The 398 day rule
Since September 2020, browsers do not accept SSL certificates that are valid for more than 398 days. This is a browser rule, not a seller rule. So no matter what you pay, the certificate file on your server expires within about 13 months.
Then what is a 3 year plan?
It is a subscription. You pay once for 3 years at a lower yearly rate, and before each yearly expiry the certificate is reissued for free. You install the new file, and the price stays locked. You avoid two future price increases and two future payments.
Renewal checklist
- Start 30 days before expiry. Our system emails you at 30, 14 and 7 days.
- Generate a fresh CSR, or reuse the old one if the domain list is unchanged.
- Complete domain validation again (email, DNS or file). OV and EV company data is reused if it is under 825 days old, so a renewal is faster than the first order.
- Install the new certificate and the new CA bundle. The old certificate keeps working until you replace it, so there is no downtime.
- Run the SSL checker to confirm the new expiry date.
Can I renew early?
Yes. Remaining days are added to the new certificate, up to the 398 day limit, so you lose nothing.
Written by the SSLWalay team, Karachi. Last reviewed October 2026. Prices quoted are SSLWalay PKR prices at the time of review and can change; the product pages always show the live price.