Rank #1 on Google Maps
India English
Kenya English
United Kingdom English
South Africa English
Nigeria English
United States English
United States Español
Indonesia English
Bangladesh English
Egypt العربية
Tanzania English
Ethiopia English
Uganda English
Congo - Kinshasa English
Ghana English
Côte d’Ivoire English
Zambia English
Cameroon English
Rwanda English
Germany Deutsch
France Français
Spain Català
Spain Español
Italy Italiano
Russia Русский
Japan English
Brazil Português
Brazil Português
Mexico Español
Philippines English
Pakistan English
Türkiye Türkçe
Vietnam English
Thailand English
South Korea English
Australia English
China 中文
Somalia English
Canada English
Canada Français
Netherlands Nederlands

Who Pays When Your SSL Certificate Fails: You, Your Host, or Your Developer?

  • Home
  • Website Guides
  • Who Pays When Your SSL Certificate Fails: You, Your Host, or Your Developer?

Buy domains, business emails, hosting, VPS and more: Get Started

Cheapest Domains in Kenya

Get your .Co.ke or .Com domain now for just 299.00 KES (Back to 1200 in 7 days)

.CO.KE for 299.00 KES | .COM for 999.00 KES

You are staring at a “Not Secure” warning, or worse, someone just asked you for money to “fix your SSL,” and you have no idea if that charge is legitimate.

Maybe your developer built the site two years ago, disappeared, and just resurfaced asking for a fee you were never told about. 

Maybe your host is pointing at your developer, and your developer is pointing back at your host. 

Nobody is giving you a straight answer, and your site is the one paying the price.

Here is the straight answer. 

Responsibility for your SSL certificate comes down to one question: who controls the part of your setup where the certificate lives.

It is not about who built your site, and it is not about who you paid first. 

Once you know where that control sits, the confusion clears up fast, and so does the question of who pays when your SSL certificate  fails. 

The Short Answer: It Depends on Who Controls the Setup, Not Who Built the Site

An SSL certificate has to be issued, installed, and renewed somewhere specific. 

That somewhere is either:

  • Your hosting account
  • Your domain’s DNS settings
  • A separate service your developer set up on your behalf, such as a proxy or CDN. 

Whoever controls that specific piece controls your certificate, and that is who is responsible when it fails.

That responsibility shift becomes more relevant given how the SSL industry has changed. A certificate is no longer a one-time install you forget about for a year. 

Validity periods have been shrinking steadily.

Every renewal cycle is another moment where responsibility can quietly slip through the cracks between you, your host, and whoever built your site. 

The fewer people involved in that chain, the fewer chances something gets missed.

Building a website and hosting a website are also two different jobs, and that distinction is at the center of most disputes like this one. 

A developer can build your entire site and never touch your SSL certificate again once it goes live, especially on hosts that manage certificates automatically. 

Or a developer can set up a separate layer, like a content delivery network, that puts them back in the loop every time a certificate needs attention. 

Knowing which situation you are genuinely in settles most of the confusion on its own.

When It Is On You, the Site Owner

If you personally hold the hosting account, meaning you have the login and you are the one paying the hosting bill directly. 

The responsibility for the SSL certificate usually sits with you. 

Most hosting providers today bundle a free SSL certificate with every plan and renew it automatically in the background. 

If that describes your setup, there should be no separate SSL bill from anyone. 

For example, if a site owner paid for the domain and hosting directly through a major provider. 

Then a developer who no longer had platform access demanded a separate fee for SSL hosting and maintenance. 

Free SSL certificates are standard on most hosting plans. 

So, a surprise recurring charge for something your host likely already includes is worth questioning hard before you pay it. 

Ask your host directly whether SSL is included in your plan. If it is, you already have your answer.

The age of the site is also worth weighing here. 

A site that has run for two years without a single SSL-related conversation is a strong signal. 

Whatever certificate came with the hosting has simply been renewing itself the entire time, quietly, in the background. 

A sudden demand after all that silence is far more consistent with someone trying to regain leverage than with a genuine service suddenly needing payment.

When It Is On Your Host

Shared hosting plans and most managed WordPress hosting typically include SSL as part of the package and handle the entire lifecycle for you. 

The certificate gets issued when your site goes live, and it renews itself before it expires. You never touch it, and you should never be billed extra for it.

This is the arrangement most small business owners assume they have, and for good reason.

It is genuinely how most modern hosting works. 

Certificate validity periods have also been shrinking industry-wide, dropping from a full year down to roughly 200 days as of March 2026, with further cuts planned through 2029. 

A host running proper automation absorbs all of that complexity for you. 

You only need to worry about your host if their automation breaks, which is rare but not impossible, or if you are on a legacy plan that still requires manual renewal.

A quick way to check this yourself: 

Log in to your hosting control panel and look for an SSL or security section. 

If you see an active certificate listed there with an automatic renewal date, your host is already handling this. 

But any separate SSL invoice from anyone else deserves a closer look before you pay it.

When It Is On Your Developer

Here is where things get  complicated, and where there is a lot of the confusion in the situation. 

For example, if your developer set up a separate layer in front of your hosting, most commonly a free tier of a service like Cloudflare, they created an additional point where your SSL certificate lives. 

Someone still has to manage that layer, and if your developer is the one who configured it, ongoing maintenance on it can be legitimate billable work.

