TLS uses a public-key certificate, issued by a trusted authority, to establish an encrypted session between browser and server. Modern free CAs like Let's Encrypt made HTTPS the universal default around 2018.
HTTPS is a soft ranking signal in Google and a hard requirement for many browser APIs (service workers, geolocation, WebAuthn, camera/microphone). Chrome marks plain HTTP pages as 'Not Secure'.
A correctly-configured site redirects all HTTP traffic to HTTPS, sets a canonical to the HTTPS URL, and enables HSTS so the browser refuses to fall back.