Certificate Expiry Risk Report 2026
· CSR.plus Team

- •Expiry incidents remain the single largest preventable cause of certificate-related outages.
- •Short-lived certificates (90 days) dramatically reduce exposure but raise the cost of manual renewal mistakes.
- •Monitoring with a 30-day warning window and automated renewal are the two practices that eliminate almost all expiry risk.
How expiry incidents happen
An expiry incident is rarely a technical failure — it is a missed renewal: a certificate on a forgotten server, a manual process skipped during holidays, an automation job whose cron entry was lost in a migration. The certificate crosses its notAfter date and every visitor hits NET::ERR_CERT_DATE_INVALID until someone renews.
The short-lived certificate effect
The shift to 90-day certificates (pioneered by Let’s Encrypt and now industry practice) shortens the worst-case window from years to months. The trade-off is operational: renewal must be automated, because quarterly manual renewal is exactly the process that gets skipped.
The two habits that eliminate expiry risk
First, monitor every certificate you own — track days-remaining and alert at 30 days, not 7. Second, automate renewal (ACME/certbot with a timer, or CA-managed renewals) and test it with a dry run in CI. Together these two practices convert expiry from a recurring incident into a non-event.
FAQ
What is the best alert threshold?
Alert at 30 days remaining for automated renewals and at 14 days for manual processes. A 7-day window leaves no room for validation failures or vendor delays.
Do short-lived certificates increase risk?
Only if renewal is manual. With automation, short-lived certificates reduce the damage window and force good hygiene.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.