TLS and certificates
Certificate expiry checker
See when the certificate on a website runs out and how many days are left, for the domain and its www name. After that date browsers warn visitors away from the site, so it is worth knowing well in advance.
What this checks
- The not-after date of the certificate each host serves on port 443, and the whole days remaining until then.
- Whether that date is 30 days away or less, raised as a low-severity finding, or 14 days or less, raised as medium.
- The not-before date, so a certificate dated to start in the future is caught as well.
- Trust and hostname coverage alongside the dates, because a renewal that installs the wrong certificate breaks the site just as an expired one does.
What the result means
Every certificate has a fixed lifetime, set by its issuer when it is created, and nothing extends it: the only fix is a new certificate. Lifetimes are short and getting shorter, which makes renewal a job for automation rather than a reminder in a calendar.
A pass means more than 30 days remain. Inside 30 days the result becomes a finding, low at first and medium from 14 days. Automated renewal usually acts with weeks to spare, so a certificate that stays in that window for more than a few days suggests the renewal job, its DNS or HTTP validation, or the step that reloads the server has failed.
Dates are read per host. The bare domain and the www. name can carry different certificates with different expiry dates, and the earlier one is the one to plan around.
How to fix common issues
Certificate expires soon
Renew the certificate now, or check that automated renewal is working.
Certificate has expired
Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.
Certificate is not yet valid
Check the server's clock and the certificate's validity dates, and install a certificate that is valid now.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 sets a renewal deadline. Under ISO/IEC 27001:2022, certificate renewal falls within key management, part of Annex A 8.24 (use of cryptography). A date seen from outside is evidence that renewal worked this time; the organisation still needs a named owner for each certificate and a way of noticing when renewal fails.
Scope and limitations
- The date is taken from the certificate served at one address per host when the check ran. If several servers or regions answer for the name, another of them may still hold an older certificate.
- Your renewal set-up is invisible from outside, so the check cannot tell whether a certificate with 40 days left will renew itself.
- Other subdomains need a run each. Certificates on other ports and on internal systems are out of reach.
Related guides
Questions
- How do I check when an SSL certificate expires?
- Enter the domain above. The checker connects to the site, reads the certificate it serves and shows the expiry date and the days left. In most browsers the certificate viewer, opened from the address bar, shows the same date.
- What happens when a certificate expires?
- Browsers stop at a warning page instead of loading the site, and most apps, API clients and other servers refuse to connect. The server keeps sending the expired certificate until a new one is installed.
- How long are SSL certificates valid for?
- It depends on the issuer, within a ceiling set by the CA/Browser Forum. Publicly trusted certificates issued since 15 March 2026 can last at most 200 days, falling to 100 days in 2027 and 47 days in 2029. Many authorities issue for 90 days or less.
Related security tools
- Certificate checker - Read a site's TLS certificate: the names it covers, its issuer, validity and trust.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- CAA checker - See which certificate authorities a domain allows to issue its certificates.

