Stephen,
I didn't know what nelreports.net was about until I started investigating myself, while everyone else in these and the other threads I've seen here are so focused on the {obviously} expired certificate that Bitdefender is detecting that they've ignored completely what it might actually be used for.
Since you don't know how threads here work, scroll to the bottom of the page and you'll find a listing of the other pages in the thread, preceded by the word 'Previous', with the current page number highlighted.
Simply click whichever of these you'd like to move through the thread, in this case press page number 2 and scroll down a few posts to see my previous post where I initially described my first guesses, then came back and added and 'EDIT' where I describe in more detail what I found out about NELReporting, its purpose and why I wouldn't be worried about whether this particular certificate was expired or not.
No, it wasn't immediately obvious what nelreports.net was for, nor any of these other details, but since I've been dealing with such issues myself both professionally and personally for decades, it simply takes a little time with search and other online tools to learn anything you want, since the web is inherently a map to everything it contains that any knowledgeable person can follow.
My post is a bit rambling, but I refer to keep the original musings as a record rather than remove them, since otherwise any later comments might also lose context.
Once you've read that you're free to come back and make your case for why you still feel this expired certificate situation is urgent, but as I stated it's only made so by a detection that virtually no other security app chooses to make, while even though it's expired, nothing appears to be failing for anyone else not using Bitdefender with MSEdge.
As for Bitdefender itself, its reputation for a 'feature' that added their own local certificate to allow Man-in-the-Middle operation to monitor the browser(s) SSL secure traffic, effectively removing all security for anything transmitted as a side effect, is well known to all security professionals and most long-term helpers in any security related forum as well. Though as I understand it this feature was at least removed as a default, I'd never trust an app that did this without warning.
Here's one Reddit thread that discussed this back when it was in effect, though the one I saw at the time was much larger and more involved, but you'll get the gist from these few posts.
Bitdefender Total Security hijacking browser's SSL connections - Acceptable practice? : r/AskNetsec
I simply see no need for any 3rd-party security with Windows Defender included free with Windows, that is unless you've got some sort of specialized need that this relatively simple to use product doesn't provide. For some reason people get religious (read; Mythology) about their security apps, though in many cases that trust is not well placed.
Rob