Guide · Updated daily

Managing Your Spanish Digital Certificate

Getting the certificado digital is the easy part. Keeping it alive across new laptops, forgotten passwords, expiry dates, a stolen phone, and a TIE renewal is where people lose access at the worst possible moment. This is the maintenance manual — every routine job, in order, checked against FNMT-RCM and Cl@ve.

A person at a home desk entering a password on a laptop beside a USB drive and a Spanish residence card
Updated September 22, 202616 min read13 sections

This guide is what worked for us and the people we've helped — it is not legal advice, and we are not legal professionals. Rules change, every situation is different, and the cost of getting it wrong (denied visas, double taxation, fines, missed deadlines) is real.

Before you act on anything here, speak with a qualified legal professional — an immigration lawyer (abogado de extranjería), a cross-border tax accountant, or a licensed gestor — who can review your specific facts. Use this guide to know what questions to ask, not as a substitute for paid advice.

If you have not obtained one yet, start with Getting Your Digital Certificate in Spain — this guide assumes the certificate already exists and is installed somewhere.

A certificado digital is not an account you log into. It is a key pair: a public certificate that identifies you, and a private key that only your machine holds. Nobody — not the FNMT, not Hacienda, not a gestor — can recover that private key for you. Everything below follows from that one fact.

The five jobs you will actually have to do, roughly in the order life throws them at you: change or recover the password on your exported backup file; move the certificate to a new computer or phone; renew it before it expires; revoke it if a laptop is lost or stolen; and clean out the expired copies that pile up in your browser and confuse every government site you visit.

The one rule that prevents all of the pain: the moment you have a working certificate, export it to a password-protected .p12 file, store that file and its password in two separate safe places, and test the restore once. A certificate that exists only inside one browser profile is one laptop failure away from a new in-person appointment.

A word about the word "password". Three different secrets get called the password, and mixing them up is the single most common cause of "my certificate stopped working". The next section untangles them.

1. The export / import password (the `.p12` password). You invent this yourself when you export the certificate to a .p12 or .pfx file. It protects that file and nothing else. It is only ever requested when you export, or when you import the file onto another device. This is the one you can change freely, because changing it just means re-exporting the file with a new password.

2. The browser or keystore master password. Firefox has its own Primary Password protecting its internal certificate store; Windows and macOS instead use your operating-system login and, on Mac, the Keychain password. This is a device-level secret, not a certificate secret. Changing your Mac login password or your Firefox primary password does not affect the certificate itself.

3. The Cl@ve Permanente password. Nothing to do with the certificate at all — it belongs to the separate Cl@ve login system. People routinely try to use it on the FNMT site and conclude their certificate is broken. It is not.

There is no password on the certificate itself. This surprises people. Once the certificate is installed in Windows, macOS or Firefox, any procedure that reaches that keystore can use it — typically protected only by your device login. That is precisely why a shared or unlocked laptop is a genuine risk: on an unlocked machine, your legal signature is one click away for whoever is sitting at it.

So "I forgot my certificate password" means one of two very different things. If you forgot the .p12 password but the certificate is still installed and working on a machine, you are fine — just export a fresh copy with a new password. If you forgot the .p12 password and the file is the only copy you have, the file is unrecoverable: there is no reset, and you must revoke and reissue.

You cannot edit the password inside an existing .p12 file. You re-export from a machine where the certificate is installed and working, choosing a new password, then destroy the old file. Ten minutes, start to finish.

On Windows. Press Win+R, run certmgr.msc, open Personal → Certificates, right-click your certificate → All Tasks → Export. Choose "Yes, export the private key" — if that option is greyed out, the private key is not on this machine and the export will be useless. Select the .pfx format, tick Include all certificates in the certification path, set your new password (choose AES-256 encryption if offered), and save.

On macOS. Open Keychain Access, select the login keychain, find the certificate under My Certificates, and confirm there is a small key entry nested underneath it — that is the private key. Right-click the certificate → Export, choose Personal Information Exchange (.p12), set the new password, and authorise with your Mac login when prompted.

In Firefox. Settings → Privacy & Security → Certificates → View Certificates → Your Certificates, select it, click Backup, save as .p12, and set the new password. Firefox keeps a store entirely separate from the operating system — a certificate visible in Chrome may be invisible here, and vice versa.

