Skip to main content

SSL Certificate Validity Changes in 2026

Posted by UptimeObserver Team on April 3, 2026

Contents

If you’ve recently issued a new SSL/TLS certificate and noticed the expiration date is much sooner than expected, you aren’t alone. As of March 15, 2026, the industry has officially moved away from the 398-day (one-year) standard.

We have entered a phased “step-down” period mandated by the CA/Browser Forum (Ballot SC-081). This represents one of the biggest operational changes to public TLS certificate management in years. By 2029, certificates will expire in less than seven weeks.

The Roadmap: 200, 100, and 47 Days

The industry-wide transition follows a strict timeline. Each milestone reduces the “margin of error” for manual management:

Effective DateMax Certificate ValidityMax Domain Validation (DCV) Reuse
March 15, 2026 (Active Now)200 Days200 Days
March 15, 2027100 Days100 Days
March 15, 202947 Days10 Days

Although the final 47-day limit doesn’t arrive until 2029, organizations that wait until then to automate certificate management will likely find themselves under significant operational pressure.

Why the 47-Day Era Changes Everything

Timeline chart showing the reduction of TLS certificate validity from 5 years in 2015 to 47 days in 2029 Line chart showing the maximum allowed TLS certificate validity dropping from 5 years (1,825 days) in 2015 to 47 days in 2029, with the decline accelerating sharply in the 2026-2029 projections. 1,825d 1,350d 900d 450d 0d 2015 2016 2018 2020 2026 2027 2029 5 Years Historical 39 Months 2 Years Ballot 193 1 Year Apple Mandate 200 Days Ballot SC-081 Active 100 Days 47 Days TLS Certificate Validity Timeline (2015 – 2029) The industry-wide transition from multi-year certs to rapid rotation

Not long ago, managing SSL certificates was a low-maintenance chore. Prior to 2016, certificates could last up to five years, allowing teams to track renewals on a simple calendar or spreadsheet. However, the industry has been steadily tightening the window, dropping maximum validity to 39 months, then to 825 days (roughly two years) in 2018 via CA/Browser Forum Ballot 193, and finally to 398 days in September 2020 when Apple unilaterally forced the one-year standard. Now, as lifespans plummet toward 47 days, continuing to rely on manual tracking is a high-risk gamble for three reasons:

  1. The “Ghost” Outage: With 47-day lifespans coming in 2029, you will be renewing certificates ~8 times per year. If you manage 10 domains, that’s 80 potential points of failure annually.
  2. The DCV Crisis: By 2029, your Domain Control Validation (DCV), the proof that you own the site, will expire every 10 days. This means your automation must not only renew the cert but also successfully re-verify your domain ownership almost weekly.
  3. No More Safety Net: As we noted in our coverage of Let’s Encrypt ending expiration email alerts, the world’s largest CA is stepping back from manual notifications just as the frequency of renewals is exploding.

Why Are Browsers Forcing This? (The “Bygone SSL” Threat)

If you are frustrated by the rapid reduction in certificate lifespans, it helps to understand why Browser vendors, including Google, Apple, and Microsoft supported the change through the CA/Browser Forum process. They aren’t trying to make your life harder. they are trying to solve a massive vulnerability known as “Bygone SSL.”

When certificates lasted for 398 days (or years, historically), a major security flaw lingered in the background: domain transfers.

Imagine you own example.com and generate a certificate for it today. Next month, you sell that domain to someone else. The new owner controls the domain, but you still possess a valid, cryptographically sound TLS certificate for example.com that doesn’t expire for nearly a year. Security researchers discovered that millions of domains, including massive platforms like Stripe, had valid certificates floating around that were owned by previous registrants.

If an attacker also gains a position to impersonate the service (for example through DNS hijacking, BGP attacks, or other infrastructure compromise), an old but still-valid certificate significantly increases the opportunity for abuse.

The industry realized that certificate revocation systems (like CRLs and OCSP) are notoriously unreliable at scale. The only mathematically guaranteed way to kill these lingering certificates is to let them naturally expire. By shrinking validity down to 47 days, the window during which an outdated certificate remains usable is dramatically reduced.

