AutoSSL periodically checks eligible certificates and attempts renewal before expiration. Current cPanel documentation states that AutoSSL attempts to renew Let's Encrypt-issued certificates when they are within 29 days of expiration.
Renewal still requires successful domain-control validation. If DNS was changed, a hostname was removed, or validation is blocked, renewal can fail even though the existing certificate is still active.
Use SSL/TLS Status to watch expiration dates and AutoSSL results. Resolve renewal errors before the current certificate expires rather than waiting for the browser warning to appear.
The stated renewal window describes the documented Let’s Encrypt AutoSSL workflow, not every manually installed or other short-lived certificate. Check the installed certificate’s actual expiry and renewal result.
Documentation for this guidance: docs.cpanel.net — guide to ssl.