Reminders for Teams

SSL Certificate Expiration: The 90-Day Clock Nobody's Watching

An expired SSL certificate scares visitors off and can break your APIs. How cert expiration works—and how to make sure one never lapses on your watch.

ITrenewals
A security shield with a padlock next to a 30-day countdown ring for an expiring SSL certificate

Everyone has hit one: the full-page red warning telling you a site isn't secure and asking whether you really want to continue. Most people don't continue. They leave.

That warning is what your customers see the moment your SSL/TLS certificate expires. It doesn't matter that your site is perfectly fine underneath—browsers treat an expired certificate as a broken promise and put a wall in front of it. For an e-commerce checkout, a login page, or a public marketing site, that wall converts visitors into bounces and support tickets in real time.

What actually happens when a certificate expires

An SSL certificate is a time-boxed statement of trust. It says, in effect, "this server is who it claims to be, verified until this date." When that date passes, the guarantee is void, and everything that relied on it starts to fail:

  • Browsers block the page with an interstitial security warning that most visitors won't click past.
  • APIs and integrations break. Any service that connects to yours over HTTPS may reject the expired certificate and stop working—often silently, until something downstream fails.
  • Mobile apps can go dark. Apps that pin or validate your certificate can lose the ability to reach your backend entirely.
  • Trust takes a hit. Even after you fix it, some visitors remember the scary warning.

The frustrating part is that the fix is trivial. Renewing or reissuing a certificate takes minutes. The entire problem is that nobody remembered to do it in time.

Certificates expire more often than they used to

The window keeps shrinking. Certificate lifetimes have been getting shorter across the industry, which means renewals come around far more frequently than the annual cadence many teams still assume. Shorter lifetimes are good for security—a compromised certificate is trusted for less time—but they multiply the number of renewal deadlines your team has to catch.

Automation like ACME and Let's Encrypt handles a lot of this quietly in the background. But automation isn't universal. Plenty of certificates still renew manually: internal services, load balancers, third-party appliances, client-facing systems with strict validation requirements, and anything a vendor manages on your behalf. Every one of those is a manual deadline waiting to be missed. And the cost is lopsided: renewing on time takes minutes, while a single lapse can cascade through every service that trusts the certificate, taking down far more than the one site you were watching.

Why SSL renewals slip through the cracks

  • They're invisible until they fail. A certificate gives no warning to your team as it counts down. It just works, right up until the moment it doesn't.
  • They're scattered. A single company can have certificates across dozens of domains, subdomains, and services, each with its own expiration date and its own owner—or no owner at all.
  • Automation creates false confidence. "It auto-renews" is true until a renewal hook fails, a domain validation breaks, or a certificate falls outside the automated pipeline. Then it expires like any other.

Build a certificate renewal process that doesn't rely on luck

  1. Inventory every certificate, including the ones you assume are automated. Note the domain, the expiration date, the issuer, and whether renewal is automatic or manual.
  2. Set reminders well ahead of expiration—typically 30 days out, with an earlier heads-up for certificates that require validation or vendor coordination.
  3. Give each certificate an owner, so "someone should renew that" becomes "this is your task."
  4. Monitor the live certificates, not just your intentions. Auto-renewal should still be verified, because a silent renewal failure looks exactly like a working system until the expiration date.
  5. Route expiration alerts to a team channel, so a single person's vacation doesn't become an outage.

Don't let a two-minute task cause a two-day incident

An expired certificate is one of the most preventable outages there is. The renewal is fast. The monitoring is the whole game.

Reminders for Teams tracks the expiration date of every certificate and domain your team depends on, assigns clear ownership, and alerts the right people early—so a background countdown never turns into a front-page security warning. It's the core of both SSL & domain tracking and broader renewal management.

Know exactly when every certificate expires, before your customers do. Try it free.

Never miss a deadline again

Reminders for Teams helps your team track renewals, compliance dates, and recurring obligations — with automatic email alerts.