A digital padlock with circuit patterns floats in front of blurred server racks, symbolizing cybersecurity and data protection. A logo labeled “AVOID-E” appears at the bottom center.
|||

SSL Certificates Validity Period: The Countdown to 47 Days

Businesses are in the middle of a security deadline they can’t ignore. SSL/TLS certificates, the digital credentials that keep websites encrypted and trusted by browsers, are shifting from year-long lifespans to windows measured in weeks. The SSL certificates validity period already dropped from 398 days to 200 days back in March 2026, and a new industry schedule will shrink that number further, down to just 47 days by 2029. This guide walks through the full timeline, explains why the change is happening, and lays out exactly what businesses should do to prepare for shorter SSL certificate lifespans, including how to handle wildcard certificates, private clouds, and complex international infrastructure.

Key Takeaways

  • Maximum certificate validity has already dropped from 398 days to 200 days as of March 2026, on its way to 47 days by 2029.

  • The CA/Browser Forum’s Ballot SC-081v3, approved in April 2025, drives this entire schedule.

  • Automation through the ACME protocol becomes mandatory, not optional, once cycles hit 100 days or less in March 2027.

  • Wildcard certificates, private clouds, and hybrid systems need special planning beyond simple auto-renewal.

  • NETK5 can review your infrastructure to confirm it’s ready for automated certificate renewal.

What Is the SSL Certificate 47-Day Rule?

Server room representing digital certificate infrastructure

The SSL certificate 47-day rule is the industry’s final target for how long a publicly trusted certificate can stay valid, replacing the 398-day maximum that applied until March 2026. In plain terms, an SSL/TLS certificate is a small file that proves a website’s identity and encrypts traffic between a server and a visitor’s browser, a process explained in this beginner’s guide to SSL certificate verification. As of March 15, 2026, that ceiling fell to 200 days, and it will keep falling under Ballot SC-081v3, approved by the CA/Browser Forum in April 2025 and backed by Apple, Google, Mozilla, DigiCert, and Sectigo.

The 47-day figure isn’t a random round number. It follows calendar-month math, working out to one full month plus half a month plus a single day of buffer. Google originally pushed for a 90-day maximum, but ultimately backed Apple’s more aggressive proposal once voting began. The result is a binding schedule that every public certificate authority must now follow, and the first phase of that schedule is already behind us.

How Will the SSL Certificate Validity Period Change Between Now and 2029?

Calendar pages symbolizing shrinking certificate renewal timeline

The SSL certificate validity period is falling in three scheduled drops between March 2026 and March 2029, moving from 398 days down to a final 47-day maximum. The first drop has already taken effect, and businesses are now operating under the 200-day ceiling. Each milestone also compresses how long domain validation data can be reused, which affects how quickly organizations must reconfirm ownership of their domains.

DateMax Certificate ValidityMax Domain Validation Reuse
Before March 15, 2026398 days398 days
March 15, 2026 to today200 days200 days
March 15, 2027100 days100 days
March 15, 202947 days10 days

There’s a separate rule worth flagging for organization-validated (OV) and extended-validation (EV) certificates. As of March 15, 2026, the reuse period for Subject Identity Information, meaning the company name and legal details behind a certificate, dropped from 825 days to 398 days. Domain-only certificates aren’t affected by this piece.

Let’s Encrypt, one of the largest certificate authorities in the world, runs its own parallel rollout. It plans to reach 45-day certificates by 2028, with the authorization reuse window (the time a domain check stays valid) shrinking to just 7 hours by that point. Anyone relying on Let’s Encrypt should expect renewal events far more often than they’re used to, and that shift is already underway.

Why Are SSL Certificate Lifespans Shrinking So Fast?

Cracked padlock representing certificate revocation vulnerabilities

SSL certificate lifespans are shrinking mainly because certificate revocation systems don’t work reliably, and shorter certificates limit the damage when something goes wrong. Certificate Revocation Lists and the Online Certificate Status Protocol were supposed to flag compromised certificates instantly, but many browsers ignore them for performance and privacy reasons, a gap explored in recent research on certificate revocation mechanisms. When a certificate’s validity is short, a stolen key or a bad issuance simply expires on its own within days or weeks, instead of remaining trusted for over a year, a safeguard highlighted in continuous SSL certificate monitoring research.

A second driver is data freshness. Domain ownership and company details can change quietly, so frequent revalidation keeps that information accurate. A third factor is preparation for post-quantum cryptography, the coming shift to encryption algorithms resistant to quantum computers, which will require organizations to rotate keys and certificates quickly and often. Taken together, these forces have already pushed automated certificate lifecycle management from a nice-to-have into an operational requirement, as the first compression phase now underway makes clear.

What Should Businesses Do to Prepare for Shorter Certificate Validity?

IT team reviewing infrastructure for certificate automation readiness

Businesses should prepare for shorter certificate validity by building a full certificate inventory, assigning clear ownership, and shifting to automated renewal through the ACME protocol before the next deadline hits in March 2027. The Automated Certificate Management Environment, or ACME, is the standard protocol behind tools that issue and renew certificates without human intervention. Pair it with ACME Renewal Information, a feature that tells your system precisely when to renew instead of guessing based on a fixed day count.

Concrete steps worth putting in place now include the following.

  • Build a complete inventory of every certificate in use, including who owns it, where it lives, and when it expires, so nothing gets missed once renewal cycles compress further.

  • Map out any manual steps still baked into your renewal process and replace them with ACME-based automation wherever possible, since misconfigured or non-compliant certificate chains are a documented source of outages, according to research on web PKI certificate chain compliance.

  • Assign clear accountability across IT, security, and DevOps teams, since ambiguous ownership tends to cause missed renewals in larger organizations.

  • Set up monitoring and alerts that flag certificates approaching expiration, acting as a safety net if automation fails.

Many SMEs and personal users simply rely on Let’s Encrypt and rarely think about certificate validity periods at all, so the drop from 90 days to 47 days won’t feel like a crisis for most of them. The challenge appears with more complex environments: wildcard certificates, private clouds, and multi-server architectures where auto-renew isn’t always practical. If that describes your infrastructure, letting NETK5 review your architecture for auto-renew compatibility is a far safer path than discovering the gaps during an outage.

类似文章