Why our certificates expire
A security certificate that never expires is a photo of a moving car. Here is why ours last 3 to 6 months, and why that helps you close deals.
You ship every week. The product we test on day one is not the product your customers use three months later. New endpoints, new integrations, a new AI feature someone wired up on a Friday.
So a certificate that says "tested" forever is not proof of anything. It is a photo of a moving car.
That is why every DXCL certificate has an expiry date. Here is the thinking behind it.
Fixing takes time, even for the worst bugs
Finding a vulnerability is the fast part. Fixing it properly is where the time goes.
Verizon's 2026 Data Breach Investigations Report found that exploiting vulnerabilities is now the most common way attackers get in, at 31% of breaches.1 The same report found that only 26% of the most dangerous known vulnerabilities, the ones on CISA's Known Exploited Vulnerabilities list, were fully fixed in 2025. The median time to fully fix one was 43 days.1
That is not because teams are careless. A client of any size might get a report with ten findings, three of them critical. Fixing even one critical issue can take days, depending on what else is on the roadmap and how the team works. We would rather say that out loud than pretend a report is the end of the story.
Buyers and investors are checking
The other reason is simple: people now ask.
In G2's 2026 buyer research, IT security review was the single biggest source of delay after a software vendor had been chosen. 39% of buyers named it, and half of enterprise buyers did.2 On the investment side, 84% of M&A advisers surveyed by SRS Acquiom expect more scrutiny of cybersecurity in due diligence over the next one to two years.3
When that question lands in your inbox, an old PDF does not answer it. A current, checkable record does.
How our certificate works
We built it around three ideas.
- One scope, one window. The certificate names exactly what we tested and when. Nothing more is implied.
- Validity set by what we found. It lasts 3 to 6 months from the day of the report. A team with a few low-severity findings and a quiet roadmap gets longer. A team with critical issues and a big release coming gets shorter. One fixed number would be wrong for one of them.
- Anyone can check it in seconds. Every certificate has a unique ID and a QR code. Your buyer or investor opens our Trust portal, and sees who it was issued to, the scope, the dates, and whether we have confirmed your fixes.
When it expires, a full retest renews it. That is the point: your assurance moves with your product.
What it is not
A DXCL certificate is a dated record of one engagement. It is not a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report, and it does not claim your system has no vulnerabilities. No honest test can claim that. It sits alongside those, and it is often what a buyer can check fastest.
Using it well
Put the certificate ID in your security questionnaire answers, your data room and your sales deck. Tell buyers they can verify it themselves. Then book the retest before it lapses, ideally before your next big release.
Expiry is not a weakness of the certificate. It is the feature that makes it worth trusting.
Sources
- Verizon, 2026 Data Breach Investigations Report, executive summary.
- G2, 2026 Buyer Behavior Report (1,038 B2B software decision-makers).
- SRS Acquiom with Mergermarket, M&A Due Diligence Study 2026 (150 senior US investment bank executives).