Infrastructure · 18 September 2026

Certificate renewal is about to become somebody's job

A change agreed in April 2025 begins landing this year. Anyone still renewing certificates by hand is about to find out how often.

On 11 April 2025 the CA/Browser Forum, the body that sets the rules every public certificate authority follows, passed ballot SC-081v3. It schedules a reduction in the maximum life of a public TLS certificate from 398 days to 47 days. The reductions begin in March 2026 and conclude in March 2029, stepping down in stages across that window.

The same ballot cuts how long a certificate authority may reuse the evidence that you control your own domain, from 398 days to 10.

What that actually changes

If your certificate renews itself, nothing. Automated issuance already runs on short lifetimes and shorter ones cost you nothing.

If somebody renews it by hand once a year, the arithmetic changes underneath them. A 47 day certificate needs replacing roughly eight times a year. A task that was an annual diary entry becomes a recurring operational duty, and the failure mode is not subtle: a browser refuses to load the site and tells every visitor it is not safe.

Who this catches

When we measured 95 companies in one industry, 8 were running certificates with a lifetime beyond 180 days. Those are the manually managed ones. The rest were on 90 day certificates that renew themselves, which is why a short remaining life on one of those is nothing to worry about and a short remaining life on a long certificate is.

That distinction matters more than it sounds. Plenty of monitoring tools will warn you that a certificate expires in three weeks. On an automated 90 day certificate that is routine. On a 397 day certificate it means a person has to do something, and the person in question usually does not know the certificate exists.

What to do

  • Find out whether your certificate is automated. A lifetime of about 90 days means it is. A lifetime near 398 days means it is not.
  • If it is not, move to an automated issuer before March 2029 rather than after. The work is the same either way and doing it early removes seven renewals.
  • Check every domain you own, not only the main one. Parked domains, campaign domains and the old company name all present certificates to somebody.

This is a small thing. It is on this blog because it is a small thing with a public failure mode, arriving on a schedule nobody outside the certificate industry has read.

Sources

  • CA/Browser Forum, Ballot SC-081v3 — passed 11 April 2025. Maximum validity from 398 days to 47 days, reductions starting March 2026 and concluding March 2029; domain validation data reuse from 398 days to 10 days. The stepped schedule itself sits in the Baseline Requirements rather than the announcement.
  • Our own measurement of 95 companies, 18 September 2026. Method in What we found on 95 company websites.

Worth two minutes

Open your site, click the padlock, and look at the issue and expiry dates. If they are about 90 days apart you can stop reading. If they are a year apart, somebody needs to own this.

See what else nobody owns

Next step

Let's structure your growth.

Ready to move from ad-hoc selling to systemic revenue generation? Let's identify where the engine is leaking opportunity — and build the system designed to fix it.

Randhir Manekar
Randhir ManekarSales & business development partner

Opens your email app with the message already written.