You are staring at a “Not Secure” warning, or worse, someone just asked you for money to “fix your SSL,” and you have no idea if that charge is legitimate.
Maybe your developer built the site two years ago, disappeared, and just resurfaced asking for a fee you were never told about.
Maybe your host is pointing at your developer, and your developer is pointing back at your host.
Nobody is giving you a straight answer, and your site is the one paying the price.
Here is the straight answer.
Responsibility for your SSL certificate comes down to one question: who controls the part of your setup where the certificate lives.
It is not about who built your site, and it is not about who you paid first.
Once you know where that control sits, the confusion clears up fast, and so does the question of who pays when your SSL certificate fails.
The Short Answer: It Depends on Who Controls the Setup, Not Who Built the Site
An SSL certificate has to be issued, installed, and renewed somewhere specific.
That somewhere is either:
- Your hosting account
- Your domain’s DNS settings
- A separate service your developer set up on your behalf, such as a proxy or CDN.
Whoever controls that specific piece controls your certificate, and that is who is responsible when it fails.
That responsibility shift becomes more relevant given how the SSL industry has changed. A certificate is no longer a one-time install you forget about for a year.
Validity periods have been shrinking steadily.
Every renewal cycle is another moment where responsibility can quietly slip through the cracks between you, your host, and whoever built your site.
The fewer people involved in that chain, the fewer chances something gets missed.
Building a website and hosting a website are also two different jobs, and that distinction is at the center of most disputes like this one.
A developer can build your entire site and never touch your SSL certificate again once it goes live, especially on hosts that manage certificates automatically.
Or a developer can set up a separate layer, like a content delivery network, that puts them back in the loop every time a certificate needs attention.
Knowing which situation you are genuinely in settles most of the confusion on its own.
When It Is On You, the Site Owner
If you personally hold the hosting account, meaning you have the login and you are the one paying the hosting bill directly.
The responsibility for the SSL certificate usually sits with you.
Most hosting providers today bundle a free SSL certificate with every plan and renew it automatically in the background.
If that describes your setup, there should be no separate SSL bill from anyone.
For example, if a site owner paid for the domain and hosting directly through a major provider.
Then a developer who no longer had platform access demanded a separate fee for SSL hosting and maintenance.
Free SSL certificates are standard on most hosting plans.
So, a surprise recurring charge for something your host likely already includes is worth questioning hard before you pay it.
Ask your host directly whether SSL is included in your plan. If it is, you already have your answer.
The age of the site is also worth weighing here.
A site that has run for two years without a single SSL-related conversation is a strong signal.
Whatever certificate came with the hosting has simply been renewing itself the entire time, quietly, in the background.
A sudden demand after all that silence is far more consistent with someone trying to regain leverage than with a genuine service suddenly needing payment.
When It Is On Your Host
Shared hosting plans and most managed WordPress hosting typically include SSL as part of the package and handle the entire lifecycle for you.
The certificate gets issued when your site goes live, and it renews itself before it expires. You never touch it, and you should never be billed extra for it.
This is the arrangement most small business owners assume they have, and for good reason.
It is genuinely how most modern hosting works.
Certificate validity periods have also been shrinking industry-wide, dropping from a full year down to roughly 200 days as of March 2026, with further cuts planned through 2029.
A host running proper automation absorbs all of that complexity for you.
You only need to worry about your host if their automation breaks, which is rare but not impossible, or if you are on a legacy plan that still requires manual renewal.
A quick way to check this yourself:
Log in to your hosting control panel and look for an SSL or security section.
If you see an active certificate listed there with an automatic renewal date, your host is already handling this.
But any separate SSL invoice from anyone else deserves a closer look before you pay it.
When It Is On Your Developer
Here is where things get complicated, and where there is a lot of the confusion in the situation.
For example, if your developer set up a separate layer in front of your hosting, most commonly a free tier of a service like Cloudflare, they created an additional point where your SSL certificate lives.
Someone still has to manage that layer, and if your developer is the one who configured it, ongoing maintenance on it can be legitimate billable work.
The distinction comes down to whether that work was disclosed upfront.
A developer charging for SSL maintenance on a service they set up, explained clearly, and continue to manage is doing normal, fair work.
A developer who never mentions a recurring SSL fee for two years, then contacts you demanding payment or your site goes down, without providing your login credentials first, is using access as leverage rather than billing for a service.
Free certificate management, even through Cloudflare, is not expensive or complex enough to justify that kind of pressure.
What Happens When a Certificate Fails
Knowing the mechanics helps you spot who dropped the ball.
When your SSL certificate expires or breaks, browsers block the page entirely and show a warning like “Your connection is not private,” rather than simply loading the site without the padlock.
Visitors see this before they see anything else on your page, and most will leave immediately rather than click through a security warning.
The specific error code tells you exactly what went wrong. An expired certificate throws a date-related error and points straight at a missed renewal.