Choose the password properly. This file plus this password together are your legal identity in Spain. Use a generated passphrase from your password manager, store it in the same manager as a note attached to the file, and never reuse a password you use anywhere else.

Then delete the old exports. Search your Downloads folder, Desktop, email attachments and any cloud sync folder for .p12 and .pfx files and remove the stale ones. Old exports protected by an old password are a live liability, not a backup.

If you cannot export at all, the private key is missing on that machine — you are looking at a certificate someone installed public-key-only, or a profile that has been migrated badly. Nothing can be recovered from it. Revoke and reissue.

This is the most common maintenance job, and it is genuinely simple provided you exported a `.p12` while the old machine still worked. Migration assistants, Time Machine restores and "transfer my files" wizards frequently fail to carry the private key — do not rely on them.

Step 1 — export from the old machine using the instructions in the previous section. Do this before you wipe, sell or return the old laptop. If the old machine is already gone and you have no .p12, skip to the revocation section; there is no recovery path.

Step 2 — move the file safely. Use an encrypted USB drive, your password manager's file vault, or an end-to-end-encrypted transfer. Do not email it to yourself, do not drop it in a shared Drive folder, and do not send it over WhatsApp — the file and password in the same channel is the whole identity in one message.

Step 3 — import on the new machine. On Windows and macOS, double-click the .p12, enter the password, and accept the default store (on Mac, put it in the login keychain, never System). In Firefox, use View Certificates → Your Certificates → Import. If you use both Chrome and Firefox, you must import it in both places — Chrome and Edge read the system store, Firefox does not.

Step 4 — verify before you trust it. Go to the AEAT electronic office and log in with the certificate. If Hacienda greets you by name, the private key came across intact. Checking the certificate merely appears in a list proves nothing — a listing without a private key looks identical until the moment you need to sign.

Step 5 — clean up. Securely delete the .p12 from the Downloads folder of the new machine and from the USB drive. Keep the archived copy only in your password manager or encrypted vault.

Retiring the old laptop. If you are selling, returning or recycling it, remove the certificate from its keystore first (see the cleanup section below) and wipe the drive. If the machine is being handed to a family member, treat that as a compromise and revoke — convenience is not worth a live signature in someone else's hands.

You cannot request or download an FNMT certificate on a phone — key generation needs a desktop browser. But you can import an existing `.p12` onto a mobile device, and for day-to-day tasks that is often enough.

On Android, install the .p12 through Settings → Security → Encryption & credentials → Install a certificate → VPN & app user certificate. Chrome for Android will then offer it when a sede electrónica asks. Some government portals still refuse mobile browsers entirely.

On iOS, email or AirDrop the .p12 to yourself, open it to install the configuration profile, then finish in Settings → General → VPN & Device Management → Downloaded Profile. Safari can then present it. Support is patchy and varies by site.

Our honest recommendation: do not make a phone your primary access. Use Cl@ve PIN on mobile instead — it is designed for phones, works with an app or SMS code, and covers most routine AEAT and Seguridad Social tasks. Keep the certificate on a laptop for anything that requires a real signature.

If you do put it on a phone, set a device passcode and biometric lock, and add "revoke the certificate" to your mental list of things to do if the phone is stolen — not just "remote wipe".

The FNMT persona física software certificate is issued for a fixed validity period — currently four years — and renewal is only possible inside a window shortly before it expires, currently the last sixty days. The Latest Updates section above carries any change to those figures.

Inside the window, renewal is entirely online and takes about ten minutes. Go to the FNMT sede electrónica, choose Renovar, authenticate with your current valid certificate, and a new one is issued and downloaded on the spot. No appointment, no office, no code.

Outside the window — that is, one day after expiry — the online route closes. You are back to a fresh request, a código de solicitud, an in-person accreditation appointment, and whatever queue your city currently has. In Barcelona or Madrid that can be weeks. This is the single most expensive avoidable mistake in certificate management.

Set three reminders today: one at ninety days before expiry ("check the renewal window opens soon"), one at fifty days ("renew now"), and one at fifteen days ("renew today or book an appointment"). Put them in the calendar you actually read.

