Why your certificate expires before your order

Updated on 09 Sep 2026

Your order lasts twelve months. Your certificate lasts about two hundred days. That is not a mistake and you were not sold less than you paid for: they are two different clocks, and they are going to diverge further over the next few years.

Two clocks, not one

  • The order is what you bought. It entitles you to have a certificate issued for that period, and to ask for as many reissues as you need without paying again.
  • The certificate is the file you install on your server. It has its own, shorter expiry date.

When the certificate expires and the order is still running, you do not buy anything: you reissue. It is free and included.

The schedule ahead

Certificate authorities have been shortening the maximum life of a certificate for years, for security: a compromised certificate that expires soon does less damage. The schedule is already set and it is not ours to change:

From Maximum life
Today 200 days
March 2027 100 days
March 2029 47 days
Maximum SSL certificate lifetime, 2025-2030 Step chart: 398 days until March 2026, 200 days until March 2027, 100 days until March 2029, and 47 days from then on. 0 100 200 300 400 days 398 days 200 days 100 days 47 days mar 2026 mar 2027 mar 2029
The maximum lifetime a certificate authority may give an SSL certificate. The dates are already set by the CA/Browser Forum.

The certificates we issued in 2026 last, at the median, 199 days — the maximum for the current window.

That changes how many times you will install a certificate over the life of a single order:

Your order Today From 2027 From 2029
12 months 2 certificates 4 8
24 months 4 8 16
36 months 6 12 24

That last column is worth reading slowly. At 47 days, installing a certificate by hand stops being reasonable: eight times a year is survivable, but every 47 days is close to eight times a year per domain, and if you run several, automating stops being optional. If you get there and are not sure where to start, get in touch — it is exactly the kind of thing worth solving early rather than on the day the site goes down.

Working out where you are

In your TiendaSSL dashboard, every order shows both dates separately: how long the order is good for, and how long the installed certificate is good for.

The one that matters to your site is the certificate. If that date has passed, your site is showing warnings to visitors right now, however valid the order still is.

You can also check from the outside with our SSL Checker: it tells you which certificate your domain is serving at this moment and when it expires.

We email you before it expires, so you do not have to watch the calendar.

What to do in each case

  • The certificate expires soon and the order is still runningreissue, at no cost.
  • The order ends soonrenew, which means buying a new order.
  • Both at once → renew; the new order issues a new certificate.