No. Every domain hosted with Flashcloud gets a free SSL certificate from Let's Encrypt automatically, usually within about 5 minutes of your domain pointing to our servers. It renews itself before it expires. For the vast majority of sites, that's the only certificate you'll ever need.
Paid certificates exist and still get sold, but they're solving problems most sites don't have. Here's how to tell if you're one of the exceptions.
What the free certificate actually gives you
Let's Encrypt issues Domain Validation (DV) certificates. DV confirms one thing: whoever requested the certificate controls the domain. That's it. It doesn't verify your business identity, and it doesn't need to, because the padlock icon in the browser bar has never shown identity information anyway. Modern browsers dropped the old "green bar with company name" Extended Validation (EV) display years ago. Visitors today just see a padlock, regardless of whether the certificate behind it is DV, OV (Organization Validation), or EV.
Encryption strength is identical across DV, OV, and EV certificates. A $0 DV cert and a $200/year EV cert protect the connection with the same TLS. The differences between certificate types are entirely about identity vetting paperwork, not security.
On our platform, this is automatic once DNS resolves to us. You don't request it, install it, or renew it. If a certificate isn't showing up, it's almost always a DNS propagation timing issue rather than anything about the certificate itself.
When a paid certificate might still make sense
There are a few real reasons businesses buy paid certificates, though they're narrower than the sales copy suggests:
- Extended Validation for brand trust in specific industries. Some banks and financial institutions still buy EV certificates as an internal compliance or brand-trust exercise, even though the visible browser UI difference is gone. If a compliance policy specifically requires EV, that's a real requirement, not a marketing one.
- Wildcard certificates for complex subdomain setups. A wildcard cert (
*.yourdomain.com) secures unlimited subdomains under one certificate. It's worth knowing wildcards exist as a category separate from DV/OV/EV. - Extended warranty or liability coverage. Paid certificate authorities sometimes bundle a warranty that pays out if the certificate itself fails and causes a breach. In practice these payouts are rare and the fine print is narrow. It's an insurance product more than a security feature.
- Certain enterprise or government procurement rules. Some contracts specify a named commercial CA. That's a contractual constraint, not a technical one.
If none of these apply to you, and for most small business and personal sites none of them do, a paid certificate buys you extra paperwork behind the scenes and nothing your visitors will notice.
Checking your certificate status
If you want to confirm your certificate is active and see its expiry, you don't need a paid tool. Run this from any terminal:
echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -dates
That prints notBefore and notAfter dates. You can also just check in a browser: click the padlock icon next to the address bar and view the certificate details.
If the certificate is missing entirely or shows as invalid, the cause is almost always one of: DNS not yet pointed at us, a mismatched www vs non-www configuration, or a cached browser warning from before the certificate was issued. Clearing your browser cache rules out the last one quickly.
If you're moving a domain from elsewhere
If you're transferring a domain to Flashcloud or pointing an existing domain at us for the first time, the certificate issuance happens automatically once our nameservers or DNS records are live, with no separate order or activation step. If you're not sure whether your DNS is fully pointed at us yet, that's worth checking first since it's the most common reason a certificate hasn't appeared.
When to contact support
If more than a few hours have passed since your domain started resolving to us and you still don't have a valid certificate, or if you have a specific compliance requirement that mandates a particular certificate type, open a ticket from the portal (Support → New ticket) or use live chat. A real person can look into your account and help you work through whether your situation is one of the genuine exceptions above.