New Rules Mean Your Title Company’s Website Certificate Now Expires Every Few Months. Here’s Why That Actually Matters.
A client sent this our way recently: a link to a routine-looking industry update about certificate renewal timelines. Her question was simple. Are we covered? The answer was yes. But that update is worth unpacking on its own, because “are we covered” is exactly the right question for every title company to be asking right now, even if nobody sent them the link, and getting ahead of a title company certificate renewal shift like this one is exactly the kind of thing that shouldn’t wait for a client to ask first.
Here’s what the update actually said, stripped of the jargon. The public SSL/TLS certificates that secure websites are moving to a much shorter lifespan. As of March 15, 2026, the maximum validity dropped from about 13 months to 200 days. By March 2027, that shrinks to 100 days. By March 2029, it’s down to just 47 days. This isn’t a title-industry rule. It’s an industry-wide decision from the CA/Browser Forum, the group that sets the standards every public certificate authority follows, and it affects any organization with a public-facing website or client portal, regardless of what business they’re in.
What a Title Company Certificate Renewal Actually Protects
A quick, plain-language version of what a certificate actually does: it’s the mechanism that proves a website is really who it claims to be, and it encrypts what passes between a visitor and that site. When a client logs into a secure portal to review closing documents or confirm wire instructions, the certificate is the thing quietly working in the background to make that connection trustworthy. Most people never think about it until something goes wrong, which is exactly the problem. The things nobody thinks about are usually the things nobody’s watching either.
Here’s why a title company feels this differently than, say, a local bakery’s website. Title and settlement companies run on trust in digital communication at exactly the moment the most money is on the line in a client’s life. A lapsed certificate on a client portal doesn’t just look unprofessional or trigger a browser warning. It’s the kind of gap that erodes the very signal clients are relying on to know they’re really talking to their title company and not somebody impersonating it, right at the moment that signal matters most. A homebuyer who’s never heard of a certificate before still notices when a site suddenly looks different or throws up a warning, and in an industry built on trust at the closing table, that kind of moment does real damage even when nothing was actually stolen.
That connects directly to wire fraud, which is already the threat every title company fights daily. The FBI’s Internet Crime Complaint Center logged business email compromise losses of just over $3 billion in 2025, the second-highest fraud category behind investment fraud. The IC3’s own report includes a case that captures exactly what’s at stake: a couple mid-closing received an email impersonating their attorney and wired more than $449,000 to a fraudulent account before anyone caught it. Most of this fraud happens in the tight 24 to 48 hour window right before a wire goes out, when instructions are being shared and everyone’s moving fast. Anything that weakens the reliability of “this is really them” raises the stakes in exactly that window.
None of this means the certificate itself is the fraud, or that this update is some kind of new attack. It means the infrastructure behind trusted communication needs to be maintained properly, not set up once and forgotten, especially as the renewal window keeps shrinking. A business that renewed its certificate once a year without much thought is about to find that habit doesn’t hold up. At 200 days, it’s already tighter than an annual reminder. At 100 days, most manual tracking starts to break down. At 47 days, there’s no realistic path to catching it by hand, no matter how organized the front desk calendar is.
This is exactly the kind of thing that should be automated and monitored by an IT partner, not tracked on a calendar reminder. Angie and Oscar have always run Paradigm on the idea that being proactive means catching things before a client has to ask, not scrambling to answer well after the fact. That’s really what “are we covered” is asking underneath the words: has somebody already been watching this, or are we about to find out the hard way. The businesses that get caught off guard here aren’t the ones being careless. They’re the ones who had a process that worked fine for years, right up until the schedule underneath it changed without much warning.
Here’s the honest version of that reassurance: our team already tracks certificate status across every client website and portal we manage, on a schedule that doesn’t depend on anyone remembering to check. That’s what let the answer to “are we covered” be an immediate yes instead of a scramble to go find out.
What This Means for Your Business
Automate certificate renewal and monitoring: Manual tracking that worked at once-a-year intervals won’t survive quarterly, and it definitely won’t survive every six weeks. This needs to move to something that renews and verifies itself, with a real person checking that it actually happened, not just trusting that it did.
Keep your existing wire fraud habits in place: This update doesn’t replace phone verification of wire instructions or healthy skepticism toward an “updated” instruction that shows up over email. It sits alongside those habits, reinforcing the same trust the whole closing process depends on, not instead of them.
Get a straight answer on how this is being handled: If nobody can say clearly who owns certificate renewal and monitoring for the business’s website and client portal, that’s worth finding out now, not after a lapse causes a problem during a live closing.
Loop this into vendor conversations, too: If a title company relies on any third-party platform for closings, portals, or document sharing, it’s worth asking that vendor the same question being asked internally. A gap in a vendor’s certificate management is just as real a risk as a gap in the business’s own.
Questions to Ask Your IT Team This Week
Ask your IT provider: what certificate are we using on our client-facing website and portal, and how is renewal being handled today?
Ask: would we actually know if a certificate was about to lapse, or would we find out when a client called to say the site looked broken?
Ask: does our wire fraud prevention process assume anything about how our website is secured, and does that assumption still hold under the new renewal schedule?
A quiet industry update like this one is easy to skim past, especially when the headline sounds like IT housekeeping. But “are we covered” is worth asking every time something like this crosses a desk, and the honest answer should always be more than a guess. This isn’t about panicking over a certificate schedule. It’s about making sure the infrastructure behind trusted communication gets the same proactive attention as the fraud prevention habits already in place, so the next time a client asks, the answer is already yes.
As always, remember that your Paradigm team is just a call, email, or text away for any questions or concerns that may arise.
If you’d like us to take a look at how your certificate renewal is being handled today, or just want a second set of eyes on your wire fraud prevention setup, we’re here to help. No pressure, no sales pitch — just an honest conversation about where you stand.
— Angie and Oscar
P.S. This update was highlighted in ALTA’s industry news [https://www.alta.org/news-and-publications/news/20260416-New-Certificate-Rules-Mean-More-Frequent-Renewals-for-Title-Companies]
Wire fraud prevention doesn’t stop at the certificate. Our piece on Ransomware Backup Recovery walks through what a real 72-hour recovery looks like when something does slip through. [Blog 7 — Ransomware Backup Recovery, or swap to the MFA Guide (Blog 8) if that’s a closer thematic fit]