Skip to main content
compliance · aws

ACM certificates with fewer than 30 days left before expiry, or already expired

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

ZopNight flags an AWS Certificate Manager certificate when its `NotAfter` date is fewer than 30 days away, and reports certificates that have already expired separately. The rule is critical severity with no dollar figure, because an expired certificate breaks TLS for every load balancer, CloudFront distribution or API that serves it.

Signal and threshold

How ZopNight evaluates ACM certificates with fewer than 30 days left before expiry, or already expired.
Field Value
Rule IDsRC-198
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdfewer than 30 days to expiry
SourceZopNight
Permissions usedacm:ListCertificates · acm:DescribeCertificate

When ACM does not renew in time

ACM renews Amazon-issued certificates automatically, but only under conditions. The managed renewal guide lists imported certificates and already-expired certificates as not eligible. For DNS-validated certificates, the DNS renewal page says ACM checks 45 days before expiry that the certificate is in use by an AWS service and that every ACM-provided CNAME record is still reachable in public DNS. Remove a CNAME during a DNS migration, or import a certificate from another CA, and nothing renews it. Email-validated certificates need the domain owner to respond to renewal mail.

Checking expiry dates yourself

list-certificates returns the expiry date, whether the certificate was imported, and its renewal eligibility:

Terminal window
aws acm list-certificates \
--query 'CertificateSummaryList[].[DomainName,NotAfter,Type,RenewalEligibility,InUse]' \
--output table

For one certificate, see the renewal status and where it is used:

Terminal window
aws acm describe-certificate --certificate-arn CERT_ARN \
--query 'Certificate.{notAfter:NotAfter,renewal:RenewalSummary.RenewalStatus,usedBy:InUseBy}'

The 30-day trigger

ZopNight computes the whole number of days between now and the certificate’s expiry date. The finding fires when that number is below 30. A negative value means the certificate has already expired, and the finding says so explicitly (“has already expired, N days past expiry”) rather than counting down.

Certificates that are not evaluated

A certificate that has not been issued yet, such as one still pending validation, has no expiry date and is skipped. ZopNight uses only the expiry date it read from ACM; a tag on the certificate claiming a date is ignored.

Outage risk instead of a saving

The finding carries a fixed $0 estimate. The cost of ignoring it is an outage: browsers and API clients reject an expired certificate, so every endpoint behind it goes dark at the same moment. That is why the rule is rated critical.

Getting the certificate renewed

  1. For a DNS-validated certificate, confirm the validation CNAME records are still published; the values are under DomainValidationOptions in describe-certificate.
  2. For an email-validated certificate, respond to the renewal email AWS sends to the domain contacts.
  3. If automatic renewal failed, read RenewalSummary in the ACM console or CLI for the reason.
  4. Request a new certificate if renewal is not possible, attach it to the load balancer or distribution, and remove the old one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·