.png&w=3840&q=75)
Websites & Hosting3 min
Why Does My SSL Certificate Keep Expiring? (90 Days vs 6 Months)
NS
NameSilo Staff7/15/2026
Share
Your SSL certificate expires on a short cycle because the entire industry now enforces brief validity windows. Free automated certificates (like AutoSSL) renew every 90 days. Commercial certificates, including those sold on a 1-year term, are now issued for a maximum of roughly six months (199 days) per certificate, with free reissuance covering the rest of your paid term. Neither is a setup error.
Automated Lifecycles vs the Traditional Annual Model
For years, businesses purchased SSL certificates valid for a full year or longer. That has changed industry-wide:
Certificate Type | Old Validity | Current Validity |
Free automated (AutoSSL / Let's Encrypt) | 90 days | 90 days (unchanged) |
Commercial (sold as 1-5 year terms) | Up to 398 days | Up to 199 days per issued certificate |
The key nuance: you can still purchase a commercial SSL certificate in a 1-year or multi-year term. Each individual certificate issued within that term is now only valid for up to 199 days (roughly 6 months). Your provider automatically reissues a fresh certificate for the remainder of your paid term at no extra cost.
Why It Matters: Security Hardening
Shorter certificate lifespans exist for one reason: reducing the damage window if a private key is ever compromised.
- A stolen key on a 1-year certificate remains exploitable for up to 12 months
- A stolen key on a 199-day certificate is exploitable for roughly 6 months
- A stolen key on a 90-day certificate is exploitable for 3 months at most
The CA/Browser Forum has progressively shortened these windows for years, with further reductions already scheduled for 2027 and beyond. This is a deliberate, industry-wide direction, not an isolated inconvenience.
The Role of Automated Renewal
For free hosting-included SSL (AutoSSL): On NameSilo's Turbo hosting plan, certificates renew automatically through a background process that checks status every few hours and reissues before expiry. No manual clicks, no CSR generation, no action required.
For purchased commercial certificates: Because each issued certificate now lasts up to 199 days, a 1-year purchase requires roughly two reissuances during the term, included in what you already paid for. You'll typically receive a validation email partway through your term. Complete that quick verification step and the new certificate installs automatically.
Decision Framework: Free Automated vs Paid Commercial
Option | Best For | Validity Cycle |
AutoSSL (free, included with Turbo hosting) | Standard websites, blogs, small business sites | 90 days, fully automatic |
Commercial SSL (purchased) | Enterprise compliance, extended validation needs | Up to 199 days per issuance, free reissue within term |
Both options require essentially zero ongoing effort once configured correctly. The difference is validation level and support, not reliability.
Common Pitfalls
Background renewal scripts failing silently: DNS misconfiguration, firewall rules, or an expired validation email can block the automated check, leaving visitors to see an expired security warning on day 91 or day 200.
Missing the reissuance validation email: If you purchased a 1-year commercial certificate and never see the mid-term revalidation email, check spam before your 199-day window closes.
Assuming a failed renewal means something is broken: It almost always means one small step (a DNS check, an email click) was missed.
What This Means for You
Whether you need the fully automated free option or want a higher-assurance commercial certificate, NameSilo's SSL Certificates page covers both. If you ever have questions about your renewal cycle or a validation email you can't find, reach out to support and we'll walk you through it. NameSilo's Turbo hosting plan includes AutoSSL at no additional cost.
Frequently Asked Questions
Is a 90 day SSL certificate safe?
Yes. Shorter lifespans reduce the exploitation window if a key is compromised.
Why did the industry move to shorter SSL lifecycles?
The CA/Browser Forum mandates it to limit damage from compromised keys.
What is Let's Encrypt?
A free, automated Certificate Authority commonly used via AutoSSL.
How do I automate my 90-day SSL renewal?
On Turbo hosting, AutoSSL handles this automatically with no action needed.
Can I buy a 1-year SSL certificate?
Yes. Each issued certificate lasts up to 199 days, with free reissuance during your term.
Does an automated SSL renewal cause site downtime?
No, when functioning correctly. Renewal happens before the old certificate expires.
What is an ACME protocol client?
Software that automates certificate requests and renewals with a Certificate Authority.
Does NameSilo sell long-term security certificates?
.png&w=2048&q=75)
NameSilo StaffThe NameSilo staff of writers worked together on this post. It was a combination of efforts from our passionate writers that produce content to educate and provide insights for all our readers.
More articleswritten by NameSilo

.png&w=3840&q=75)
.png&w=3840&q=75)
.png&w=3840&q=75)