When a website's SSL certificate expires, browsers don't quietly downgrade the padlock icon — Chrome, Safari and Firefox all block the entire page behind a full-screen warning, and most visitors won't click through it. Under the CA/Browser Forum's current rules, a certificate issued today already has to be renewed within 200 days, half the old yearly cycle most businesses still assume applies.
Why the renewal clock keeps shrinking
Certificates used to last up to two years. The industry body that sets these rules cut the maximum to 398 days back in 2020, then voted through a further schedule that took effect this year: 200 days now, 100 days from 2027, 47 days from 2029. The reasoning is narrower exposure — a certificate that's valid for two years stays trusted for two years even if the private key behind it was quietly compromised, or the domain changed hands, on day one. Shortening the window shortens how long a mistake made once keeps paying off for whoever made it. It also means the old habit of setting a certificate up at launch and not thinking about it again is already obsolete, and getting more so on a fixed schedule — which is exactly the kind of thing an ongoing maintenance plan exists to catch, not a box a developer ticks once and hands over.
What actually breaks, and where it hides
The visible failure is the full-page browser warning, and it's not subtle — it replaces the page entirely, for every visitor, on every browser, until the certificate is renewed. Less visible: a contact form or checkout that posts to a subdomain or API endpoint with its own certificate can fail silently even while the main page still loads from a cache, because the browser or payment gateway refuses the connection underneath without changing what's on screen. A handful of places let this happen without anyone noticing until it does:
- A subdomain — a staging site, an API endpoint, a booking widget someone added later — that was never covered by the main certificate's automatic renewal in the first place.
- Automatic renewal failing quietly because the DNS record or file it uses to prove domain ownership stopped matching after an unrelated change, with no visible symptom until the old certificate's clock finally runs out.
- A certificate installed manually years ago on infrastructure that never had automatic renewal configured at all, so it depends entirely on someone remembering.
Our secure website checklist groups this with the other things that expire on their own timeline whether or not anyone is watching — worth reading alongside this if certificate renewal isn't already a named line item in however the site gets maintained.
Frequently asked questions
How would I know if my SSL certificate is about to expire?
Most modern hosts and CDNs renew automatically and email a warning if renewal fails, but the only way to be certain is to check the certificate's own expiry date directly — click the padlock in the browser address bar and view the certificate details, rather than assume a reminder email would have arrived.
Does a certificate that renews automatically still need anyone to check on it?
Yes. Automatic renewal depends on a few things staying unchanged underneath it — the DNS records or file it uses to prove domain ownership, mainly. When one of those quietly breaks, the renewal fails the same way, just as quietly, until the expiry date actually arrives and the site goes down.
If certificates only last 47 days by 2029, will someone have to renew mine by hand every month and a half?
No — the shortening schedule only works because it forces renewal onto automated tooling industry-wide. A lifespan that short is only safe to mandate because manual renewal was already being phased out; it isn't asking anyone to do the old process more often.
Is a certificate expiring the same thing as a domain name expiring?
No, and the two get confused often. The domain registrar renews the domain name itself, usually yearly or longer. A separate certificate authority reissues the SSL certificate on its own much shorter schedule. A business can let one lapse without touching the other at all.
Where does this fit into ongoing website maintenance?
It's one of the fixed-shelf-life items our secure website checklist groups together — nothing was set up wrong at launch, the certificate simply has a clock that keeps running for as long as the site stays live. Catching it before it lapses is exactly what an ongoing maintenance plan is for.