Buying · 4 min read

SSL renewal explained: why a 3 year plan still needs a yearly reissue

The 398 day rule, how multi-year plans really work, and a renewal checklist that avoids downtime.

The 398 day rule

Since September 2020, browsers do not accept SSL certificates that are valid for more than 398 days. This is a browser rule, not a seller rule. So no matter what you pay, the certificate file on your server expires within about 13 months.

Then what is a 3 year plan?

It is a subscription. You pay once for 3 years at a lower yearly rate, and before each yearly expiry the certificate is reissued for free. You install the new file, and the price stays locked. You avoid two future price increases and two future payments.

Renewal checklist

  1. Start 30 days before expiry. Our system emails you at 30, 14 and 7 days.
  2. Generate a fresh CSR, or reuse the old one if the domain list is unchanged.
  3. Complete domain validation again (email, DNS or file). OV and EV company data is reused if it is under 825 days old, so a renewal is faster than the first order.
  4. Install the new certificate and the new CA bundle. The old certificate keeps working until you replace it, so there is no downtime.
  5. Run the SSL checker to confirm the new expiry date.

Can I renew early?

Yes. Remaining days are added to the new certificate, up to the 398 day limit, so you lose nothing.

Certificates bought from another seller can be moved to SSLWalay at renewal time. Prices are in PKR and the process is the same.

Written by the SSLWalay team, Karachi. Last reviewed October 2026. Prices quoted are SSLWalay PKR prices at the time of review and can change; the product pages always show the live price.

Not sure which SSL to buy? We will pick it for you.

Tell us your website type and hosting. We recommend the right certificate, the right term and the PKR price. Free, no pressure.

Bank transferJazzCashEasyPaisaDebit or credit card
WhatsApp, reply in minutes