We do not publish a price list for ssl & https setup, and this article explains why rather than dodging it. A headline number without a scope is a guess, and the gap between the guess and the invoice is where the argument happens.
What we can do is tell you exactly what moves the number.
The three things that move the price
How wide the scope is
The base of this work is:
- Scoped assessment and rules of engagement for SSL & HTTPS Setup
- Findings report ranked by severity with reproduction steps
- Remediation performed or specified for your developers
- Access, credential and permission review
- Backup and recovery verification
- Retest confirming each finding is genuinely closed
Every addition beyond that is quoted as a line, not folded in silently.
What state your current setup is in
Clean input is fast. The things that slow it down are usually invisible until someone looks:
- You have been hacked before and are not certain it is fully gone
- Nobody has reviewed who still has admin access in two years
- Backups run nightly and have never once been restored
- A customer or scanner reported a vulnerability you cannot assess
How many other systems have to keep working
Let's Encrypt, Cloudflare, HSTS — and anything of yours that touches them. Every integration that must survive the change is a thing to test, and testing is where honest estimates spend their time.
What moves the timeline
Usually 1–3 days. What extends it, in order of how often it actually happens: access arriving late, approvals sitting with one person who is travelling, and scope added mid-build. Only the third of those is about the work.
What you are not paying for
No discovery fee. No deposit to hold a slot. No account manager relaying messages between you and the person building it. No retainer attached to the build — if you want ongoing work afterwards, that is a separate decision made after you have seen how we work.
What we will not do
We will not quote a number before we understand the scope, and we will not guarantee a commercial outcome. Encrypt everything, redirect properly and stop mixed-content warnings is what the work delivers; what that produces in revenue depends on your market and your pricing as much as on us.
Want a real number for ssl & https setup? Send us what you have and you get a written scope and one fixed price, usually within a working day.
When it is not worth the money
- You need it faster than 1–3 days. We will not compress ssl & https setup into a weekend by skipping the testing, and an agency that agrees to is telling you which corner they plan to cut
- You are not committed to Let's Encrypt. Most of the value here comes from working properly inside Let's Encrypt, so if you are mid-way through deciding whether to move off it, decide first — otherwise you are paying us to improve something you are about to replace
- What you actually want is encrypt everything, redirect properly and stop mixed-content warnings guaranteed as an outcome. We will not sign that, because the result depends on your market, your pricing and your traffic as much as on the build. We guarantee the scope, the date and the quality of the work
- You want someone to take it away and report back monthly. This runs as a fixed piece of work with a written scope and a handover, not as a retainer — if you want a permanent security function, hiring is usually cheaper than us
Cost and timeline questions
What is SSL & HTTPS Setup?
SSL & HTTPS Setup is a security service from Livin Services. In one line: encrypt everything, redirect properly and stop mixed-content warnings. It's a defined piece of work with an agreed finish line, not an open-ended retainer, so you know what you're buying before you commit to it.
What is included in SSL & HTTPS Setup?
SSL & HTTPS Setup covers scoped assessment and rules of engagement for ssl & https setup, findings report ranked by severity with reproduction steps, remediation performed or specified for your developers, access, credential and permission review, backup and recovery verification, retest confirming each finding is genuinely closed, automatic renewal configured and tested, so nothing expires unnoticed, every mixed-content warning found and fixed, not only the ones on the homepage and redirects consolidated to one hop, because chains cost speed and search signals. All of that gets written down before we start, so you know exactly what's landing and what isn't. Anything outside the list gets quoted separately — we won't quietly absorb it and we won't quietly bill for it either.
What is not included in SSL & HTTPS Setup?
Anything not named in the written scope. In practice that usually means ongoing management after handover, content and copy you have not supplied, third-party licence and subscription costs, and work in other disciplines — those are separate services with their own scopes. We list exclusions explicitly rather than leaving them to be discovered halfway through.
How long does SSL & HTTPS Setup take?
A typical SSL & HTTPS Setup engagement runs 1–3 days from kickoff to handover. That covers discovery and scoping, build or implementation, review with your team, and a final QA pass. Larger or multi-market builds extend this and we say so during scoping rather than after.
Can SSL & HTTPS Setup be delivered faster than 1–3 days?
Sometimes, if the scope is reduced rather than the care taken. We will tell you which parts can be deferred to a second phase to hit a date. What we will not do is compress testing and review to make a deadline look achievable — that moves the cost from the timeline to the month after launch.
How is SSL & HTTPS Setup quoted?
One fixed price against a written scope. Not an hourly rate. What moves that number is how many templates, integrations and awkward edge cases are involved — not how long we happen to take, which is our problem to manage, not yours. There's no price list because a real quote depends on your situation. Tell us what you need and you'll get a written scope and a fixed figure back, with anything that could change it flagged upfront rather than appearing on an invoice later.
How the work runs, week by week
People ask for this more than anything else, and it is a fair question: you are about to hand over access to systems you depend on, and "we will keep you posted" is not an answer.
Stage 1 — We look at what you actually have
Before anything is quoted we go through your current Let's Encrypt setup and whatever else touches it. Half the time this changes the recommendation — the thing you asked for turns out not to be the thing that is costing you.
Stage 2 — The scope gets written down
Every line of SSL & HTTPS Setup that will be delivered, in plain English, with one fixed price and a date. Exclusions are listed as explicitly as inclusions, because the argument three weeks in is always about something nobody wrote down.
Stage 3 — Build, in the open
You see encrypt everything, redirect properly and stop mixed-content warnings take shape rather than being shown a finished thing at the end. If something we assumed turns out to be wrong, you hear it the day we find out.
