> The validity period for a certificate is the period of time from notBefore through notAfter, inclusive.
It says nothing about the comparison precision, just the storage format. It says CAs MUST encode validity dates as UTCTime / GeneralTime. It does not say this encoding must be used for comparison.
So I don't think it's actually defined if 2020-01-02 03:04:05.01Z is actually <= 2020-01-02 03:04:05Z.
That would mean this is not a 1 second-mistake but instead an infinitesimal mistake.
[1] https://datatracker.ietf.org/doc/html/rfc5280#section-4.1.2....