An expired SSL certificate doesn't give much warning. One day the padlock icon works fine; the next, every visitor sees a "Your connection is not private" warning, and depending on the browser, they may not even be able to click past it. For an e-commerce checkout, a client portal, or an API integration, that's a full outage — and it happened not because anything broke, but because a date on a calendar quietly passed.
Why SSL renewals get missed more than other expiries
Certificates usually get set up once, during a deployment or migration, by whoever was handling infrastructure that week. If auto-renewal wasn't configured — or was configured but silently failed because a domain validation record moved — nobody finds out until the certificate is already gone. Unlike a license or a contract, there's rarely a human on the other end sending a renewal reminder; it's just infrastructure, and infrastructure only tells you it's broken after it breaks.
A simple tracking system that actually holds up
- List every certificate your business depends on — including ones covering subdomains, staging environments, and third-party integrations, not just the main website.
- Record the expiry date and the certificate authority for each one, in the same place you track domains and hosting.
- Assign an owner per certificate, so renewal isn't "whoever notices first."
- Set reminders well before expiry — 30 and 7 days out is a reasonable default — rather than relying on auto-renewal alone.
This is the same pattern that works for domain and hosting renewals, and it's worth tracking all three together rather than in separate systems. See the checklist in our guide on tracking domain and hosting renewals for the broader version of this approach, or explore how CorpoAlert's automated reminders handle this without manual spreadsheet upkeep.