From October 2026, Google Chrome will start warning visitors before they open any website that isn’t running on HTTPS — the padlocked, encrypted version of a web address. If your Melbourne business website is still sitting on plain HTTP, or has HTTPS installed but not properly enforced, that change is about to matter a lot more than a small ranking tweak. Here’s what HTTPS actually does for SEO, what’s changing in 2026, and how to check whether your site is genuinely secure or just appears to be.
Does HTTPS actually affect your Google rankings?
Yes, but modestly. Google confirmed HTTPS as a ranking signal back in 2014, and it remains one today — but it has always been what Google itself describes as closer to a tie-breaker than a major ranking driver. If two pages are otherwise similar in quality and relevance, the secure one gets a slight edge. On its own, switching to HTTPS won’t move a page from position 20 to position 3. So if HTTPS is only a “lightweight” ranking factor, why does it deserve a full article? Because the ranking impact was never really the main story — the trust and conversion impact is, and that’s about to become unavoidable.
It’s also worth being clear about what HTTPS does not do. It won’t fix thin content, slow load times or a confusing site structure, and it won’t outrank a genuinely more relevant competitor page. Think of it as a baseline requirement rather than a growth lever — something every page on a professional Melbourne business website should simply have, in the same way a shopfront should have a working front door. The businesses that get caught out are rarely the ones who never heard of HTTPS; they’re the ones who installed it years ago, assumed the job was done, and never checked it again as their site grew new pages, plugins and subdomains.
Why it matters far more in 2026 than the ranking boost suggests
Google announced on its official Security Blog that Chrome is moving to “HTTPS by default” in two stages. From April 2026, Chrome 147 started warning users enrolled in Enhanced Safe Browsing — a group of more than a billion people — before they load an insecure HTTP page. From October 2026, Chrome 154 extends that warning to everyone, by default, worldwide.
| Date | Chrome version | Who sees the warning |
|---|---|---|
| April 2026 | Chrome 147 | Enhanced Safe Browsing users (1 billion+ people) |
| October 2026 | Chrome 154 | All Chrome users globally, by default |
In practice, this means any Melbourne business still running an HTTP page — even a single old landing page that never got migrated — will soon show visitors an active warning before the page even loads, not just a missing padlock icon they might not notice. Full detail is available directly from the Google Security Blog’s announcement on HTTPS by default.
What happens when a visitor sees “Not Secure”
This is where the real cost sits. Once Chrome flags a page as “Not Secure,” a large share of visitors simply leave — around 64% close the page immediately rather than proceed. For a Melbourne business relying on its website for enquiries, quote requests or online sales, that’s not a ranking problem, it’s a lost-customer problem, and it happens before your content, your offer or your reviews get a chance to do their job.
Not sure if your whole site is properly secured? Get your free SEO audit worth $1,200 and we’ll check HTTPS enforcement along with everything else.
Common mistakes that undermine HTTPS even when you have a certificate
Plenty of Melbourne business sites technically “have HTTPS” and are still exposed to the coming changes because the certificate isn’t doing its full job. The most common issues we see are:
- No sitewide redirect — the HTTP version of the site still loads instead of automatically forwarding to HTTPS.
- Mixed content — the page itself is secure, but it loads images, scripts or fonts from insecure HTTP sources, which can still trigger warnings.
- Missing HSTS — a setting that tells browsers to always use the secure version of your site, even if someone types the address without “https://”.
- Forgotten subdomains — a blog, booking page or staging subdomain that never got its own certificate.
- Expired certificates — free certificates typically renew automatically, but manually issued ones can lapse unnoticed.
The Australian Government’s small business cyber security guide lists a properly enforced HTTPS setup — not just an issued certificate — as one of the first controls worth getting right, alongside strong passwords and regular updates.
Most of these issues are invisible to a business owner clicking around their own site, because a browser that’s already loaded a page once often caches enough of it to hide the warning on repeat visits. The people who see the problem clearly are new visitors, which for a Melbourne business chasing new enquiries is exactly the audience you can least afford to lose.
What it costs and how long it takes to fix in 2026
The good news is that fixing this is usually cheap and fast. Most Australian hosting providers now bundle a free SSL certificate through Let’s Encrypt, so getting a certificate issued rarely costs anything extra. The work — and where the real cost sits — is in configuration: forcing the redirect, fixing mixed-content warnings, enabling HSTS and checking every subdomain. For a typical small business WordPress site, that’s usually a half-day to one-day job for a developer, and it’s exactly the kind of item a proper technical SEO audit should catch before Chrome’s October 2026 rollout does it for you, publicly, in front of your visitors. Larger sites with multiple subdomains, older custom-built pages or a mix of hosting providers from different eras of the business can take longer simply because there are more places for a certificate to have been missed, rather than because the fix itself is complicated.
Want us to run this check for you? Claim your free audit before Chrome’s October 2026 warnings go live sitewide.
A practical HTTPS health check you can run today
You don’t need to wait for an agency to get a first read on where you stand:
- Type your domain into a browser without “https://” and confirm it redirects automatically to the secure version.
- Open your browser’s developer console on your homepage and look for any “mixed content” warnings.
- Check every subdomain you use — blog, shop, booking system — for its own valid certificate.
- Search your site in Chrome’s security settings or a free SSL checker tool to confirm your certificate’s expiry date.
How this fits into your wider technical SEO
HTTPS is one piece of a bigger technical picture. We’ve covered the full scope of technical SEO — from indexing through to Core Web Vitals — in our practical guide to technical SEO for Melbourne businesses, and if Google isn’t finding your pages properly in the first place, our guide on fixing crawl errors before they hurt your rankings is a good next read. Our full range of SEO services covers all of this as part of an ongoing technical health check, not a one-off fix.
Frequently asked questions
Will my rankings drop if I don’t fix HTTPS before October 2026?
Not directly from the ranking signal itself — that part hasn’t changed. What will hurt is the visitor drop-off once Chrome actively warns people away from your pages, which affects the engagement and conversion signals Google does care about over time.
Is a free SSL certificate as good as a paid one for a small business site?
For almost all small business sites, yes. Free certificates issued through Let’s Encrypt provide the same encryption as paid ones; paid certificates mostly add extended validation branding that matters more for large financial institutions than a local Melbourne business.
How do I know if my site has mixed content right now?
Open your homepage in Chrome, right-click and choose “Inspect,” then check the Console tab for warnings mentioning “mixed content” or “insecure content” — these point to specific images, scripts or fonts still loading over HTTP.
Does this affect e-commerce and booking sites more than a simple brochure website?
Yes, noticeably. Any page that asks a visitor to enter personal details, payment information or a booking request is exactly where trust signals matter most, and it’s exactly where a “Not Secure” warning does the most damage. If you take payments or bookings online, HTTPS enforcement and a clean mixed-content check should be treated as non-negotiable rather than a nice-to-have, well ahead of Chrome’s October 2026 deadline.
Get ahead of Chrome’s 2026 rollout. Claim your free SEO audit worth $1,200 →
Leave a Reply