Skip to main content
HostingSeller
Shop plans

Margin Brief

Lets encrypt vs paid SSL — You cannot bill for what is already included, so what can you bill for?

Somebody has told your client that a paid certificate is more secure, and you have to answer that without either lying or losing the sale.

Straight answer first

For almost every client site the free certificate included on every account is the correct answer, and the honest reseller position is to say so — the paid certificates worth stocking are the two that do jobs a free one cannot: one certificate covering every subdomain, and a checked company identity inside the certificate itself.

That is an uncomfortable answer if certificates were a line on your invoice. It is a much better position commercially than being the agency that charged a client annually for something their hosting already included, which is the sort of thing clients discover eventually and never forget.

Written by the Hosting Seller staff · Checked 24 August 2026

99.9%

Uptime commitment behind it

24/7

Cover behind your desk

Free

SSL on every site you host

NVMe

Disks under the accounts

Certificate upselling used to be easy money in this trade and is not any more, because free automated certificates are included on essentially every account you will ever create. Pretending otherwise is a short-term revenue plan with a long-term reputation cost.

The useful reframing is operational. The interesting question is no longer what a certificate costs, it is what happens across a hundred client sites when one fails to renew, and which two situations genuinely justify buying something.

What is already in the plan, and why that settles most sites

Free SSL is issued on every site you host and reissued before it lapses. Encryption strength is not the variable people imagine: a free domain-validated certificate and a paid domain-validated certificate secure a connection identically, and browsers treat them the same.

So for a brochure site, a portfolio, a small shop or a booking page, the answer is the included certificate, and the correct thing to tell a client asking about upgrades is that they do not need one.

Say it plainly and you gain something more valuable than the margin you gave up: a client who believes you when you do recommend spending money.

The two jobs a free certificate cannot do

The first is coverage. If your build pattern gives every client a subdomain — staging copies, client portals, per-tenant apps — a wildcard certificate written as *.yourdomain covers all of them from one certificate, is usually issued the same day, can be installed on as many servers as you like and reissued as often as you need.

The second is identity. Extended Validation puts your client's checked company name inside the certificate, backed by a relying-party warranty, and it takes one to three days because a human genuinely verifies the company. That matters to a small number of businesses — regulated ones, and those whose customers are being told to check.

A single-domain paid certificate sits in neither category, which is why it is not advertised here even though it can still be issued on request. Everything it does, the included certificate already does.

Renewal across a hundred accounts is the real question

One certificate expiring is an inconvenience. Forty expiring in a week because an automation broke is a business event, and every client discovers it at the same moment through a browser warning that says, in effect, that you are not trustworthy.

So the thing to check about any host is not the certificate they issue but the renewal behaviour: whether reissue happens automatically on every site you host, what occurs when a domain's delegation moves mid-renewal, and whether anything alerts you before a client's visitor does.

Build one habit around it. Keep a list of every client hostname you are responsible for, including the odd ones — the mail hostname, the staging subdomain, the legacy redirect nobody has touched since 2022 — and check it quarterly. That list is a five-minute job and it is the difference between noticing and being told.

Quoting certificates without looking like you are padding

Put the free certificate in the inclusions list of every tier, explicitly, so the client can see they are getting it. What is invisible cannot be valued, and what is unmentioned gets sold to them by somebody else.

When a paid certificate is genuinely warranted, quote it as a named requirement rather than a security upgrade: this client has fifty subdomains, or this client's compliance department has asked for a verified company identity. A reason a client can repeat to their own board is worth more than a persuasive paragraph.

And put the validation calendar in the project plan. A wildcard is usually same-day; extended validation takes one to three days and depends on the client returning paperwork, which historically they do slowly.

A padlock on a laptop screen standing in for a free SSL certificate

Included, and said out loud

Free SSL on every site you host, reissued automatically, on every tier including the cheapest. We would rather you told your clients that honestly than built a revenue line on something they already have.

The certificates we do stock are the two that earn their price: a wildcard covering every subdomain from one certificate, and an EV certificate carrying a checked company name for the clients who genuinely need one.

  • Free SSL on every client site
  • Reissued before it lapses
  • Wildcard for subdomain-heavy builds
  • EV when a client must prove identity

Why Hosting Seller

On every plan, as standard

Certificates on every tier

Free SSL on every site you host, including the cheapest package you sell, with reissue handled automatically.

One certificate, every subdomain

A wildcard written as *.yourdomain, usually issued the same day, for build patterns that spawn subdomains.

Install anywhere, reissue freely

The wildcard installs on as many servers as you like and reissues as often as you need, which suits an estate rather than a site.

Identity when it is required

EV certificates carrying a checked company name, with a relying-party warranty behind them, for clients who must demonstrate who they are.

Validation help included

Our team fits the certificate and walks the client through each validation step, so the paperwork is not your afternoon.

Honest inclusions

We say what is free, so you can put it in your own inclusions list and be believed when you recommend spending.

First Steps

From choosing to live

  1. 1

    List every hostname you are responsible for

    Client sites, staging subdomains, mail hostnames and forgotten redirects. You cannot monitor renewals for a list you have never written down.

  2. 2

    Answer the client's question honestly first

    Tell them the included certificate is right for their site. The sale you decline here buys credibility for the recommendation you make later.

  3. 3

    Only quote paid when the reason is nameable

    Subdomain coverage or verified identity. If you cannot name which one applies, the answer is the included certificate.

  4. 4

    Put validation time in the launch plan

    Same-day for a wildcard, one to three days for extended validation, plus however long the client takes to return paperwork. Never promise a launch date without that allowance.

In the Box

Packed with every plan

  • Free SSL issued on every site you host, on every tier
  • Automatic reissue before a certificate lapses
  • A wildcard option covering every subdomain from one certificate
  • Same-day issue in most cases on the wildcard
  • Installation on as many servers as you need, with unlimited reissues
  • EV certificates carrying a checked company name where it is required
  • Extended validation guided step by step by our team
  • 256-bit encryption on a 2048-bit key on the paid certificates
  • A single-domain certificate available on request, if a client insists
  • Free migration in, so inherited client sites arrive already covered

Across the Counter

Things people ask us all the time

Can I still sell certificates as a line item when free ones are included?

Only where the paid certificate does something the free one cannot, which means subdomain coverage or a verified company identity. Billing a client annually for a single-domain certificate their hosting already provides is the kind of thing that surfaces during a handover and costs far more than it earned.

What happens across a hundred client sites if renewal breaks?

Every affected visitor sees a browser warning at roughly the same time, and each client experiences it as your failure. Keep a written list of every hostname you are responsible for, check it quarterly, and treat renewal automation as something to verify rather than assume.

When does a wildcard genuinely save money?

When your build pattern creates subdomains — staging copies per client, per-tenant portals, regional splits. One certificate written as *.yourdomain covers all of them, installs on as many servers as you need and reissues freely, which is cheaper and considerably tidier than managing them one at a time.

A client's compliance team is asking for EV. Is that a real requirement?

Sometimes, and it is worth checking rather than assuming. Ask what specifically must be demonstrated. If the answer is a verified company identity inside the certificate, EV is the product and you should allow one to three days plus paperwork. If the answer is vague reassurance, the included certificate does the security job identically.

Read next

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Sell what is worth selling.

Free SSL on every client site you host, and the two paid certificates that genuinely do a different job.

See SSL Certificates plans