Considering that SPDY requires SSL/TLS and therefore the webmaster will have to get and set up a certificate for his domain, I bet most websites will use HTTP for years to come.
There was some discussion about using self-signed certs with SPDY which would be treated as insecure (no lock). I don't know if a decision has been made.
It's not about the money. As patrick said you can get free certs from StartSSL, and companies like namecheap offer 1-year free certs if you buy a domain. It's about 1) lack of knowledge, 2) lack of support by shared hosting companies and 3) laziness.
SSL rules remain the same, and SPDY runs over SSL.
My opinion - get a real signed cert. A basic free one from startssl.com is available.
The PKI has problems to be sure and needs to evolve. But simple forms of eavesdropping and MITM attacks need to stop. Its great that SPDY is SSL based.
Google exposes a lot more services to IPv6 than SPDY, though traffic might be another matter. I am merely poking fun at any hopes of a replacement, for as long as HTTP still works; even a protocol with a death warrant and a significantly better alternative doesn't get displaced but merely coexists. On the other hand, SPDY can be enabled on the edges, and become useful without waiting for network support.
Spdy actually shines brightest on things like plus.google.com or picasa because of all the little icons.. images.google.com is also a very big beneficiary.
It would be an excellent fit for things that look like facebook, ebay, twitter..