Stage 4 — Tested against real conditions
Scoped assessment and rules of engagement for SSL & HTTPS Setup is checked on real devices and real data, not just on the machine it was built on. A thing that works only in ideal conditions is not finished.
Stage 5 — Handover, then it is yours
Documentation written for your team, every account already in your name, and a walkthrough. Typical end to end: 1–3 days. Nothing rolls over into a monthly fee you did not ask for.
None of that is a fixed calendar. It is an order. The dates go in the scope, and the honest note is that the order almost never changes while the dates sometimes do — usually for reasons on the client side rather than ours.
What we need from you, and when
The commonest cause of a slipped date on this kind of work is not the build. It is access and approvals arriving late. So this is written down as plainly as our side of the deal:
- Access to Let's Encrypt — Admin or collaborator access, created in your account so you can revoke it whenever you like. The single most common cause of a slipped date on SSL & HTTPS Setup is access arriving two weeks after kickoff
- One person who can decide — Not a committee. Someone who can approve a direction without escalating it. Where approvals need three people, we build that into the timeline rather than pretending it is free
- Whatever content the scope depends on — Copy, images, product data, brand assets — whichever apply. If you would rather we produced them, that is a separate scope and we will say so before you assume it is included
- An agreed definition of finished — We write down what "done" means for SSL & HTTPS Setup before starting, and both sides sign off on it. It is the cheapest thing you can do to avoid a dispute at the end
A note on access and approvals
Two practical notes. Send individual accounts rather than a shared login — individual access can be revoked per person at handover, and a shared password is the most common way a business quietly loses control of its own systems. And name one person who can approve decisions. Not a committee. A project with three approvers moves at the speed of the slowest one, and everybody ends up frustrated with the wrong party.
What we check before we call it finished
"Done" is the word that causes the most arguments in this industry, because it usually means something different to each side. Ours means all of the following are true, and you can hold us to the list:
- Every item in the SSL & HTTPS Setup scope ticked off against the written list, in front of you
- Tested on a real mid-range phone, not only on a desktop browser
- Checked against your existing Let's Encrypt setup so nothing that already worked has quietly broken
- Findings report ranked by severity with reproduction steps verified end to end rather than assumed
- Keyboard navigation and screen-reader labelling checked on anything interactive
- Handover documentation read back by someone who did not build it
Note what is in there and what is not. There is no line about you being happy — not because we do not care, but because a definition of done that depends on a feeling has no end. If something is wrong against the scope, we fix it. If something outside the scope turns out to matter, we quote it as a line rather than absorbing it quietly, because absorbed work is how a fixed price stops being fixed.
The tools, and who owns them
Let's Encrypt, Cloudflare, HSTS.
Where you already own something that does the job, we use it. Where we recommend adding something, the account gets created in your name, on your billing, with your team as administrators from the first day — not ours, and not a reseller's. This is not generosity. It is the single thing that determines whether you have a supplier or a dependency.
The same applies to everything we produce. Source files, configuration, documentation, credentials: yours, handed over as we go rather than held until a final invoice clears.
What we check before we call it finished
"Done" is the word that causes the most arguments in this industry, because it usually means something different to each side. Ours means all of the following are true, and you can hold us to the list:
- Every item in the SSL & HTTPS Setup scope ticked off against the written list, in front of you
- Tested on a real mid-range phone, not only on a desktop browser
- Checked against your existing Let's Encrypt setup so nothing that already worked has quietly broken
- Findings report ranked by severity with reproduction steps verified end to end rather than assumed
- Keyboard navigation and screen-reader labelling checked on anything interactive
- Handover documentation read back by someone who did not build it
Note what is in there and what is not. There is no line about you being happy — not because we do not care, but because a definition of done that depends on a feeling has no end. If something is wrong against the scope, we fix it. If something outside the scope turns out to matter, we quote it as a line rather than absorbing it quietly, because absorbed work is how a fixed price stops being fixed.
Where this discipline actually stands
Infrastructure work is invisible when it is right, which makes it easy to under-buy and easy to oversell. Our rule is that nothing counts as done until it has been tested in the failure case, not the happy one: a backup that has been restored, a firewall run in monitoring mode first, an alert that someone has agreed to act on. And it all lives in your accounts, because a supplier holding your infrastructure holds your business.
What we will not do
Worth being explicit, because these are the promises you will hear elsewhere:
- We will not guarantee a commercial outcome. Encrypt everything, redirect properly and stop mixed-content warnings is what the work delivers. What that turns into depends on your market, your pricing and your competitors as much as on us.
- We will not quote a number before understanding the scope. A price given in the first five minutes is a price with the risk padded in, and you pay for the padding.
- We will not take work we do not think will help. That has cost us enquiries and it will again.
- We will not hold your accounts, your data or your files as leverage.
- We will not add a tool where removing one would do. We say "remove this" fairly often, and it is always less to invoice for.
What is different once it is done
- SSL & HTTPS Setup is in place and documented, so your team can change it without calling us
- Scoped assessment and rules of engagement for SSL & HTTPS Setup delivered against a written list you can check line by line
- Every account and credential in your name, with nothing on our infrastructure
- A clear record of where you started, so the effect of the security work is measurable rather than a feeling
- One fixed price paid, with no retainer required to keep it working
That is the honest list. Not a transformation — a specific set of things that are true afterwards and were not true before, each one checkable.
How we would want to be compared
If you are getting other quotes, and you should, compare the scopes rather than the totals. Ask each supplier the same three things: what exactly is included and excluded, what does done mean, and who owns the accounts at the end. The answers separate suppliers far more reliably than a portfolio does.
And if someone else's scope covers the same ground for less, take it. We would rather you did that than start something on a number nobody is comfortable with.
