SaQura

Certificates & encryption

Certificates under control — before the deadlines force it.

A single forgotten certificate takes down a shop, portal or API — and the deadlines keep tightening: since March 2026 new TLS certificates are capped at 200 days, from March 2027 at 100. Here you'll find both: the overview of what runs where and when it expires — and the setup of automated renewal at a fixed price.

200 days

since 15 March 2026

100 days

from 15 March 2027

47 days

from 15 March 2029

The maximum lifetime of publicly trusted TLS certificates is dropping in fixed steps, set by industry ballot. Manual renewal simply doesn't scale any more.

And NIS2 demands the evidence

Germany's NIS2 implementation act has been in force since December 2025. Affected companies must present documented policies for the use of cryptography — and such a policy starts with knowing which encryption and which certificates are in use at all.

Three building blocks — depending on where you stand

Get the overview

SaQura Crypto Inventory

A scan on your own computer shows, within a day, every certificate with its expiry date and all encryption in use — as a clear report plus a technical inventory (CBOM). Reads only, sends nothing out.

Pro €5,900 / year — available to buy online

View product & buy

Monitor continuously

SaQura CertWatch

The watchdog on your own server checks your domains from the outside every day, warns you well before anything expires and proves it with sealed reports. Trial mode without a license for up to 3 addresses.

Self-host €1,290 / year — available to buy online

View product & download

Have renewal set up for you

Fixed-price service

We set up automated renewal in your environment (ACME — Let's Encrypt or your CA), configure expiry alerts and hand over the documentation. Fully remote, no downtime for your services, with 30 days of follow-up support.

S €2,900 · M €4,900 · L €8,900 — one-off, fixed price

Request automation

The product for continuous operation

SaQura CertWatch — on watch before anything fails.

The certificate watchdog for your own server: it checks your domains and services from the outside every day, warns you well before anything expires and proves — with sealed reports — that watch was kept. Runs entirely on your side; your monitoring data never leaves your house.

Warns before things fail

Alert levels 30/14/7/1 days before expiry (configurable), reminders until it's fixed — and the all-clear only once the new certificate is actually being served.

Checks more than the expiry date

Grades A–F with reasons in plain sentences: the certificate chain exactly as your server serves it, revocation status (OCSP/CRL), protocol and key quality — mail servers and arbitrary ports included.

Sealed reports

Every report carries a protocol number and a checksum from a continuous audit chain. Any auditor can recalculate the checksum independently — no CertWatch required.

No one has to log in

Alerts and reports arrive by e-mail (German, English, Japanese), expiry dates as a calendar subscription, and your systems connect via webhooks and a read API.

Tenants and your own brand

End customers with their own recipients and reports under your logo — built for IT service providers and MSPs.

Finds what was forgotten

Inventory discovery via the public certificate logs: suggests certificates of your domains nobody remembers — and reports when new ones appear.

Start without a license: trial mode monitors up to 3 addresses — download the package, set a password, try it.

Buy

Self-Host

€1,290/ year

Your server, your data

  • All checks, unlimited addresses
  • Sealed reports + continuous audit chain
  • Tenants, your own brand, webhooks, read API
  • License file by e-mail, updates during the term
  • Windows · macOS · Linux (systemd)

IT service providers & MSPs

On request

Many end customers, one watchdog

  • Tenants with their own recipients and reports
  • Reports under your brand
  • Terms per end customer
Get in touch

Annual subscription, renews automatically — cancellable to the end of each term. Prices excl. VAT.

Renew

CertWatch is an annual subscription: renewal happens automatically and the new license file arrives by e-mail every year — drop it into the settings, done. If a license runs out (for example after cancellation), CertWatch keeps watching for another 14 days and then stops its checks; your data is preserved. To reactivate, simply purchase again.

Download

Current version 1.0.1 — with license-free trial mode (up to 3 addresses). After downloading, compare the SHA-256 checksum:

Windows (10/11, 64-bit)

SaQura-CertWatch-Windows.zip · 50,2 MB

Download

SHA-256 acc2af6062226d03dacdbac0c1c7c6f96b14405b27e1c12895171ab1ebeaf40f

macOS (Apple silicon, macOS 12+)

SaQura-CertWatch-macOS.dmg · 47,4 MB

Download

SHA-256 11f1c034312127e1298f802154a6a407be810e067a895ab20135f4c047669165

Linux x86-64 (with systemd template)

SaQura-CertWatch-Linux.tar.gz · 43,4 MB

Download

SHA-256 42f0c9e72c9a214397f85ee6febb50417896625fdaa810ea5bbaab63fe66dff9

Linux arm64 (Graviton · Ampere · Raspberry Pi)

SaQura-CertWatch-Linux-arm64.tar.gz · 41,3 MB

Download

SHA-256 c2cb013b99635d8612a733d0fa3781dc1cfb4085891a17bbec5da1f6c986b468

Compute the checksum: macOS/Linux shasum -a 256 <file> · Windows certutil -hashfile <file> SHA256

Windows packages are signed (KyotoTech LLC, via Microsoft's signing service); the macOS package is notarized by Apple. Note on macOS: TLS 1.3 and revocation checks are limited by the system there, and it runs on Apple-silicon Macs only — macOS is fine for trying it out and for the desk; for continuous operation we recommend Linux or Windows.

How the setup works

Four steps, fully remote — no phone call, no project to set up.

1 · Pick a package, fill in the form

S, M or L — plus a short online form: which systems, which CA, how many certificates. Five minutes, no call.

2 · Fixed price confirmed in writing

Within one working day you receive scope, price and date in writing — before anything is touched. If it doesn't fit, nothing has happened.

3 · We set everything up

Via remote access — you only grant the access. A test run against the staging CA first, then the real switch; your services keep running throughout.

4 · Handover & follow-up

You receive the full documentation and configured expiry alerts. We're available for questions for 30 days.

Package sizes apply to standard systems (e.g. Linux web servers, IIS, Caddy). Systems without ACME support — such as appliances or load balancers — are documented and covered by expiry alerts; anything beyond that we clarify up front. Larger environments are planned individually.

Where do you stand right now?

Describe your situation in a few lines — you'll get a clear recommendation which building block is the right first step.

Get in touch

Lifetime steps per CA/Browser Forum ballot SC-081v3 (April 2025): max. 200 days since 15 Mar 2026, 100 days from 15 Mar 2027, 47 days from 15 Mar 2029; applies to publicly trusted TLS certificates. Germany's NIS2 implementation act in force since December 2025; Art. 21(2)(h) of the NIS2 Directive names policies and procedures regarding the use of cryptography and, where appropriate, encryption.