The 47-day deadline
Certificate lifetimes are collapsing. Here is why - and why it will not wait.
For a decade, the maximum life of a public TLS certificate has been falling. In April 2025 the CA/Browser Forum locked in a schedule that takes it to 47 days by 2029 - close to a monthly renewal for every certificate you run. This is the change that turns certificate tracking from a once-a-year chore into a standing operational job.
A decade of shrinking - and it is accelerating
Each step below was a deliberate decision by the browser and certificate-authority industry. The line only goes one way, and the drops are getting bigger and closer together.
Maximum lifetime of a publicly-trusted TLS certificate, on a logarithmic scale. The dotted step is Let’s Encrypt’s 6-day certificate - off the mandate, and already available now for fully-automated setups.
The schedule, in four steps
One ballot — CA/Browser Forum SC-081v3, passed April 2025 with every browser voting yes — sets two clocks running down together: how long a certificate may live, and how long the proof that you control the domain may be reused.
What it does to your workload
The renewal count is just arithmetic: an estate renews every certificate once per lifetime, so as the lifetime falls, the same estate renews far more often. Put your own number in.
A working estimate: one certificate per name, each renewed at the maximum lifetime allowed. Wildcard and multi-name (SAN) certificates lower the count; short-lived automation raises it. The direction does not change.
Why the industry decided this
Shorter certificates are not busywork. The forum gave six reasons, and they are the same reasons a security-minded team would choose short lifetimes on its own.
Revocation never really worked
When a certificate goes bad, it is supposed to be revoked — but the mechanisms for that (CRL, OCSP) are slow, often skipped, and quietly fail. A short lifetime is the backstop that actually holds: the certificate simply expires before revocation would have mattered.
A smaller blast radius
A stolen private key or a mis-issued certificate is dangerous only until it expires. Cutting the window to 47 days caps how long any single compromise can be used against you.
Claims that stay true
A certificate is a statement about a moment in time — who owns a name, which key is theirs. The shorter it lives, the less chance those facts have gone stale while it is still trusted.
Crypto agility
When an algorithm weakens — or post-quantum forces a change — a fleet of 47-day certificates rolls over to stronger cryptography in weeks, not the years a long-lived fleet takes.
Fresher proof of control
Domain-control validation is re-checked far more often, so certificates track who genuinely controls a name today, not who controlled it two years ago.
Automation, on purpose
If you can replace a certificate every 47 days without an outage, you can also replace one in an emergency. The schedule forces every organisation to build the muscle it would need anyway.
The renewals multiply. The room for error multiplies with them.
SSLScan is built for exactly this window. It keeps a live inventory of every certificate you have — including the subdomains you never entered — grades each one for posture, and shows a forward timeline of what breaks next. A shorter clock stops meaning more surprises.
The clock is already running. Start with what you can see.
One domain, one minute, no card required.