# Everything you need to know about the new 47-day certificate lifespan The SSL certificate validity period defines how long a certificate stays trusted before it must be renewed. This is now being cut dramatically. In August 2024, Apple [made a proposal](https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI?pli=1) (CA/Browser Forum Ballot SC-081v3) to drastically shorten the lifespan of certificates. This move was endorsed by major web browser makers and certificate authorities. After months of discussions, the move is now official. The CA/Browser Forum [unanimously voted](https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/9768xgUUfhQ) to bring down the certificate lifespan from 398 days to 47 days by 2029, with significant changes starting from March 2026. ## What is the SSL certificate validity period? The SSL certificate validity period is how long an SSL/TLS certificate stays trusted by browsers before you have to renew or replace it. This maximum validity is set by the CA/Browser Forum, a central body that lays the ground rules for the individual vendors who sell certificates. For a few years, the maximum SSL validity period stayed at 398 days. The new mandate has already brought it down to 200 days as of March 15, 2026, and it will keep dropping in stages until it reaches 47 days in 2029. So checking your SSL cert's validity period, and acting on it, is now something teams do several times a year instead of once. ## Key highlights of this announcement The move intends to strengthen the WebPKI system by significantly reducing the validity of all certificates issued by public certificate authorities and encouraging the adoption of [automation in certificate management](https://www.manageengine.com/key-manager/?reducedto47days). The gradual shift to short-lived certificates is already underway. Since March 2026, the maximum lifespan has been capped at 200 days, and it keeps shrinking from here. Alongside the validity changes, the domain control validation (DCV) reuse period is dropping on the same schedule, from 398 days down to 10 days by 2029. Here's an overview of the changes and the timeline involved: | Maximum certificate lifespan | DCV reuse period | Change in effect from | |---|---|---| | 398 days | 398 days | Valid until Mar. 14, 2026 | | 200 days | 200 days | In effect now - From Mar. 15, 2026 | | 100 days | 100 days | Mar. 15, 2027 | | 47 days | 10 days | Mar. 15, 2029 | ### SSL/TLS Certificate Maximum Validity Timeline The chart below shows how the maximum SSL certificate validity period shrinks at each CA/Browser Forum deadline, dropping from 398 days to 47 days between 2026 and 2029. ![SSL certificate validity period timeline: 398 to 47 days, 2026—2029](https://cdn.manageengine.com/sites/meweb/images/key-manager/ssl-certificate-maximum-validity-timeline.svg) ## The significance of this announcement While this does seem to be a drastic change, this has been in the works for a while now. Google proposed a 90-day certificate lifespan back in 2023; Apple's recent proposal only took things a little further. Nonetheless, organizations will have to deal with the reality and the significance of this move now. So, what changes? ### Prepare for frequent renewals What was just a consideration not too long ago is now a mandate that's already in force. Since Mar. 15, 2026, organizations have had to renew their certificates a minimum of two times per year, and it only gets progressively more challenging from here. | Timeline | Minimum number of renewals per year | |---|---| | Until March 2026 | ~ Once | | From Mar. 15, 2026 | ~ Twice | | Mar. 15, 2027 | ~ Four times | | Mar. 15, 2029 | ~ Eight times | ### Embrace automation Along with this change, the DCV reuse period is also shrinking to just about 10 days by Mar. 15, 2029. This means organizations will have to go through the full validation process, validating their domain or IP address a lot more frequently. Given the increasing frequency of DCV and the overall shortened lifespan of TLS certificates, automation will become even more critical for managing certificates efficiently and avoiding downtime. ### No change in costs Despite the increasing frequency of renewals, the cost spent on certificates should still remain the same. Several certificate authorities offer single- or multi-year coverage for certificates and renew (reissue) them at no additional cost. This means you only pay for the coverage period. ### Timeline of Key SSL/TLS Validity Proposals and Ballots ![Timeline of key SSL validity period proposals and CA/Browser Forum ballots](https://www.manageengine.com/key-manager/images/timeline-of-key-ssl-validity-proposals-ballots.svg) ## Why is the certificate validity coming down? If you're wondering why this is even happening in the first place, it is to ensure that the WebPKI is safeguarded and automation is embraced to make the whole process efficient and seamless. ### Better security The primary driver for this change is to enhance online security by reducing the window of opportunity for threat actors to exploit compromised certificates and private keys. Shorter certificate lifetimes limit the duration a compromised private key can be misused by an attacker during attacks like manipulator-in-the-middle, minimizing the potential damage. ### Adoption of best practices To adapt to a world where eight certificate renewals a year will be the norm, organizations must embrace automated certificate management in the form of ACME to reduce human error and minimize downtime. This transition will not only make life easier but also inculcate large-scale certificate management best practices. ### Minimize reliance on revocation mechanisms Default revocation checks have inherent issues, such as update delays in certificate revocation lists or OCSP responses, inconsistent enforcement where clients might "soft-fail" and accept certificates despite failed checks, and network blockages that prevent access to revocation servers. Shorter validity alleviates the need to rely solely on such mechanisms and can act as a reliable failsafe option. ### Frequent revalidation The CA/B Forum