The distinction comes down to whether that work was disclosed upfront. 

A developer charging for SSL maintenance on a service they set up, explained clearly, and continue to manage is doing normal, fair work. 

A developer who never mentions a recurring SSL fee for two years, then contacts you demanding payment or your site goes down, without providing your login credentials first, is using access as leverage rather than billing for a service. 

Free certificate management, even through Cloudflare, is not expensive or complex enough to justify that kind of pressure.

What Happens When a Certificate Fails

Knowing the mechanics helps you spot who dropped the ball. 

When your SSL certificate expires or breaks, browsers block the page entirely and show a warning like “Your connection is not private,” rather than simply loading the site without the padlock. 

Visitors see this before they see anything else on your page, and most will leave immediately rather than click through a security warning.

The specific error code tells you exactly what went wrong. An expired certificate throws a date-related error and points straight at a missed renewal.

A certificate that does not match your domain name. 

For instance, one issued only for the bare domain when visitors are typing in the www version, throws a different error entirely and points to a setup mistake, not a lapse.

A missing intermediate certificate, the file that links your certificate back to a trusted authority, produces yet another error. 

It usually means whoever installed the certificate did the job halfway.

None of these are billing disputes. They are technical problems with a specific, identifiable cause, and the fix always lives wherever that certificate was installed.

If your developer installed it manually and left, the fix is on whoever now controls that server. 

If your host manages it, the fix is theirs to make, quickly and without an extra invoice.

Warning SignWhat It Usually MeansWho Should Fix It
Certificate expired, date error shownA renewal was missedWhoever manages the hosting account or server where the certificate is installed
Hostname mismatch, for example www not coveredThe certificate was set up incorrectly at issuanceWhoever originally installed the certificate, since it needs reissuing
Missing intermediate certificateInstallation was done halfwayWhoever installed it manually, rather than an automated host
Sudden request for an unexplained SSL feeAccess is being used as leverage rather than a legitimate service being billedNobody, until the fee is explained and the underlying work is verified

How to Find Out Who Is Really Responsible for Your Domain

Before paying anyone or accusing anyone, run through this short checklist. It settles the question faster than any back-and-forth over email.

Check who owns your hosting account login

If you have direct access with your own username and password, you likely control your certificate too, and your host is responsible for keeping it valid.

Ask your host, in writing, if SSL is included in your current plan. Most hosts answer this within minutes over live chat, and the answer is usually yes.

Find out if a separate service sits in front of your hosting, such as a CDN or proxy

If your developer set one up, ask them directly what it does and whether it was ever mentioned in your original agreement.

Compare what you are being asked to pay against what the service genuinely costs

 A free Cloudflare plan, for example, costs nothing at the provider level, so a large recurring fee attached to it deserves a clear explanation of exactly what work that fee covers.

Request full credentials for everything connected to your site

  • Hosting control panel
  • DNS management
  • Any third-party service your developer configured. 

You are entitled to this regardless of what anyone tells you, since it is your domain and your business.

Look at your contract or original agreement with your developer, if one exists

Many disputes like this happen precisely because nothing was written down, which leaves both sides guessing about what was originally promised. 

If a fee was never mentioned anywhere in writing across two years of working together, that absence is itself useful information.

Get an SSL Setup Where Nobody Can Surprise You Later

The safest long-term fix for all of this is controlling your own SSL certificate directly, on a host that includes it as standard rather than treating it as a future upsell. 

Truehost issues SSL certificates for the Kenyan market with installation handled for you from the start, so there is no separate maintenance fee waiting to appear a year later.

A Domain Validated certificate through Truehost starts from KSh 750 a year and is typically issued within minutes.

If your business needs the extra trust signal of organization-level verification, Sectigo InstantSSL is available from KSh 4,968 a year. 

Every certificate includes:

  • 256-bit SHA-2 encryption 
  • A 7-day money-back guarantee
  • Support is available directly if you ever need help with installation, instead of relying on a developer you may lose contact with later.

This also solves the developer-access problem directly. 

If you ever part ways with whoever built your site, your SSL certificate stays tied to your own hosting account rather than to a proxy or service only your developer can access. 

When you hold that control yourself, nobody can hold your certificate or your site hostage over a fee you were never told about.

You can bring someone in to build, redesign, or maintain your site without ever handing over control of your hosting or your domain. 

Their job is to build the site. Yours stays owning it.

Fix This Before an Expired Certificate Costs You Customers

A lapsed SSL certificate does not politely wait for you to sort out who is responsible. 

The moment it expires, browsers block your site behind a warning, and most visitors will not risk clicking through it to reach a competitor’s site instead. 

Every day that the ownership question stays unresolved is another day your site is one missed renewal away from going dark.

Stop guessing who is supposed to fix it. 

Set up your SSL certificate directly through Truehost and keep your renewal, your keys, and your site’s uptime entirely in your own hands.

Truehost website builder home cta

Anne Purity
Author

Anne Purity

Conversion Focused SEO Copywriter Nairobi, Kenya

Anne is a conversion-focused SEO copywriter specializing in the web hosting and domain industry. She creates high-performing content that not only ranks on search engines but also turns visitors into customers. By combining keyword strategy with user intent and persuasive messaging, she helps businesses attract qualified traffic and drive meaningful growth.

View All Posts