SSL Certificates Explained for Non-Technical Business Owners
No jargon, no acronyms. Here's what SSL certificates actually are, why your business needs one, and what happens if yours lapses — in plain English.
SSL isn't optional for online stores. Here's what Australian Shopify and WooCommerce store owners need to know about SSL certificates, PCI DSS compliance, and keeping their store secure.
By CertGuard Team
If you run an online store, SSL certificates are not optional — they're a legal and commercial requirement. But the specifics differ depending on whether you're on Shopify, WooCommerce, or another platform. Here's what Australian e-commerce operators actually need to know.
Stripe, PayPal, Afterpay, and every other payment gateway require a valid SSL certificate to process transactions. Their technical requirements explicitly state that any page in the payment flow — including checkout pages, order confirmation pages, and customer account pages — must be served over HTTPS.
Without a valid SSL certificate, your checkout will fail. Depending on the processor, it may fail silently (customers see a generic error) or visibly (the processor's checkout widget won't load).
The Payment Card Industry Data Security Standard (PCI DSS) applies to any business that accepts, processes, stores, or transmits card data — which includes your online store, even if you use a payment gateway.
PCI DSS Requirement 4.2 specifies that cardholder data must be protected with strong cryptography during transmission. In practice, this means HTTPS with a valid, properly configured SSL certificate on all pages in the payment flow.
Australian consumers are increasingly security-aware. Consumer research consistently shows that the large majority of online shoppers look for security indicators before entering payment details. A site without a valid SSL certificate — or with a mixed content warning — sees significant cart abandonment at checkout.
Shopify includes SSL certificates for all stores by default. Every Shopify store gets:
yourstore.myshopify.com addressyourstore.com.au)For most Shopify store owners, SSL is one less thing to worry about.
Custom domain configuration issues: If you recently connected a custom domain to your Shopify store, SSL provisioning can take up to 48 hours. During that window, your custom domain may show an SSL error. This is temporary and expected.
Certificate errors on subdomains: If you have a blog, a landing page subdomain, or other web properties outside your main Shopify store, those may have separate SSL certificates that Shopify doesn't manage. These need to be monitored separately.
Theme assets loading over HTTP: Older Shopify themes or third-party apps may reference assets over HTTP, creating mixed content warnings at checkout — which some payment processors flag as a security issue.
WooCommerce is a plugin for WordPress, which runs on self-managed hosting. This means you — or your developer — are responsible for SSL certificate management.
Unlike Shopify, WooCommerce doesn't manage your SSL certificate. Your hosting provider does.
Shared hosting (SiteGround, Crazy Domains, VentraIP): Usually includes a free Let's Encrypt certificate with auto-renewal. Usually reliable, but the renewal can fail silently if your domain's DNS configuration changes.
cPanel-based hosting: Auto-renewal via cPanel's SSL plugin. Renewal notifications go to the email address associated with the hosting account — which may not be actively monitored.
WP Engine / Kinsta / managed WordPress hosting: Typically includes SSL management as part of the service. More reliable than shared hosting.
VPS or dedicated server: Your team is fully responsible. SSL certificate management must be explicitly configured — either via Certbot for Let's Encrypt or manual renewal for commercial certificates.
WooCommerce stores that collect card data (rather than offloading entirely to Stripe or PayPal) face stricter PCI DSS requirements. Key SSL-related requirements:
Whether you're on Shopify or WooCommerce, if you operate multiple domains — a .com.au and a .com, a separate blog subdomain, a staging environment — those domains may have separate SSL certificates with separate expiry dates.
Managing all of these manually is error-prone. A monitoring tool that covers all your domains from a single dashboard is more reliable.
The uncomfortable truth is that most customers who hit an SSL error on your store won't contact you. They'll abandon their cart and buy from a competitor. You'll see it as an unexplained drop in conversion rate, not as the clear SSL issue it is.
Proactive monitoring means you find out before your customers do.
At checkout — the highest-intent moment in your customer's journey — an SSL error is catastrophic. The customer has already committed to buying. An unexpected security warning or broken padlock breaks that commitment immediately. Cart abandonment at this stage is rarely recovered.
For Shopify stores: monitor your custom domain(s) only — Shopify's managed domains are reliable, but your custom domain configuration can occasionally develop issues.
For WooCommerce stores: monitor your main domain, any subdomains, and your staging environment.
CertGuard's free tier covers 3 domains with 6-hour checks and email alerts — enough for most small stores. Pro ($9.99/month) covers 25 domains including all your subdomains and staging environments.
Set up monitoring for your store in 2 minutes — free for up to 3 domains.
CertGuard monitors your certificates automatically and alerts you before anything expires. Free for up to 3 domains.
Start Free →No jargon, no acronyms. Here's what SSL certificates actually are, why your business needs one, and what happens if yours lapses — in plain English.
PCI DSS has specific SSL and TLS requirements that apply to any Australian business accepting card payments online. Here's what you're required to do and how to stay compliant.
Relying solely on your developer to manage SSL certificates is a single point of failure that routinely costs businesses money. Here's how to build a resilient approach.