IT AND SECURITY CLOUD AND MANAGED SERVICES CONSULTING SERVICES AND SUPPORT

Your SSL/TLS Certificates Are About to Get a Lot Shorter Shelf Life (Here's What to Do About It)

BY PROFESSIONAL ADVANTAGE - - 5 MINS READ

If you manage certificates in your organisation, mark this one down: the rules around how long your TLS/SSL certificates can stay valid are changing, and the timeline is shorter than most people expect.

The CA/Browser Forum, the industry body that sets the rules for how certificate authorities issue and manage certificates, has voted to adopt a new schedule that will steadily shorten certificate lifetimes over the next few years. By 2029, the certificates that once lasted well over a year will be valid for just 47 days.

If that number made you do a double take, you're not alone. Let's break down what is actually changing, why it's happening, and most importantly, what your team can do to stay ahead of it.

The New Certificate Lifetime Schedule

Here's the rollout, step by step:

  • Previously: TLS certificates can be issued for up to 398 days (just over a year).
  • From March 2026: Maximum lifetime drops to 200 days.
  • From March 2027: Down again to 100 days.
  • From March 2029: Down to just 47 days.

Domain and IP validation reuse windows are shrinking on a similar curve, too, eventually landing at just 10 days by 2029. In other words, even the information used to validate a domain will need to be refreshed far more often than it is today.

For organisations still validating certificates manually, this is the part that should get your attention: doing this by hand on a 47-day cycle is not just inconvenient, it's a genuine operational risk.

Why Is This Happening?

It's a fair question, especially if your current certificate process has worked fine for years.

The short answer is trust. The information embedded in a certificate, such as company details, domain ownership, and validation records, becomes less reliable the longer it sits unchanged. Shorter lifetimes require more frequent revalidation, keeping that information current and trustworthy.

There is also a practical security angle. The systems used to revoke compromised certificates (think CRLs and OCSP) are not as reliable as they should be, and browsers often do not check them consistently. Shorter-lived certificates limit how long a compromised or outdated certificate can stay active and cause damage, even if revocation does not happen cleanly.

Apple was the driving force behind the 47-day proposal, and its underlying argument is hard to dispute: the industry has been signalling for years, through steadily shrinking lifetimes, that manual certificate management was always meant to be a stopgap. Automation was always the endpoint.

What This Means for Your Team

If your certificate process today looks like a spreadsheet, a shared calendar, and someone remembering to renew things before they lapse, it is worth being honest about how well that scales down to a 47-day cycle.

A few things worth thinking through:

  • How many certificates are you currently managing, and across how many teams or systems?
  • Who owns renewal today, and what happens if that person is on leave when a certificate is due?
  • What is your visibility like across your certificate estate? Do you actually know what is expiring and when?
  • How would a missed renewal show up—a broken customer-facing site, an internal outage, or something worse?

None of this is meant to be alarming. It's simply what shorter lifetimes make visible: processes that worked at an annual cadence often do not hold up at a monthly one.

The Good News: This Is a Solved Problem

The reassuring part of this is that certificate automation is not new, and it’s not complicated to get right either. Modern certificate lifecycle management tools (many built around the ACME protocol) can handle discovery, issuance, renewal, and deployment without anyone needing to remember a renewal date ever again.

Once automation is in place, a 47-day certificate lifecycle isn't actually harder to manage than a 398-day one. It just runs quietly in the background. Some organisations even find that once they have automated, they are happy to move to shorter cycles voluntarily, simply because it reduces the blast radius if anything does go wrong.

The real work is not the 47-day deadline in the future. It's getting your current environment automation-ready before manual processes become untenable, which for many teams will happen well before 2029.

If you are not sure how exposed your organisation is, a good first step is a straightforward review: what certificates you have, how they are currently managed, and where the gaps are between where you are now and where you will need to be.

That's exactly what our team at Professional Advantage helps IT managers, cybersecurity engineers, and network admins work through: turning a manual, reactive certificate process into an automated one, well before shorter lifetimes make manual management a liability. 

Want a second set of eyes on your certificate setup? Get in touch with our team to talk through where you stand today and what a practical path to automation looks like for your environment. Book your complimentary consultation here.

Write a Comment


Talk to us

If you would like to learn more, complete the form below and one of our team will be in contact.

Your information will never be shared or sold to a 3rd party,
please read our privacy policy.