Find your expiry date in Windows certmgr.msc (the Expiration Date column), macOS Keychain Access (double-click the certificate, read Expires), or Firefox's certificate viewer. Do it now rather than assuming you remember the issue date.

Renew early, not late. There is no penalty for renewing on the first day of the window, and the new certificate simply starts a fresh term. Waiting adds risk and gains nothing.

After renewing, redo the maintenance: export a fresh .p12 with a new password, store it in both places, import it onto your second device, and delete the old expired certificate from every keystore. Skipping that last step is what produces the "which certificate do I pick?" dialog that breaks filings.

Revocation permanently cancels a certificate. Do it immediately, without waiting to see whether anything bad happens, in any of these cases: a laptop or phone holding the certificate is lost or stolen; a .p12 file or its password may have been seen by someone else; you sold, returned or recycled a device without wiping it; you shared the file with a gestor or colleague and the relationship ended; or you simply cannot account for every copy.

Why the urgency. Anything signed with your certificate is legally attributed to you — tax filings, contracts, company registrations, immigration submissions. A revoked certificate is inert the moment it is revoked, and unwinding a fraudulent submission afterwards is far harder than revoking early on a false alarm.

How to revoke. The FNMT sede electrónica has an Anular / Revocación option under the persona física menu. There are three routes: online with the certificate itself if it is still installed and working (fastest — do this before wiping a machine you are retiring); online with an identifying code using the data you registered with; or by telephone through the FNMT's revocation line, which exists precisely for the case where you no longer have access to anything. In a genuine theft, phone revocation is the right call.

Revocation is irreversible and it is not renewal. A revoked certificate can never be reactivated. You will need a completely new request, including a new código de solicitud and a new in-person accreditation — unless you happen to hold a second, separate valid certificate you can authenticate with.

Report the theft too. If a device was stolen, file a denuncia with the police. The report costs an hour and is the document that protects you if anything is later submitted in your name.

Then rebuild in this order: revoke → request a new certificate → book accreditation → install → export a new .p12 with a new password → import on the second device → re-enrol wherever you had the old one registered.

After two or three renewals, most people's keystores hold several certificates with the same name and different dates. Government sites then present a chooser, you pick an expired one, the site throws an unhelpful Spanish error, and you lose twenty minutes concluding your certificate is broken. It is not — it is clutter.

Windows. Run certmgr.msc, open Personal → Certificates, sort by Expiration Date, and delete anything already expired. Keep exactly one current certificate per person.

macOS. Keychain Access, login keychain, My Certificates. Expired entries show a red cross and "This certificate has expired". Right-click → Delete. Leave system and developer certificates alone.

Firefox. View Certificates → Your Certificates, select the old entry, click Delete. Firefox lists dates in its own column, so match carefully before deleting.

Delete, do not just ignore. An expired certificate left in place keeps appearing in the chooser forever, and on a shared or family machine an abandoned certificate is also an abandoned signature.

Before you delete anything, confirm the current one works. Log into the AEAT with the certificate you intend to keep, then remove the rest. Never clear the whole store hoping to start fresh — that destroys the private key of the one you actually need.

If two people share a computer, keep each person's certificate in their own operating-system user account. Two certificates in one profile means either person can sign as the other, and it is the fastest route to filing a return under the wrong name.

It is extremely common for a gestoría to ask you to send them your .p12 and its password. Do not do it. That is not delegation — it is handing over your legal signature with no record of who used it or when, and everything they submit is legally your act.

The correct mechanism is apoderamiento. Spain provides a formal representation register, the Registro Electrónico de Apoderamientos (REA), plus the AEAT's own apoderamiento register. You grant a named professional the right to carry out specific procedures on your behalf, using their certificate. You can see exactly what was granted, and you can revoke it in minutes without touching your own certificate.

How to grant it. Log into the AEAT sede electrónica with your certificate, find Apoderar y otorgar representación, enter the gestor's NIF, and select only the trámites they actually need — typically the quarterly filings. For non-tax procedures, use the general REA at the Punto de Acceso General. A gestoría can also register a poder signed before a notary, which is heavier but sometimes required.

Review your grants annually and revoke anyone you no longer work with. Apoderamientos quietly survive the end of a business relationship unless you cancel them.