The browser ecosystem is driving the internet to adopt automated, rapid rotation to ensure that if a domain changes hands, or if a private key is exposed, the window of vulnerability is closed in a matter of weeks, not years.

3 Steps to Prepare Your Infrastructure

As certificates get shorter, the “window for recovery” shrinks. With 47-day certificates, every failed renewal consumes a much larger percentage of the certificate’s lifetime. A problem that might once have gone unnoticed for weeks can now result in user-visible outages within days. This is now one of the 7 leading causes of downtime that is entirely preventable.

1. Audit Your “Manual” Debt

Any certificate still being handled via a manual CSR (Certificate Signing Request) is a ticking time bomb. You must transition to ACME (Automated Certificate Management Environment) protocols wherever possible. Use our Free SSL Expiry Checker to identify which of your current certificates are already on the new 200-day limit.

2. Transition to ACME Automation

The push toward 47-day validity isn’t just about defending against today’s security threats, it’s a forcing function to prepare the internet for the next era of cryptography.

Quantum computers are rapidly advancing, and a Cryptographically Relevant Quantum Computer (CRQC) will eventually be able to break current public-key encryption methods like RSA and Elliptic Curve Cryptography (ECC) using algorithms like Shor’s. The National Institute of Standards and Technology (NIST) has already released its finalized Post-Quantum Cryptography (PQC) standards, such as ML-KEM and ML-DSA, to replace these vulnerable protocols.

Over the coming years, many organizations will migrate to post-quantum or hybrid certificates as standards mature. If you are still managing certificates manually, transitioning to PQC will be a massive, year-long crisis of hunting down and replacing keys across every server, load balancer, and firewall.

By encouraging organizations to adopt automated Certificate Lifecycle Management (CLM) today, shorter certificate lifetimes also make future cryptographic migrations, including the move toward post-quantum certificates, far easier to execute.

3. Implement Third-Party Verification

Automation is critical, but it can fail. A broken DNS configuration, an expired token, or a server restart failure can prevent an automated script from applying a new certificate. You need an external SSL Certificate Monitoring service like UptimeObserver to verify that the outside world is actually seeing the updated certificate.

The Bottom Line

The shift to 47-day certificates is about Crypto-Agility. It forces the internet to be faster and more secure. But for the unprepared, it is an express lane to frequent outages.

The transition has already begun. If you still rely on manual certificate renewals, now is the time to automate renewals and independently monitor every certificate before shorter validity periods become the norm.

FAQ

Frequently Asked Questions

No. Any certificate issued before March 15, 2026, will remain valid until its original expiration date. However, the moment you renew or reissue that certificate, it will be capped at the new 200-day limit. By March 2027, that limit drops to 100 days.

The primary goal is security. Shorter lifespans reduce the "window of opportunity" for hackers to use a stolen private key. It also forces "crypto-agility," ensuring that if a new security vulnerability is found, the entire internet can rotate to new, secure keys within weeks rather than years.

Technically, yes, but it is no longer practical. In the 47-day era (starting 2029), you would need to manually prove domain ownership and install a new certificate every 6–7 weeks. This significantly increases the risk of human error, which is already one of the leading causes of website downtime.

No. These changes only apply to Publicly Trusted Certificates (those issued by CAs like Let's Encrypt, DigiCert, or Sectigo that browsers automatically trust). Certificates issued by a private, internal CA for corporate intranets can still have longer validity periods.

Most Certificate Authorities are moving to a Subscription Model. You will likely still pay for 1 or 2 years upfront, but the "technical" certificate will automatically swap out every 45–90 days in the background.

In the old "one-year" model, you had a long time to notice a failure. In the new 47-day model, your Domain Validation might only be valid for 10 days. If the automation fails, your site will show a security warning to users almost immediately.

As manual alerts from providers become less reliable you need an independent monitoring system. Our SSL Certificate Monitoring tool tracks your expiration dates 24/7 and alerts you via Slack, Email, or SMS the moment a renewal doesn't go as planned.

Monitor. Be alerted. Sleep easy.

Try UptimeObserver now. Setup in 2 minutes.