You don't need to pay anything to get a certificate. You only need if you want it signed by a major CA. Something with closed membership like the bar association could just publish the fingerprint and have everyone trust the certificate manually.
it might be even wiser.
Yeah, I know I'd be happier with a bar issued certificate than a, say, DigiNotar one.