365
Avg certificate duration
Days from issuance to expiry
3814
Certs expiring next 6 months
From dataset date of July 2, 2026
75%
Renew before expiry
Early or on-time renewals
25%
Renew late (after expiry)
Gap in logo display occurs

Section 01

The BIMI Certificate Lifecycle

A BIMI certificate has a fixed validity period — almost always 13 months (396 days) or exactly 12 months (365 days). The certificate is technically valid until its Not After date. On that date, the BIMI DNS lookup fails validation, and the verified logo stops appearing in recipient inboxes immediately — not gradually, not partially. It disappears.

The lifecycle has four distinct phases, each with different operational priorities:

Active
Issuance to 60 days before expiry. Certificate is valid. Logo displays across all supporting mailbox providers. No action required. Ideal time to audit SVG file, DMARC policy, and DNS records to ensure they remain aligned.
Renewal window
60 days before expiry. Begin renewal process. A new certificate can be issued and staged before the current one expires — ensuring zero logo gap at transition. Most CAs complete issuance within 1–5 business days; allow more time for any SVG or trademark re-verification.
Critical
14 days before expiry to expiry date. If renewal has not started, start immediately. Emergency reissuance is possible but creates operational risk. Any DNS propagation delay or CA processing delay results in a gap period.
Lapsed
After expiry without renewal. Logo disappears from inboxes. The BIMI DNS record remains but validation fails. Reissuance restores the logo after DNS propagation (typically 24–48 hours after the new cert is published). The longer the lapse, the greater the cumulative impression loss.

Section 02

Renewal Timing: What the Data Shows

Across 5008 multi-certificate domains in this dataset, renewal timing breaks into three patterns. Early renewal (new cert issued more than 30 days before the old one expires) accounts for 38% of all renewals. On-time renewal (within 14 days of expiry) accounts for 37%. Late renewal (after expiry, within 90 days) accounts for 25%.

That 25% late renewal rate means roughly 1 in 4 organisations experiences at least some logo-gap period at each renewal cycle. For high-frequency senders — a bank sending daily statements, a retailer running continuous campaigns — that gap has measurable impact on inbox trust signals.

Renewal timing distribution across all multi-cert domains
How organisations time their certificate renewal relative to expiry

Certificates — Early (>30d before expiry): 3564; On-time (0–30d before): 3485; Late (after expiry): 2327
The gap cost

A 7-day logo gap on a sender with 1 million weekly email sends means approximately 1 million inbox views without the verified mark. For brands using BIMI as a customer trust signal in transactional email — banking alerts, order confirmations, healthcare communications — that absence is visible to recipients even if they cannot articulate why the email “looks different.”

Section 03

Upcoming Expiry Volume: The Next 12 Months

3814 certificates in this dataset expire between May 2026 and November 2026. A further 4160 expire between December 2026 and May 2027. The combined 7974 expiries over the next 12 months represent 39.4% of all active certificates — the largest renewal wave the BIMI market has faced.

BIMI certificates expiring by month — June 2026 to May 2027
Each bar represents the number of certificates reaching their Not After date in that month

Certificates expiring — Jun 26: 572; Jul 26: 576; Aug 26: 548; Sep 26: 698; Oct 26: 757; Nov 26: 635; Dec 26: 600; Jan 27: 584; Feb 27: 623; Mar 27: 820; Apr 27: 697; May 27: 668
SectorExpiring next 6 monthsAction priority
Technology/SaaS1024High — largest volume
Banking/Financial652High — customer trust impact
Retail/Ecommerce604Medium
Healthcare206High — patient trust sensitivity
Media/Publishing83Medium
Energy/Utilities73Medium

Section 04

Multi-Domain Portfolio Management

1663 organisations in this dataset hold 3 or more BIMI certificates. Condé Nast holds 238. eBay holds 54. Air Canada holds 38. For these organisations, BIMI lifecycle management is a programme, not a task.

The core challenge in multi-domain portfolios is staggered expiry dates. Certificates issued across different domains at different times expire at different times. Without active tracking, the first sign of an expiry is a customer complaint or an internal audit flagging a missing logo — both avoidable with a simple expiry register.

  • 📋
    Build an expiry register. Domain, certificate serial number, Not After date, responsible owner, CA name. Review monthly. Flag anything within 60 days for action.
  • 🔔
    Set calendar reminders at 60 days and 30 days. Most CAs send renewal reminders, but these go to the certificate contact email — which may not be the person responsible for BIMI. Internal reminders are more reliable.
  • 🔄
    Stage renewals before expiry. Issue the new certificate while the old one is still valid. Update the BIMI DNS record. Confirm the new cert is live before the old one expires. Allow 48 hours for DNS propagation before the old cert expires.
  • 🏗
    Standardise on one CA where possible. Multi-CA portfolios (common in post-merger organisations) create operational complexity. Migrating to a single CA simplifies renewal scheduling, billing, and support escalation paths.
  • Audit for Entrust certificates immediately. Entrust was publicly distrusted by Google Chrome and Mozilla Firefox in November 2024, ending new certificate issuance. Any Entrust-issued BIMI certificate in your portfolio requires migration planning. Waiting until expiry means an unplanned forced migration under time pressure.

FAQ

Common Lifecycle Questions

What happens to my BIMI logo the moment a certificate expires?

It stops displaying immediately. Mailbox providers validate the certificate on each lookup — there is no grace period. The DNS record remains but the validation check fails.

Can I renew early without losing the remaining validity on the current cert?

Yes. Issuing a new certificate early simply gives you a new validity period starting from the new issuance date. The old certificate remains valid until its expiry. You update the DNS record to the new cert when you're ready — typically a few days before the old one expires.

Does the SVG logo file need to be re-submitted at renewal?

Generally no, if the logo has not changed. However, CAs may re-verify that the SVG meets current Tiny P/S requirements as part of the renewal process. Confirm with your CA what documentation is required for renewal vs fresh issuance.

How do I find out when my current BIMI certificate expires?

The expiry date is embedded in the certificate itself. It is also visible in CT log lookups. Your CA's certificate management portal should show the expiry date directly. For a quick check, VMCcerts can audit your domain's BIMI certificate status on request.
Let us manage your certificate lifecycle
VMCcerts tracks expiry dates, sends renewal reminders, handles reissuance, and updates DNS — so you never experience a logo gap. Particularly valuable for multi-domain enterprise portfolios.
Cite This Report



VMCcerts Research. (2026). BIMI Certificate Lifecycle Management Guide 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/bimi-certificate-lifecycle-renewal-2026
VMCcerts Research. “BIMI Certificate Lifecycle Management Guide 2026.” VMCcerts, 2026, https://vmccerts.com/research/bimi-certificate-lifecycle-renewal-2026.
@techreport{vmccerts2026BIMILifecycle,
author = {VMCcerts Research},
title = {BIMI Certificate Lifecycle Management Guide 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/bimi-certificate-lifecycle-renewal-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – BIMI Certificate Lifecycle Management Guide 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/bimi-certificate-lifecycle-renewal-2026
ER –