Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To prevent a certificate-expiry surprise, track who owns each certificate, verify whether its renewal is actually automatic, and send renewal and deployment alerts to someone responsible for fixing them. In AWS, AWS Certificate Manager (ACM) can manage renewal for eligible certificates it issued—but imported certificates and certificates that fail validation need an operator-led process.

Why automatic certificate renewal is not a set-and-forget guarantee

ACM-managed renewal applies to eligible certificates issued by ACM, not every certificate used by an AWS workload. AWS’s managed renewal criteria include whether a certificate is associated with an integrated AWS service or has been exported. Imported certificates are not eligible for ACM managed renewal.

For imported certificates, AWS says the customer must monitor expiration, obtain a replacement, and import it before the old certificate expires. The import process is an operational responsibility, not a renewal ACM performs on the customer’s behalf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check whether your ACM certificate can renew

For each ACM-issued certificate, confirm that it meets ACM’s current managed-renewal criteria and identify the AWS service using it. Do not assume that seeing a certificate in ACM means its renewal is covered.

DNS validation also has to keep working. For a DNS-validated certificate, the certificate must be in use by an AWS service, and the required ACM CNAME records must remain present and publicly accessible when ACM checks renewal. A removed, incorrect, or inaccessible record can block renewal. See AWS’s DNS validation renewal requirements.

Check renewal status, not only the expiration date

An expiration date tells you when a certificate ends; renewal status can show whether ACM is progressing toward renewal or needs action. AWS supports checking status in the ACM console, through its API or CLI, and through the AWS Health Dashboard. Statuses distinguish states such as pending automatic renewal, pending validation, success, and failure. AWS notes that some status changes may take time to appear, so a change should not be assumed to show instantly. Details are in the ACM renewal status guidance.

Route AWS certificate-expiration alerts to an accountable person

ACM publishes approaching-expiration events through Amazon EventBridge. As documented by AWS on October 7, 2026, these events are sent daily starting 30 days before expiration for public certificates and 45 days before expiration for private or imported certificates. These thresholds are AWS-documented behavior and may change. Consult the ACM events documentation when configuring or reviewing your rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create an EventBridge rule for the relevant ACM events and route notifications to a monitored channel or incident queue. The alert should identify the certificate and its owner, and make clear who handles validation, renewal, or deployment problems. AWS recommends monitoring renewal events, automating deployment after renewal, and alerting on renewal or deployment failures; see its ACM monitoring recommendations.

Rank #3
Sale
MOSA BEAR Password Keeper Book with Alphabetical Tabs,4.3"x5.7" Small Password Books for Seniors Password Notebook for Internet Website Address Log in Detail(Dark Blue)
  • 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
  • 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
  • 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
  • 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
  • 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.

An event being available does not by itself prove your notification route works. Periodically exercise the route and confirm that the intended person or queue receives and owns the alert.

Build a certificate inventory and response workflow

  1. Inventory coverage: List every client domain and subdomain, the certificate serving it, its expiration date, validation method, service using it, and a named human owner. Include imported certificates and certificates outside AWS.
  2. Verify renewal eligibility: For ACM-issued certificates, check the current managed-renewal criteria and confirm the certificate is associated with an integrated AWS service or otherwise meets the documented criteria. Mark imported certificates as requiring an operator-led replacement process.
  3. Verify DNS validation: For DNS-validated certificates, check that each required ACM CNAME record remains in public DNS and can be resolved. Investigate pending-validation or failure status rather than relying on the expiry date alone.
  4. Configure and test alert routing: Use EventBridge for ACM events, route them to a monitored destination, and confirm the named owner or response queue can act on them.
  5. Track deployment separately: After renewal or reimport, verify that the renewed certificate is actually deployed to the service presenting it. Treat successful issuance and successful deployment as separate completion checks.
  6. Schedule imported-certificate replacement: Arrange reissue and reimport with enough time before expiry to resolve problems, and confirm both the replacement and its deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What AWS-native alerts do—and do not—cover

ACM’s status and EventBridge mechanisms address certificates managed or tracked by ACM. The cited AWS documentation does not establish that they discover every certificate across unrelated hosting providers, registrars, CDNs, load balancers, or external certificate authorities, nor that an alert verifies the live certificate visitors receive.

Rank #4
AT-A-GLANCE Undated Website Address Book and Password Keeper, Black, 3.63 x 6.13 x .21 Inches (80-500-05)
  • Bookbound planner helps you keep track of passwords and favorite websites
  • Room for over 200 entries; 3.5 x 6 inch page sizes
  • User name and security questions field
  • Tips for what makes a strong password; web resources; notes pages
  • Printed on quality paper containing 30% post-consumer waste; black simulated leather cover; 3.63 x 6.13 x .21 inches

When comparing monitoring approaches, check what domains and certificates they discover, whether thresholds are configurable, whether alerts cover renewal, validation, and deployment, who owns each alert, and whether the system checks the certificate presented to visitors. Confirm capabilities against the provider’s current official documentation; renewal and notification behavior differs by service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.