SSL/TLS certificates expire by design. When a publicly trusted certificate reaches its expiration date, browsers can no longer treat that certificate as valid for the website. The result can be a browser security warning, failed API connections, broken integrations or outages for services that depend on TLS.
This matters more in 2026 because public TLS certificate lifetimes are getting much shorter. Under the current CA/Browser Forum Baseline Requirements, publicly trusted subscriber certificates issued from March 15, 2026 through March 14, 2027 have a maximum validity period of 200 days. The scheduled maximum drops to 100 days in March 2027 and 47 days in March 2029.
Current public TLS certificate validity schedule
| Certificate issued | Maximum validity period |
|---|---|
| Before March 15, 2026 | 398 days |
| March 15, 2026 through March 14, 2027 | 200 days |
| March 15, 2027 through March 14, 2029 | 100 days |
| March 15, 2029 and later | 47 days |
Source: the CA/Browser Forum current TLS Baseline Requirements and the SC081v3 validity-reduction schedule.
What happens when an SSL certificate expires?
An expired certificate is no longer valid for establishing a normally trusted TLS connection. Depending on the browser, application or API client, users can see a security warning or the connection can fail entirely.
- Website visitors can encounter certificate-expired warnings.
- APIs and webhooks can reject the connection.
- Payment, login or third-party integrations can fail if they require a valid TLS connection.
- Monitoring systems can report certificate or HTTPS failures.
- Automated clients can fail without giving an end user a browser override option.
Expiration therefore needs to be treated as an operational deadline, not only an administrative renewal date.
Certificate validity is not always the same as the billing term
A certificate subscription or commercial plan can be sold on a billing term that is longer than the validity period of an individual certificate issued under that plan. As public certificate lifetimes shorten, a provider may need to issue or reissue replacement certificates during the subscription period.
When comparing SSL certificate plans, review both the commercial term and how certificate renewal/reissuance is handled. Do not assume that paying for a year means one browser-trusted certificate can remain valid for a full year under current public Web PKI rules.
How early should you renew or replace an expiring certificate?
Do not wait until the final day. The correct lead time depends on whether issuance is automated, whether domain or organization validation is required, and how many systems need the replacement certificate.
For a manually managed certificate, build enough time to:
- Confirm the hostname coverage you still need.
- Complete any required validation.
- Issue or reissue the replacement certificate.
- Install it on every relevant server, load balancer or service.
- Verify the full certificate chain.
- Test HTTPS from outside the server environment.
- Confirm monitoring sees the new expiration date.
Domain validation also has a shorter reuse window
The current CA/Browser Forum schedule also reduces how long prior domain-name and IP-address validation data can be reused. For certificates issued from March 15, 2026 through March 14, 2027, the maximum domain/IP validation data reuse period is 200 days. The schedule drops further in later years.
That means shorter certificate lifetimes are part of a broader move toward more frequent validation and automation—not simply a browser cosmetic change.
How to check when a certificate expires
You can inspect the certificate in a browser, use a monitoring service, or check from a command line. On a system with OpenSSL, a basic remote check looks like this:
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates -issuer -subject
Replace example.com with the hostname you control. The notAfter value is the certificate’s expiration time. For production monitoring, use an automated check rather than relying on occasional manual inspection.
Wildcard and multi-domain certificates need the same expiration planning
A wildcard or SAN certificate can affect many hostnames at once, so expiration can have a larger blast radius.
- Wildcard SSL is designed for eligible subdomains under one base domain.
- Multi-Domain SAN SSL is designed for multiple covered domain names/hostnames.
Maintain an inventory of every hostname and server using the certificate before renewal or replacement.
What if your hosting already manages SSL automatically?
Some hosting platforms automate certificate issuance and renewal. If your current hosting product already handles the TLS certificate you need, buying a separate certificate can be unnecessary.
Check what the hosting platform actually covers, whether the certificate renews automatically, and whether your required hostnames are included. A separate paid certificate can still be appropriate when you need a specific validation type, coverage model or certificate-management workflow.
How shorter SSL lifetimes change operations
The direction of the Web PKI is toward shorter validity periods and more automation. Teams that manually renew certificates once a year should start treating certificate lifecycle management as a recurring operational process.
- Inventory certificates and the systems using them.
- Monitor expiration continuously.
- Automate renewal and deployment where the platform safely supports it.
- Document emergency replacement steps.
- Test renewal before the existing certificate becomes urgent.
- Avoid storing old private keys or certificate bundles in insecure locations.
Frequently asked questions
How long can an SSL certificate last in 2026?
For publicly trusted TLS subscriber certificates issued on or after March 15, 2026 and before March 15, 2027, the current CA/Browser Forum Baseline Requirements set a maximum validity period of 200 days.
Will SSL certificates really drop to 47 days?
Yes, under the currently adopted schedule. The maximum drops to 100 days in March 2027 and 47 days in March 2029.
Does my certificate subscription also end after 200 days?
Not necessarily. Commercial billing/subscription terms and the validity period of an individual issued certificate are different concepts. Review the provider’s current renewal and reissuance process.
Does an expired SSL certificate hurt SEO?
The immediate problem is availability and trust: users and crawlers can have difficulty accessing a site with an invalid TLS certificate. Preventing expiration protects the site’s normal HTTPS availability rather than serving as a ranking tactic.
Should I buy wildcard SSL for several subdomains?
Wildcard SSL can make sense when eligible subdomains under one base domain need coverage. If you need several different domains or unrelated hostnames, compare a SAN/multi-domain certificate instead.
Need a certificate or replacement?
Compare current SSL certificate types, live pricing and coverage before checkout.