Companies use a different certificate entirely. If you run an SL, the certificado de representante de persona jurídica is issued to the administrator for the company and is separate from your personal one, and unlike the individual certificate it carries a fee. Do not use your personal certificate for company filings, and do not let the gestor use it either.

What a gestor legitimately needs is the apoderamiento, your NIF, and your documents — never your private key. Any firm that insists otherwise is telling you something about how they handle every other client's identity. Our hiring a gestor guide covers what to expect from a good one.

A certificate is bound to the identity data it was issued against. When that data changes, the certificate can become invalid — sometimes silently, which is worse.

Renewing your TIE with the same NIE. Your NIE number normally stays the same for life, so the certificate usually continues to work. Verify anyway by logging into the AEAT after the new card arrives — five minutes now beats a failure on a deadline.

A changed NIE or a change of immigration status. If your identification number itself changes, the old certificate no longer matches the person it names. Revoke it and request a new one against the new number.

A legal name change — marriage, correction of a misspelling, adding a second surname — invalidates the match. Update your details with the administration first, then reissue the certificate so the name matches character for character, accents included.

Moving house within Spain does not affect the certificate at all. Update your empadronamiento and your AEAT address separately — see Empadronamiento in Spain.

Leaving Spain. If you keep any Spanish tax obligation — property, a Modelo 210, a pension — keep the certificate current, because renewal from abroad still works online inside the window and is impossible outside it. If you are closing everything down, revoke the certificate once your final filings are done.

Whichever of these happens, redo the backup afterwards. A new certificate means a new .p12, a new password, a new copy on the second device, and the old one deleted.

"The private key is not exportable" / the export option is greyed out. The key is not present on this machine, or it was imported without the exportable flag. You cannot fix this from the copy you have; use another device that works, or reissue.

The import asks for a password you never set. You are being asked for the .p12 password chosen at export time — by you, or by whoever exported it for you. If a gestor exported it, ask them. There is no bypass.

The certificate imported but no site offers it. Almost always a store mismatch: imported into Firefox but browsing in Chrome, or into the macOS System keychain instead of login. Import it into the store the browser you use actually reads.

"Certificado revocado" when it should be valid. Either it really was revoked, or a site is reading a stale revocation list. Check status with the FNMT's Comprobar estado del certificado tool before assuming the worst.

"Certificado caducado" and the renewal window has closed. There is no appeal. Request a new certificate and book accreditation immediately, and in the meantime file with Cl@ve PIN or through an apoderado gestor so you do not miss the deadline itself.

Autofirma hangs at "esperando a Autofirma". Reinstall the current Autofirma from firmaelectronica.gob.es, restart the browser, and allow the protocol handoff prompt. It is a signing-app problem, not a certificate problem.

A chooser appears with several identical-looking certificates. Clutter from previous renewals. Clean the store as described above, keeping only the current one.

Nothing works and a deadline is today. Two escapes, in order: file with Cl@ve PIN if you have a Spanish mobile and a registered NIE, or have an apoderado gestor file on your behalf with their own certificate. Fix the certificate afterwards, calmly.

Once a year — pick a date you will remember, such as the day you file your annual return — run this list. It takes about twenty minutes and prevents every emergency in this guide.

1. Check the expiry date and confirm your renewal reminders are still in the calendar. 2. Log into the AEAT with the certificate to prove it genuinely works, not just that it appears in a list.

3. Export a fresh password-protected .p12, and confirm both the file and its password are in your password manager. 4. Restore that backup onto your second device to prove the backup is real.

5. Delete expired certificates from Windows, macOS Keychain and Firefox, keeping exactly one current copy in each store you use. 6. Hunt down and securely delete stray .p12 files in Downloads, Desktop, email and cloud folders.

7. Review your apoderamientos at the AEAT and the REA, and revoke anyone you no longer work with. 8. Check your electronic notification inboxes (DEHú and the AEAT's own) are still enrolled and still emailing you.

9. Confirm your certificate's name and NIE still match your current documents after any TIE renewal or name change. 10. Make sure your partner has their own certificate and their own backup — they are personal and non-transferable.

Do that once a year and the certificate simply keeps working, which is the entire goal. Hit something this guide did not cover, or a Spanish error message you cannot decode? Contact us — we have moved ours between a Mac and a Windows machine, renewed it online, and cleaned up the mess afterwards.

Share this guide