argues that the information in certificates becomes less trustworthy over time, and more frequent revalidation is necessary to maintain accuracy. By reducing the maximum certificate lifespan to 47 days, the [Baseline Requirements](https://cabforum.org/working-groups/server/baseline-requirements/documents/) would inherently force subscribers to undergo this validation process more often, leading to higher assurance for relying parties that the entity presenting the certificate currently controls the domain. ### Move towards crypto agility Manual certificate management will soon become obsolete given the frequency of certificate updates. As organizations strengthen their automation systems and such solutions become the norm, the ecosystem will become more agile in responding to future cryptographic vulnerabilities. Crypto agility will ensure frequent and hassle-free transitions to new algorithms, faster key rotation, and better management, all of which are vital in a post-quantum world. ## Impacts of adapting to a shorter certificate lifespans Needless to say, this move will have significant impacts on organizations, especially the ones that rely on manual certificate management practices. ### Increased workload IT, security, public key infrastructure (PKI), DevOps, and application teams, as well as any other team that deals with certificates, will face a substantially increased workload. ### Unexpected outages Organizations with a large number of publicly facing websites and systems relying on TLS certificates could increasingly run into service disruptions and unexpected outages. ### Change management implications Existing change management processes for certificate renewals will need to be adapted to handle the much higher volume and frequency of certificate renewals. ## Preparing for the new 47-day TLS certificate validity period The reduction of TLS certificate validity to 47 days by 2029 represents a significant shift to say the least. Organizations must start today and proactively plan and implement automation strategies to manage this change effectively. ### 01. Start with policies Establishing clear PKI policies is the first step. Without internal clarity, any technology change could turn chaotic. By taking full ownership of governing digital certificates and their life cycle the right way, you can assign roles and actions accordingly within your organization. ### 02. Audit your environment Without knowing all the [TLS/SSL certificates](https://www.manageengine.com/key-manager/information-center/what-is-ssl-certificate.html?reducedto47days) employed in your organization, the transition to short-lived certificates could be a nightmare. Start by accounting for every single certificate managed across your enterprise and manage them from a central certificate repository. ### 03. Alerts and monitoring Set up real-time monitoring to check for certificate expiry and ensure timely alerts are in place. This is just as crucial as having a certificate inventory. ### 04. Automation is your friend Even the two renewals a year that came in with the March 2026 cap raise the likelihood of outages and administrative overhead, and the cadence only tightens from here. Get ahead of the next phase by adopting [certificate life cycle management solutions](https://www.manageengine.com/key-manager/?reducedto47days). They automate every step of PKI management, from discovery and issuance to renewal and provisioning. ### 05. Utilize the ACME protocol Although gaps may exist, the [Automated Certificate Management Environment (ACME)](https://www.manageengine.com/key-manager/what-is-automated-certificate-management-environment-acme.html?reducedto47days) protocol powers the automated management of certificates. Implement the ACME protocol to streamline the issuance and renewal of certificates from various certificate authorities. ### 06. Integrate with your ecosystem Expand automation further and integrate certificate management into DevOps pipelines to ensure certificates are handled efficiently as part of the software development and deployment processes. ### 07. Bring everyone on board There's nothing like having every crucial department on board when adhering to the new mandate. Efforts from everyone on IT, security DevOps, PKI, and application teams as well as other teams is vital. Educate personnel on the importance of this move to make the transition smooth. ## FAQs ### What is the SSL certificate validity period? It's how long an SSL/TLS certificate stays valid and trusted by browsers before it has to be renewed. The CA/Browser Forum defines it, and it applies to every certificate a public certificate authority issues. ### What is the current SSL certificate validity period? Since March 15, 2026, the maximum SSL validity period for public certificates is 200 days, down from 398. It drops to 100 days in March 2027 and to 47 days in March 2029. ### Why is the SSL validity period being reduced to 47 days? Shorter validity periods cut how long a compromised certificate or private key can be abused, and they lean less on revocation checks like CRLs and OCSP, which don't always work reliably. They also push teams toward automation and crypto-agility before post-quantum cryptography arrives. ### What will the SSL certificate validity period be in 2027 and 2029? It drops to 100 days on March 15, 2027, then to 47 days on March 15, 2029. The domain control validation (DCV) reuse period falls to 10 days by 2029, so you'll revalidate domains far more often too. ### How do I manage shorter SSL validity periods without downtime? Automate the certificate lifecycle. ManageEngine Key Manager Plus discovers your certificates, renews them, and deploys them for you, supports the ACME protocol, and works with every major public CA, so frequent renewals don't turn into manual tracking or surprise outages. ### Will my existing SSL certificates be revoked when the rules change? No. Certificates you've already issued stay valid until they expire. The new limits only apply to certificates issued on or after each deadline, so you'll meet the shorter validity periods at your next renewal.