The verdict in three sentences
HTTPS is non-negotiable in 2026: without it, the browser shows "Not secure" and Google demotes the page. Beyond the certificate, it's the security headers — HSTS, CSP, X-Frame-Options — that block data theft and form hijacking. The certificate is free and configuring headers takes a few hours for an immediate trust gain.
HTTPS: the bare minimum
HTTPS encrypts exchanges between visitor and server: passwords, contact details, payments. Without it, this data travels in clear text and can be intercepted on a public Wi-Fi network. For years, browsers have explicitly flagged HTTP pages as "Not secure", a signal that drives visitors away at the most sensitive moment: entering a form or a payment.
As an order of magnitude, a large share of West African SME showcase sites still runs with no security headers configured beyond bare HTTPS. This is an avoidable risk at near-zero cost.
The security headers that matter
| Header | Role | Priority | Effort |
|---|---|---|---|
| HTTPS/TLS | Encrypts all traffic | Vital | Low (free certificate) |
| HSTS | Forces HTTPS, blocks downgrade | High | Low |
| Content-Security-Policy (CSP) | Blocks injected scripts (XSS) | High | Medium |
| X-Frame-Options | Prevents clickjacking | Medium | Low |
| X-Content-Type-Options | Blocks MIME sniffing | Medium | Low |
| Referrer-Policy | Limits URL leaks | Low | Low |
| Permissions-Policy | Restricts camera/mic/geoloc | Low | Low |
Certificate cost and business impact
| SSL option | Annual cost | Use case | Trust |
|---|---|---|---|
| Let's Encrypt (free) | 0 FCFA | Showcase, SME e-commerce | High |
| Paid DV SSL | 15,000–40,000 FCFA | Managed alternative | High |
| OV/EV SSL (enterprise) | 60,000–250,000 FCFA | Bank, institutional | Maximal |
| None (HTTP) | 0 FCFA | To be banned | None |
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
A "Not secure" warning on a payment page can make 20 to 30 % of visitors abandon. For e-commerce, that's revenue lost directly.
Mini case study
Fatou launches an online shop in Thiès. Her first site ran on HTTP: out of 100 people reaching payment, ~25 abandoned on seeing "Not secure". After migrating to HTTPS (free certificate) + enabling HSTS and a restrictive CSP, the payment abandon rate drops to ~8 %. On 100 payments initiated at 20,000 FCFA, that recovers ~340,000 FCFA in sales, for a setup cost of a few hours of work.
FAQ
Is the SSL certificate expensive? No. Let's Encrypt provides free certificates, renewed automatically. The cost is zero; only configuration requires a little technical time.
What is CSP concretely? The Content-Security-Policy is a header telling the browser which scripts and resources are allowed. Well-tuned, it blocks injected scripts (XSS attacks), the most common web vulnerability.
Is HTTPS enough to secure my site? No. HTTPS encrypts transport, but you also need headers (HSTS, CSP), forms protected against spam and injection, and regular CMS updates.
Does Google penalize insecure sites? Yes. HTTPS is a ranking factor and HTTP pages are flagged "Not secure", which reduces clicks and conversions even if the page stays indexed.
Let's talk about your project. We audit and secure your site — HTTPS, HSTS, CSP and form protection — to inspire trust from the first visit. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

