Guides · Understand your certificate

SSL certificates are getting shorter: 200, 100 and then 47 days

Last reviewed by a person on October 4, 2026

If you buy a certificate and install it once a year, that routine is ending. The browser makers and certificate authorities agreed to cut the maximum lifetime of publicly trusted TLS certificates in steps, down to 47 days. This guide explains the schedule, why it is happening and what to do about it.

The schedule

In April 2025 the CA/Browser Forum, the body that sets the rules, approved ballot SC-081v3. The maximum validity of a certificate issued from these dates:

  • Until March 14, 2026: 398 days (about 13 months)
  • From March 15, 2026: 200 days
  • From March 15, 2027: 100 days
  • From March 15, 2029: 47 days

These limits apply to newly issued certificates from publicly trusted authorities; a certificate issued earlier keeps its original lifetime. They do not apply to certificates from your own private CA. The rules also shorten how long a CA may reuse an earlier check that you control the domain, which means more frequent validation as well.

Why it is happening

  • Revocation is unreliable. If a key leaks, telling every browser to stop trusting the certificate does not work well in practice. A shorter lifetime limits how long a bad certificate stays valid.
  • Information goes stale. The company name or domain control checked when the certificate was issued may be a year out of date by the time it expires.
  • It pushes everyone to automate, which is the real fix for forgotten renewals.

What it means for you

  • Renewing by hand once a year stops working. At 100 days that is four renewals a year, at 47 days eight or more. That is not a chore anybody remembers.
  • Paid certificates are affected too, not just free ones: a certificate bought today can no longer be valid for more than 200 days, whatever you pay for it.
  • More renewals means more chances for one to fail, and automation fails quietly: a changed firewall, a moved DNS provider, a CAA record or an expired API token, as in Let's Encrypt renewal failed.
  • Some devices cannot be automated easily: appliances, old control panels, a vendor's hosted portal. Find them now.

What to do before it hurts

  1. List every certificate you depend on and how each one is renewed: automatically, by a person, or by "whoever did it last time".
  2. Automate with ACME wherever you can: certbot, acme.sh, Caddy, your host's built-in TLS, or a managed load balancer certificate. Test the renewal (--dry-run) instead of assuming it works.
  3. Make sure the new certificate is actually used. A reload after renewal is the step people forget (more on that).
  4. Watch from outside. A renewal job on the same server cannot tell you that the server stopped renewing. An independent daily check can.
  5. Check every name on the certificate, not only the main one. See SAN and wildcard certificates.

How CertAvert fits

Shorter certificates make monitoring more useful, not less. CertAvert checks your certificate every day from outside, emails you before it expires (30 days on Free; 30, 14 and 7 days on Starter and Pro, or days you choose; on a certificate shorter than 90 days the emails come at no more than a third of its lifetime, so a 47-day certificate warns at 15 days and normal renewals don't trigger alerts), and warns about a broken chain or a certificate that is not trusted. It also checks the names on your certificate, so a renewal that reached one server and missed another does not go unnoticed. Monitor a domain with CertAvert, or look at any certificate right now with the SSL/TLS checker.

Don't wait for the browser warning

Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.

Understand your certificate: more guides

All guides