BlogGuides
Expired SSL certificate on your website: what actually happens

One click, and Google will show my articles more often in your results.
Anyone searching "expired SSL certificate" is usually already in the middle of the problem: they clicked on their own site and hit a screen they weren't expecting, or a customer flagged it to them. The question that matters isn't what the letters SSL stand for, it's what a visitor actually sees at that moment, and how serious it is.
What a visitor actually sees
When a site's certificate expires, visitors don't get a small warning tucked in a corner of the screen: they get a full page that covers everything else. Google Chrome's own official documentation confirms this, describing this kind of problem as a full-page error message and explicitly advising users to proceed with caution, or not use the site at all if it's flagged as dangerous. On Chrome the technical code is NET::ERR_CERT_DATE_INVALID, shown to the user as "your connection is not private"; Firefox and Edge show equivalent warnings in substance. In many cases it's still possible to force access by clicking a link hidden under "advanced", but that's a step most people, rightly wary, don't take.
It isn't, first and foremost, a Google ranking issue
A common belief is that an expired certificate makes a site disappear from Google's results. That isn't the case, or rather, it isn't the main reason to worry about it. Google has used HTTPS as a ranking signal since August 7, 2014, when it announced the change on its own official blog, describing it from the start as "a very lightweight signal, affecting fewer than 1% of global queries and carrying less weight than signals like content quality." That reference no longer appears in Google's current official guide to its ranking systems, but it's still cited among page experience factors in its documentation for site owners. So the problem with an expired certificate isn't, first of all, that Google penalizes the site: it's that whoever lands on it sees a warning that discourages them from staying, well before Google even comes into play.
Why it almost always happens for the same reason
A certificate doesn't expire because of an attack or a technical fault: it expires because it has an end date, and nobody renewed it in time. It happens even to companies with vast resources. On February 3, 2020, Microsoft Teams was unreachable worldwide for about three hours: the cause, announced at the time by the official Office 365 Status account, was "an authentication certificate has expired". It wasn't a website's public certificate, but an internal certificate that followed the same underlying logic: an expiry date nobody had marked on a calendar. The service returned for most users by late morning, US Eastern time, but the incident stayed memorable precisely because it wasn't some small site that tripped up: it was Microsoft.
What changes starting in 2026
As of March 15, 2026, the maximum validity of a public certificate dropped from 398 to 200 days: the CA/Browser Forum, the body that brings together the makers of the major browsers and the authorities that issue certificates, set this in a ballot approved on April 11, 2025. That means anyone who used to renew their certificate once a year now has to do it almost twice as often, and the schedule includes two further cuts: to 100 days from March 15, 2027, and to 47 days from March 15, 2029. For anyone handling renewal by hand, noting it on a calendar or relying on a reminder email, the risk of missing it grows in the same proportion.
The guarantee
Thirty days to change your mind.
In more than ten years I have never had a client unhappy with the work delivered. That is why I can afford to say this: you have 30 days from accepting the quote to stop, or until the site goes live if that comes first. Within that window I refund everything you have paid and we part ways, with no further claim and no argument. There are no conditions to meet and nothing to prove: you decide.
You get me, within one working day.
No switchboard, no support form. If you write or call and I do not answer within one working day, you do not pay that month.
I take the risk at the start. It is the only way I have to say “trust me” and have it mean something.
The difference that actually matters
Not every certificate renews the same way. Let's Encrypt, the world's most widely used free certificate authority, issues certificates valid for 90 days, and its own documentation recommends renewing them every 60, through a program installed on the server rather than a person who has to remember. That's the system most modern hosting now uses, including hosting built for people who don't want to deal with these details, as I've explained writing about website hosting. So the real risk isn't having an SSL certificate, which nearly every site has by now: it's having a renewal that depends on a person instead of an automatic mechanism. And with expiry dates now coming around more often, that margin for error keeps growing.
Where to start
If you manage your own site, the first thing to check isn't the certificate itself, but who renews it: if your hosting does it automatically, this problem rarely concerns you. If the certificate was instead bought separately, or installed by hand at some point in the past, it's worth checking when it expires before a customer discovers it for you. If you're not sure how your site is set up, get in touch and we'll check it together.