cert-governance · severity high
Certificate expiry
Share of web-serving domains whose TLS certificate expires within 30 days, or has already expired.
Measured every Wednesday · last updated
How it is measured
Tier 2, one TLS handshake; read not_after. Denominator: has_web.
Why it matters
The certificate nobody owns. Expiry is a scheduled, entirely predictable outage that still takes sites down constantly, because renewal was somebody's manual task and that somebody left.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 61 segments
From the newsletter
Where this base rate turned up as a real, fixable exposure.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.