# Everything you need to stay ahead of the 47-day SSL/TLS certificate validity mandate Phase one of the CA/Browser Forum's reduced certificate validity mandate is already live. By March 2029, public CA certificate renewal frequencies will be up to eight times higher. ## The phased timeline **47 days** Max certificate validity by 2029 **8x** Renewal frequency increase **10 days** Domain Control Validation (DCV) reuse period by 2029 On Mar. 15, 2026, the CA/Browser Forum's reduced certificate validity mandate officially took effect. Public SSL/TLS certificates can no longer be issued with a lifespan of more than 200 days—and this is only the first phase. By March 2029, the maximum certificate lifespan will drop to just 47 days. | Date | Phase | Maximum validity | Renewals/yr | DCV reuse | Status | |---|---|---|---|---|---| | Before Mar. 15, 2026 | Pre-mandate | 398 days | 0.9x | 398 days | Phased out | | Mar. 15, 2026 | Phase 1 | 200 days | 1.8x | 200 days | In effect | | Mar. 15, 2027 | Phase 2 | 100 days | 3.7x | 100 days | Up next | | Mar. 15, 2029 | Phase 3 | 47 days | 7.8x | 10 days | Approaching | ### Pre-mandate · 398 days Public SSL/TLS certificates could be issued with up to 398-day validity before Mar. 15, 2026. ### Phase 1 · 200 days The first phase of the mandate is now live, maximum validity of public SSL/TLS certificates is now 200 days. ### Phase 2 · 100 days Maximum lifespan halves again to 100 days, with renewal frequencies doubling. DCV reuse drops to 100 days. ### Phase 3 · 47 days Public SSL/TLS certificates drop to a 47-day maximum lifespan, with DCV reuse at just 10 days. Renewal frequency is up to eight times higher. [Read the complete explainer](https://www.manageengine.com/key-manager/ssl-tls-certificate-lifespan-reduced-to-47-days.html) ## Manage your certificate life cycles with Key Manager Plus The mandate effectively sets a minimum bar for certificate management. You need full visibility into every certificate in your environment, automatic renewal workflows that can handle a much higher frequency without manual effort, and deployment that gets the renewed certificate live at the target server along with the necessary post-deployment actions. Key Manager Plus covers all three of these facets. ### Automatic discovery Finds every certificate across your network, cloud environments, and CAs, giving you complete visibility without blind spots. ### End-to-end renewal automation Handles everything from CSR generation through issuance, so higher renewal frequencies don't translate to operational difficulties or service disruption. ### Automated deployment Pushes renewed certificates to your servers, load balancers, and cloud services, closing the gap between renewal and operational continuity. ### Post-deployment actions Automatically trigger the scripts, executables, and service restarts each server needs after deployment, making sure every renewal is complete and delivered end to end. [Learn how Key Manager Plus addresses each layer](https://www.manageengine.com/key-manager/certificate-life-cycle-management.html) ## Build your action plan Whether you're just starting to prepare for the mandate or are midway through implementation, these resources will help you build a structured, phased approach that allows you to stay ahead of the timeline. ### A step-by-step action plan ![Guide: Preparing for the 47-day SSL/TLS certificate life span](https://cdn.manageengine.com/sites/meweb/images/key-manager/47-day-mandate-hub-pdf-image.png) Access our phased guide covering discovery, inventory building, prioritization, automation setup, and validation. [Download the guide](https://www.manageengine.com/key-manager/47-day-tls-ssl-certificate-lifespan-guide.html) ### The expert walkthrough ![Webinar: Tackling the 47-day SSL/TLS certificate life span](https://cdn.manageengine.com/sites/meweb/images/key-manager/47-day-mandate-hub-pdf-video.png) Explore our step-by-step webinar walkthrough of a 90-day action plan, complete with hands-on guidance on what to do first, where to prioritize, and how to set up automation workflows. [Watch the webinar](https://www.manageengine.com/key-manager/47-day-ssl-tls-certificate-mandate.html)