The 47-day deadline

Certificate lifetimes are collapsing. Here is why - and why it will not wait.

For a decade, the maximum life of a public TLS certificate has been falling. In April 2025 the CA/Browser Forum locked in a schedule that takes it to 47 days by 2029 - close to a monthly renewal for every certificate you run. This is the change that turns certificate tracking from a once-a-year chore into a standing operational job.

A decade of shrinking - and it is accelerating

Each step below was a deliberate decision by the browser and certificate-authority industry. The line only goes one way, and the drops are getting bigger and closer together.

5 years 2012 39 months 2015 825 days 2018 398 days 2020 200 days 2026 Today 100 days 2027 47 days 2029 6 days Let’s Encrypt 398 days 2020 200 days 2026 Today 100 days 2027 47 days 2029 6 days Let’s Encrypt

Maximum lifetime of a publicly-trusted TLS certificate, on a logarithmic scale. The dotted step is Let’s Encrypt’s 6-day certificate - off the mandate, and already available now for fully-automated setups.

And it goes shorter still. The mandate sets the maximum. Let’s Encrypt began issuing 6-day certificates in 2026 for anyone who wants to automate all the way down - a preview of where the whole web is heading.

The schedule, in four steps

One ballot — CA/Browser Forum SC-081v3, passed April 2025 with every browser voting yes — sets two clocks running down together: how long a certificate may live, and how long the proof that you control the domain may be reused.

398days
Through 14 Mar 2026
The limit for most of the past decade.
Validation reuse: 398 days
200days
From 15 Mar 2026 · in effect now
Already cut by more than half.
Validation reuse: 200 days
100days
From 15 Mar 2027
Roughly quarterly, for everything.
Validation reuse: 100 days
47days
From 15 Mar 2029
A renewal about every six weeks.
Validation reuse: 10 days
The second clock is the quiet one. Domain-control validation — the check that proves a name is yours — drops from 398 days of reuse to just 10. By 2029 almost every renewal re-proves control from scratch, so anything manual in that step has to go.

What it does to your workload

The renewal count is just arithmetic: an estate renews every certificate once per lifetime, so as the lifetime falls, the same estate renews far more often. Put your own number in.

A working estimate: one certificate per name, each renewed at the maximum lifetime allowed. Wildcard and multi-name (SAN) certificates lower the count; short-lived automation raises it. The direction does not change.

Why the industry decided this

Shorter certificates are not busywork. The forum gave six reasons, and they are the same reasons a security-minded team would choose short lifetimes on its own.

Revocation never really worked

When a certificate goes bad, it is supposed to be revoked — but the mechanisms for that (CRL, OCSP) are slow, often skipped, and quietly fail. A short lifetime is the backstop that actually holds: the certificate simply expires before revocation would have mattered.

A smaller blast radius

A stolen private key or a mis-issued certificate is dangerous only until it expires. Cutting the window to 47 days caps how long any single compromise can be used against you.

Claims that stay true

A certificate is a statement about a moment in time — who owns a name, which key is theirs. The shorter it lives, the less chance those facts have gone stale while it is still trusted.

Crypto agility

When an algorithm weakens — or post-quantum forces a change — a fleet of 47-day certificates rolls over to stronger cryptography in weeks, not the years a long-lived fleet takes.

Fresher proof of control

Domain-control validation is re-checked far more often, so certificates track who genuinely controls a name today, not who controlled it two years ago.

Automation, on purpose

If you can replace a certificate every 47 days without an outage, you can also replace one in an emergency. The schedule forces every organisation to build the muscle it would need anyway.

The renewals multiply. The room for error multiplies with them.

Eight times the renewalsAn estate that renewed once a year on 398-day certificates renews roughly eight times a year at 47 days — the same names, far more often.
The spreadsheet stops workingA calendar reminder and a shared sheet survive one renewal a year. They do not survive one every six weeks, across an estate nobody has fully counted.
You cannot renew what you forgot you haveThe certificate that takes you down is usually on a subdomain nobody remembered. More renewals means more chances for a forgotten one to lapse.
Every renewal is a fresh chance to breakA wrong chain, a missing SAN, a weak key, a deprecated protocol — each renewal can introduce them. More renewals, more surface for mistakes.

SSLScan is built for exactly this window. It keeps a live inventory of every certificate you have — including the subdomains you never entered — grades each one for posture, and shows a forward timeline of what breaks next. A shorter clock stops meaning more surprises.

The clock is already running. Start with what you can see.

One domain, one minute, no card required.