A certificate that does not match your domain name.
For instance, one issued only for the bare domain when visitors are typing in the www version, throws a different error entirely and points to a setup mistake, not a lapse.
A missing intermediate certificate, the file that links your certificate back to a trusted authority, produces yet another error.
It usually means whoever installed the certificate did the job halfway.
None of these are billing disputes. They are technical problems with a specific, identifiable cause, and the fix always lives wherever that certificate was installed.
If your developer installed it manually and left, the fix is on whoever now controls that server.
If your host manages it, the fix is theirs to make, quickly and without an extra invoice.
| Warning Sign | What It Usually Means | Who Should Fix It |
| Certificate expired, date error shown | A renewal was missed | Whoever manages the hosting account or server where the certificate is installed |
| Hostname mismatch, for example www not covered | The certificate was set up incorrectly at issuance | Whoever originally installed the certificate, since it needs reissuing |
| Missing intermediate certificate | Installation was done halfway | Whoever installed it manually, rather than an automated host |
| Sudden request for an unexplained SSL fee | Access is being used as leverage rather than a legitimate service being billed | Nobody, until the fee is explained and the underlying work is verified |
How to Find Out Who Is Really Responsible for Your Domain
Before paying anyone or accusing anyone, run through this short checklist. It settles the question faster than any back-and-forth over email.
Check who owns your hosting account login
If you have direct access with your own username and password, you likely control your certificate too, and your host is responsible for keeping it valid.
Ask your host, in writing, if SSL is included in your current plan. Most hosts answer this within minutes over live chat, and the answer is usually yes.
Find out if a separate service sits in front of your hosting, such as a CDN or proxy
If your developer set one up, ask them directly what it does and whether it was ever mentioned in your original agreement.
Compare what you are being asked to pay against what the service genuinely costs
A free Cloudflare plan, for example, costs nothing at the provider level, so a large recurring fee attached to it deserves a clear explanation of exactly what work that fee covers.
Request full credentials for everything connected to your site
- Hosting control panel
- DNS management
- Any third-party service your developer configured.
You are entitled to this regardless of what anyone tells you, since it is your domain and your business.
Look at your contract or original agreement with your developer, if one exists
Many disputes like this happen precisely because nothing was written down, which leaves both sides guessing about what was originally promised.
If a fee was never mentioned anywhere in writing across two years of working together, that absence is itself useful information.
Get an SSL Setup Where Nobody Can Surprise You Later
The safest long-term fix for all of this is controlling your own SSL certificate directly, on a host that includes it as standard rather than treating it as a future upsell.
Truehost issues SSL certificates for the Kenyan market with installation handled for you from the start, so there is no separate maintenance fee waiting to appear a year later.
A Domain Validated certificate through Truehost starts from KSh 750 a year and is typically issued within minutes.
If your business needs the extra trust signal of organization-level verification, Sectigo InstantSSL is available from KSh 4,968 a year.
Every certificate includes:
- 256-bit SHA-2 encryption
- A 7-day money-back guarantee
- Support is available directly if you ever need help with installation, instead of relying on a developer you may lose contact with later.
This also solves the developer-access problem directly.
If you ever part ways with whoever built your site, your SSL certificate stays tied to your own hosting account rather than to a proxy or service only your developer can access.
When you hold that control yourself, nobody can hold your certificate or your site hostage over a fee you were never told about.
You can bring someone in to build, redesign, or maintain your site without ever handing over control of your hosting or your domain.
Their job is to build the site. Yours stays owning it.
Fix This Before an Expired Certificate Costs You Customers
A lapsed SSL certificate does not politely wait for you to sort out who is responsible.
The moment it expires, browsers block your site behind a warning, and most visitors will not risk clicking through it to reach a competitor’s site instead.
Every day that the ownership question stays unresolved is another day your site is one missed renewal away from going dark.
Stop guessing who is supposed to fix it.
Set up your SSL certificate directly through Truehost and keep your renewal, your keys, and your site’s uptime entirely in your own hands.
Domain SearchInstantly check and register your preferred domain name
Web Hosting
cPanel HostingHosting powered by cPanel (Most user friendly)
KE Domains
Reseller HostingStart your own hosting business without tech hustles
Windows HostingOptimized for Windows-based applications and sites.
Free Domain
Affiliate ProgramEarn commissions by referring customers to our platforms
Free HostingTest our SSD Hosting for free, for life (1GB storage)
Domain TransferMove your domain to us with zero downtime and full control
All DomainsBrowse and register domain extensions from around the world
.Com Domain
WhoisLook up domain ownership, expiry dates, and registrar information
VPS Hosting
Managed VPSNon techy? Opt for fully managed VPS server
Dedicated ServersEnjoy unmatched power and control with your own physical server.
SupportOur support guides cover everything you need to know about our services





