CA/Browser Forum decided to gradually shorten the SSL/TLS certificate validity period in a historic vote that determined the future of internet security. As of March 15, 2026, the maximum certificate life decreased from 398 days to 200 days, and this is just the beginning — it will drop to 100 days on March 15, 2027 and to 47 days in 2029.
This article comprehensively explains all the details of the change, its timeline, why it is being made, and how you should prepare now.
What is CA/Browser Forum and Why is This Decision Important?
CA/Browser Forum is an industry consortium of worldwide certificate authorities (DigiCert, Sectigo, GlobalSign, etc.) and browser manufacturers (Google, Apple, Mozilla, Microsoft). It determines the standards, verification policies and security rules of SSL/TLS certificates.
The decisions this organization makes directly impact billions of HTTPS connections on the internet. With the vote completed in April 2025, SC-081 ballot (Certificate Life Reduction) was accepted and a historical transformation began.
Certificate Expiration Change Timeline
The new regulation is being implemented gradually, not all at once:
| Effective Date | Max. Certificate Lifetime | Max. DCV Duration | Change |
|---|---|---|---|
| Before March 15, 2026 | 398 days (~13 months) | 398 days | — |
| March 15, 2026 | 200 days (~6.5 months) | 200 days | ⬇️ 50% decrease |
| March 15, 2027 | 100 days (~3.3 months) | 100 days | ⬇️ 75% reduction |
| March 15, 2029 | 47 days (~1.5 months) | 10 days | ⬇️ 88% reduction |
Why Are Certificate Periods Getting Shorter?
There are strong security reasons behind this change:
1. Update of Certificate Information
SSL certificates contain domain ownership and organization information. Long validity periods mean that this information is not updated for months or even years. The domain may have changed hands, the company may have closed or the authorized person may have changed. Short periods ensure continuous verification of this information.
2. Vulnerability Window Narrowing
When a certificate is compromised or the private key is leaked, the risk continues until the certificate is revoked. OCSP and CRL mechanisms do not always work perfectly. Short-lived certificates inherently limit the time taken for interception.
3. Cryptographic Agility (Crypto Agility)
When new vulnerabilities are discovered or stronger algorithms are developed, the transition is much faster thanks to short-term certificates. Remember: The transition from SHA-1 to SHA-256 took years.
4. Post-Quantum Preparation
The potential of quantum computers to break existing encryption makes cryptographic agility critical. Short-term certificates will provide flexibility in the transition to post-quantum algorithms.
5. Automation Incentive
Browser manufacturers, especially Google and Apple, aim to fully automate certificate management. The success of Let's Encrypt proves that automatic certificate management is possible and efficient.
Historical Perspective: How Have Certification Periods Changed?
Certificate validity periods have constantly shortened over the years:
- Before 2012: 5-10 years
- 2012-2015: Maximum 5 years
- 2015-2018: Maximum 3 years (39 months)
- 2018-2020: Maximum 2 years (825 days)
- September 2020: Up to 398 days (~13 months) — led by Apple
- March 2026: Maximum 200 days (~6.5 months)
- March 2027: Maximum 100 days (~3.3 months)
- March 2029: Maximum 47 days (~1.5 months)
The trend is clear: The industry keeps shortening certificate lifetimes.
How Does This Change Affect You?
For Website Owners
- Certificate renewal will be required at least 2 times a year (2026), 4-8 times in the following years
- Manual renewal processes will no longer be sustainable
- The risk of site crashes due to certificate expiration will increase
- Transition to ACME protocol and automation tools will become increasingly necessary
For System Administrators
- Automation infrastructure must be established (Certbot, acme.sh, cert-manager)
- Certificate monitoring and alarm systems are a must
- Certificate renewal should be integrated into CI/CD pipelines
- DNS-01 or HTTP-01 challenge automation will be required
For Corporate IT Teams
- Manually managing hundreds/thousands of certificates will become impossible
- Certificate Lifecycle Management (CLM) platforms will gain importance
- Investment may be required in tools such as DigiCert CertCentral, Sectigo Certificate Manager
- Vendor lock-in risk should be evaluated
How Should You Prepare Now?
