You do not need to buy an SSL certificate. Mals and/or PayPal provides the SSL certificate for you. Buying one for your website is a complete waste of money. Your sites do not have the ability (due to the designated IP addresses which is now required) to display SSL.
If your cart is in the iframe then it won't show the secure lock or the https. You have to put your cart in Normal Window in order to show the secure lock. You do that in Catalog Setup.
If you have the premium Mals version, you can add the SSL, Thawte and McAfee Safe symbols.