SSL/TLS certificates are getting shorter-lived, and this is a dated decision rather than a forecast. In April 2025 the CA/Browser Forum, which sets the rules for certificate authorities and browsers, adopted ballot SC-081v3 with no votes against. It reduces the maximum certificate lifetime to 47 days in three steps. The first step took effect on 15 March 2026.
What changes on which date?
| Issued | Maximum certificate lifetime | Domain validation reuse |
|---|---|---|
| Before 15 March 2026 | 398 days | 398 days |
| From 15 March 2026 | 200 days | 200 days |
| From 15 March 2027 | 100 days | 100 days |
| From 15 March 2029 | 47 days | 10 days |
The rule applies by the date a certificate is issued. A certificate issued earlier stays valid until it expires; it is not revoked.
The column most articles skip: validation reuse
Most coverage talks only about the certificate lifetime. The second column is what changes day-to-day work. Today, once you prove control of a domain, the certificate authority may reuse that proof for a set period, so a reissue needs no new DNS record or file upload. In 2029 that period drops to 10 days. In practice every renewal of a 47-day certificate will include a fresh domain validation.
For organization-validated (OV) and extended-validation (EV) certificates, the reuse period for organization details also fell from 825 to 398 days on 15 March 2026. Your organization documents are now re-verified roughly once a year.
Why 47 days?
The numbers are deliberate. 200 days maps to a six-month renewal rhythm, 100 days to a quarterly one and 47 days to a monthly one: the longest month (31 days), half a month (15 days) and one day of margin. The goals are that the information in a certificate stays current and that a compromised key is useful for a shorter time. Short-lived certificates also reduce reliance on revocation.
Why manual renewal stops working
A task done once a year will be done at least eight times a year in 2029. For an organization with ten domains that is eighty renewals and eighty validations a year. A process driven by calendar reminders will, at that frequency, eventually let a certificate expire, and visitors see a "your connection is not private" warning.
What to do now
- Build an inventory. Which certificate is on which server for which domain, and when does it expire? The certificate decoder shows the domains and expiry date of a certificate you hold.
- Choose a validation method that can be automated. Email validation needs a manual click. A DNS record or file-based validation can be scripted.
- Adopt ACME. ACME is the open protocol that lets a server request, validate and install certificates by itself. Paid DV, OV and EV certificates are available over ACME too; the Sectigo ACME subscription is one example.
- Add monitoring. Automation can break. A check that alerts 14 days before expiry catches silent failures.
- Generate the private key on the server. Moving keys around on every renewal is slow and risky.
What about multi-year purchases?
The certificate lifetime is shrinking, not the service period. At DATASSL you buy a certificate for 1, 2 or 3 years; each certificate is issued for at most 199 days and you reissue it free of charge from your panel for the whole service period. Reissue happens with your approval, and you choose the validation method. Current prices are on the price list.
In short
- 15 March 2026: 200 days (in force). 15 March 2027: 100 days. 15 March 2029: 47 days.
- In 2029 a domain validation can be reused for at most 10 days.
- Existing certificates remain valid until they expire.
- Preparation comes down to automation: inventory, scripted validation, ACME and monitoring.

Yorumlar
No comments yet. Be the first to comment!
Yorum Yaz