appreciate the clear breakdown of the steps. It made the process of getting my SSL certificate much less intimidating. Thanks for sharing!

  • 🗝 Transfer to you. GO >>> graph.org/BALANCE-36824-US-DOLLARS-04-24?hs=3ac5af55095875f081276fbda7f293f2&

    rz6oiv

  • 📊 Top Up 236,538 $. GET - graph.org/BALANCE-3682444-USD-04-21-2?hs=3ac5af55095875f081276fbda7f293f2& 📊

    c67i5a

  • Carolynn Heinzerling

    STOP EVERYTHING YOU ARE DOING AND READ THIS! Guys, Berlusconimarket.com has saved my skin! Seriously, the quality is chef's kiss. I ordered a few grams of fentanyl I've needed for ages, and they arrived faster than I thought possible, all packaged perfectly. If you need reliable fentanyl that actually work and are sourced ethically (trusted vendors!), run to this site NOW. You will not regret it!"

  • Tommy

    so if im running a local installation of wordpress through xampp a ssl isn't somethining i need on the site to prevent hackers from gaining entry into my system

    1 reply

    • Annie Angus
      Annie Angus

      Hi Tommy,
      Thanks for commenting. I'd recommend an SSL for every website, since it'll help your visitors feel secure. There are a few different types to choose from, each with different costs. Check out our guide on the cost of different SSL certificates to find out which is best suited to you.
      Have a great day,
      Annie

  • Lethabo

    I want to buy security certificate

    1 reply

    • Jordan Glover
      Jordan Glover

      Hi Lethabo,
      Thanks for your comment. SSL certificates are sold by CAs (Certificate Authorities). Popular CAs include GoDaddy or GlobalSign, and you can buy an SSL directly through their websites.
      I hope this helps!
      Jordan

  • Sabby

    This is one of the best website pages I came across to know about how SSL work in actuality. I am working in IT but did not know how SSL work starting from scratch however I knew the process of generating CSR, deep information about the types of SSL certificates a person can purchase and the type of domains it can apply on. I know how validation works though. Now, I know how things work in reality. Thanks for this amazing information on this website.

    1 reply

    • Jordan Glover
      Jordan Glover

      Hi Sabby,
      Thanks so much for your comment. We're so glad we could help!
      Thanks,
      Jordan

  • Çarl

    I would like to set up a ssl account if possible.
    Because everytime I use it my debit card gets hacked then the bk turns off my card then it's back to the bk for another #. Plus I have been asked to leave 1 bk because I got hacked to many times. All from ordering from my pH. I don't have a PayPal account.

    1 reply

    • Samuel Jagger
      Samuel Jagger

      Hi Çarl! Sorry to hear about your troubles. If hacking is the issue, we recommend going to a reputable source to buy your ssl certificate. The best source, for us, would be GoDaddy, who is a leader in both domain names and website building. As an established company in the website building space, they should stop your hacking woes. If you still encounter problems, you may want to speak to an IT specialist as you may have some ind of virus. Hope this helps! All the bets - Sam

  • Anne

    Thanks for this informative article. I have a question before starting the process of applying for an SSL certificate. My "insecure" site is the target of a redirect from a secure site. I would like the target site to be the URL that shows up in the search bar. My hosting company says they cannot provide an SSL for the target site even though I pay to own that domain. Are they just jerking me around? Why would I have to pay for a separate certificate for the same website just to have a different URL show up? Can I pay to upgrade the free SSL certificate that applies to the original URL so that it covers the redirect?

    1 reply

    • Lucy Carney
      Lucy Carney

      Hi Anne,
      Thanks so much for your comment! I'm sorry to hear you're having trouble with securing an SSL for your redirect. I would recommend either buying another SSL for your target site, or upgrading your current SSL so that it covers multiple domains (called a Multi Domain SSL). Domains and SSL certificates are separate, so your host may not automatically provide a free SSL for the target site depending on their policies, even though you pay for the domain. Hopefully you can upgrade your current SSL as a simple solution!
      Hope this helps and best of luck getting it sorted,
      Lucy