47-Day TLS Certificates Are Coming: The End of Manual Certificate Management

By Jim Wilson · July 16, 2026 · 7 min read

Executive summary. The industry has formally agreed to shorten the maximum life of a public TLS (SSL) certificate from today’s 398 days down to 47 days by 2029 - and the first cut lands in March 2026. This is not a distant, theoretical change. For most organizations it quietly rewrites how a core piece of infrastructure has to be run: certificates that used to be a once-a-year chore become a continuous, automated process. The businesses that treat this as an automation project starting now will barely notice the transition. The ones that keep renewing certificates by hand from a spreadsheet are signing up for outages.

What was decided

In April 2025, the CA/Browser Forum - the body where certificate authorities and browser makers set the rules that keep HTTPS trustworthy - passed Ballot SC-081v3, titled “Introduce Schedule of Reducing Validity and Data Reuse Periods.” It passed with no opposition, and all four major browser vendors - Apple (which proposed it), Google, Mozilla, and Microsoft - voted in favor. Because those vendors control what your customers’ browsers will accept, this is effectively binding on anyone who uses public certificates. There is no opting out.

The timeline: a staircase down to 47 days

The reduction happens in defined steps, not all at once. Two clocks are shrinking in parallel - how long a certificate stays valid, and how long the underlying domain validation can be reused before you have to prove control of your domain again:

  • Now through March 14, 2026: certificates valid up to 398 days.
  • March 15, 2026: maximum validity drops to 200 days; domain control validation (DCV) reuse also drops to 200 days.
  • March 15, 2027: maximum validity drops to 100 days; DCV reuse drops to 100 days.
  • March 15, 2029: maximum validity drops to 47 days; DCV reuse drops to just 10 days.

Note the nearest date. The conversation fixates on “47 days in 2029,” but the first meaningful change - certificates roughly halving in life to 200 days - is only months away, in March 2026. If your renewal process assumes a full year of runway, it is already out of date.

Why the industry is doing this

It comes down to a hard truth: certificate revocation has never worked well at internet scale. When a certificate is compromised, misissued, or tied to a key that leaks, the mechanisms meant to revoke it (CRL and OCSP) are slow, inconsistent, and often ignored by browsers for performance reasons. So a bad certificate can remain trusted far longer than anyone would like.

Shortening a certificate’s life is the blunt but effective fix. A 47-day certificate that is compromised is a problem for weeks, not more than a year. Shorter lifetimes also reduce reliance on stale validation data and push the entire ecosystem toward automation - which, done properly, is far more secure and less error-prone than a human renewing certificates by hand. The direction of travel is clear: trust is becoming something you continuously re-earn, not something you bank for a year.

The real risk isn’t security. It’s uptime.

Here is the part that catches organizations off guard. The immediate danger of this change is not a sophisticated attack - it is a self-inflicted outage. Expired certificates are already one of the most common causes of preventable downtime, and every major provider has taken a public site or API offline because someone missed a renewal. Now do the math:

  • A 398-day certificate is renewed once a year.
  • A 47-day certificate must be replaced roughly eight times a year.
  • Multiply that by every certificate across your websites, APIs, load balancers, internal services, and appliances - and manual tracking simply breaks.

A process that a person can just about manage once a year becomes mathematically impossible to run by hand every few weeks across a real environment. Every missed renewal is a customer-facing outage, a broken integration, or a security tool that silently stops working.

What good preparation looks like

The organizations that will sail through this are treating it as an operational project to start in 2026, not a fire drill for 2029. Three moves matter most:

  • Inventory everything. You cannot automate what you do not know exists. Most companies underestimate how many certificates they own - the dangerous ones live on forgotten subdomains, legacy appliances, and internal tools nobody remembers. A complete, continuously updated inventory is the foundation.
  • Automate issuance and renewal. Adopt the ACME protocol and a certificate lifecycle management (CLM) approach so certificates renew themselves without a human in the loop. This is the single highest-leverage step.
  • Practice now, while certificates still last months. Build and test automation during the current 398-day and upcoming 200-day windows, so that when renewal cycles compress to weeks, your team is already fluent and your systems are already proven.

How Inttelio helps

The certificate you forgot about is the one that takes your site down - and finding it is exactly the kind of problem we solve. OsintR continuously maps your external footprint, surfacing the subdomains, services, and forgotten assets where uncounted certificates quietly live, so your inventory reflects reality rather than a stale spreadsheet.

From there, our vCISO leadership can own the move to automated certificate lifecycle management as a program - inventory, ACME rollout, ownership, and monitoring - while our penetration testing and compliance teams make sure the change strengthens your security posture rather than introducing new gaps. If you want a clear picture of your certificate exposure before the March 2026 deadline, talk to our team.

Frequently asked questions

Why are TLS certificate lifetimes being cut to 47 days?

The CA/Browser Forum approved Ballot SC-081v3 in April 2025 to shrink the window of trust placed in any single certificate. Certificate revocation has never worked reliably at internet scale, so a certificate that is compromised or misissued can stay trusted for a long time. Shorter lifetimes limit that exposure and force the industry toward automation, which is more secure and less error-prone than manual renewals.

When does the 47-day certificate rule take effect?

It phases in. Maximum TLS certificate validity drops from 398 days to 200 days on March 15, 2026, to 100 days on March 15, 2027, and to 47 days on March 15, 2029. Domain control validation (DCV) reuse shrinks on the same dates, ending at just 10 days in 2029. The first cut is the nearest deadline, not 2029.

How many times will we have to renew a 47-day certificate?

A 47-day certificate must be replaced roughly every six to seven weeks, or about eight times a year, with practical renewals typically starting before expiry. Multiply that across every certificate you own and manual tracking becomes impossible. This is why automated certificate lifecycle management is now the only viable approach.

What should we do to prepare?

Build a complete inventory of every certificate you own, including forgotten ones on old subdomains and appliances, then automate issuance and renewal using the ACME protocol and a certificate lifecycle management process. Test automation now, while certificates still last months, so your team is fluent before renewal cycles compress to weeks.

Need help with this?

Inttelio helps businesses in Chicago and nationwide get secure and audit-ready. Let’s talk.

Book a free consultation