HTTPS as a ranking signal since 2014, and Chrome's "not secure" warning
Google confirmed in August 2014, on its official Search Central blog, that HTTPS would count as a ranking signal. At the time it described this as a "lightweight" signal, carrying less weight than content relevance or link quality, but with the stated goal of pushing the whole industry toward encryption. More than a decade later, that push worked: HTTPS is now the de facto standard, and finding a relevant page still served over plain HTTP is the exception, not the rule.
The real turning point didn't come from the search algorithm, though, it came from the browser. In February 2018, the Chromium team announced that starting with Chrome 68, released that July, any page loaded over HTTP would show a "Not secure" label next to the URL, without needing a password or credit card field on the page as had been the trigger before. That warning shows up before a visitor has read a single line of content. Later Chrome versions pushed the warning further still, briefly turning the label red instead of grey on pages with input fields, to make it harder to miss.
That's the practical distinction worth keeping straight: the ranking bonus from HTTPS is small and mostly acts as a tiebreaker between equally relevant pages. The "Not secure" warning, on the other hand, is an explicit, visible flag that a visitor reads instantly as "I shouldn't trust this site," with no algorithm involved at all. That trust damage, immediate bounces, abandoned carts, forms nobody bothers finishing, tends to outweigh the extra ranking point in practice, and it's usually the argument that convinces a hesitant client when SEO alone doesn't land. What a business feels first isn't a ranking drop, it's whether a visitor is even willing to type personal details into a form after seeing that warning.