1. Take Out Your Certificate Inventory
List all SSL/TLS certificates in your organization. On which servers, in which domains, and from which CAs do you use certificates? This inventory will form the basis of your automation plan.
2. Check ACME Protocol Support
ACME (Automatic Certificate Management Environment) is an automatic certificate acquisition and renewal protocol. Make sure the CA you are using supports ACME. Major CAs such as DigiCert, Sectigo and GlobalSign support ACME.
3. Install Automation Tools
Test the tools suitable for your server and platform now:
- Linux: Certbot, acme.sh, dehydrated
- Kubernetes:cert-manager
- Windows/IIS: win-acme (WACS)
- Cloud: AWS ACM, Azure Key Vault, Google Cloud Certificate Manager
4. Set Up Monitoring and Alarms
Establish monitoring systems that will alert at least 30 days before the certificate expires. You can use tools such as Nagios, Zabbix, Prometheus or DataSSL SSL Checker.
5. Consider Multi-Year Plans
Multi-year SSL certificate plans are still valid and advantageous! When you purchase a multi-year plan, the price is locked, but the certificate is reissued within the plan term before each maximum validity period ends. You can both gain cost advantage and plan your automation period by purchasing multi-year plans through DataSSL.
What Do CAs (Certificate Authorities) Say?
Apple (Supported)
The real architect of this change is Apple. In its original proposal, Apple proposed to reduce the certificate life to 45 days, and as a result of the consensus, the current gradual schedule (47 days in 2029) was accepted.
Google (Strong Support)
Google has been advocating for shortening certification periods for years. Chrome's "Moving Forward, Together" initiative set a 90-day certificate life as a target.
DigiCert, Sectigo, GlobalSign
To adapt to this change, large commercial CAs are strengthening their ACME infrastructures and offering automation tools to their customers. The multi-year plan model will continue.
Let's Encrypt
Let's Encrypt already provides 90-day certificates and works with full automation. This change confirms their approach.
What Does It Mean When Domain Validation (DCV) Duration Reduced To 10 Days?
In 2029, not only the certificate life, but also the Domain Control Validation (DCV) validity period will decrease to 10 days. This means:
- Domain ownership verification will be done much more frequently
- DNS or HTTP challenge automation will become mandatory
- Manual email verification will practically disappear
- DNS operations will need to be managed via API
Frequently Asked Questions (FAQ)
Will my existing certificate be affected?
No. Certificates issued before March 15, 2026 can be used during their current validity period. The change only affects newly issued certificates.
Are multi-year plans invalid?
No! Multi-year plans are still valid. The price-lock benefit continues. The certificate is reissued free of charge within the plan term.
Is free SSL (Let's Encrypt) enough?
Let's Encrypt is readily available in terms of short certificate lifetime, but commercial SSL certificates will continue to be required for enterprise needs (OV/EV verification, warranty, support, wildcard facility).
Why are certificate periods 200, 100 and 47 days?
The 200-day period corresponds to a renewal cycle of about 6 months, 100 days to about 3 months, and 47 days to about 1 month, each with some buffer.
Conclusion: Automation is No Longer a Luxury, It's a Necessity
The shortening of SSL/TLS certificate durations is a positive development that strengthens internet security. However, this change means a paradigm change in certificate management:
- Manual renewal period is ending — Automation is a must
- Monitoring critical — Expiring certificate = crashed site
- The time to plan is now — the 200-day rule is in force, and the 100-day step in 2027 is approaching
As DataSSL, we support our customers during this transition process. We make your SSL certificate management easier with our multi-year certificate plans, free reissue during the certificate term, installation guides and support by phone, email and ticket.
Yorumlar
No comments yet. Be the first to comment!
Yorum Yaz