Reference · CA/Browser Forum SC-081v3

The TLS certificate lifetime timeline

Public TLS certificates are getting shorter on a fixed schedule. The CA/Browser Forum — the body whose Baseline Requirements every public certificate authority and browser follows — voted in April 2025 to cut the maximum certificate lifetime from 398 days today to 47 days by 2029, in three steps. Here is the full timeline, the parallel cut to domain-validation reuse, and the renewal math each stage forces.

The schedule

398 → 200 → 100 → 47 days, in three steps

Each date below is when the new maximum takes effect for newly issued certificates. Today, a public TLS certificate can be valid for at most 200 days.

EffectiveMax certificate validityMax domain-validation reuseReissues per certificate / yearStatus
Before 15 Mar 2026398 days398 days~1× per yearPast
15 Mar 2026200 days200 days~2× per yearIn effect now
15 Mar 2027100 days100 days~4× per yearScheduled
15 Mar 202947 days10 days~8× per yearScheduled

Source: CA/Browser Forum Ballot SC-081v3 (passed April 2025, 29–0). Reissues-per-year is 365 ÷ maximum validity — arithmetic, not a measurement of any real set of sites.

What it means

The load multiplies across a portfolio

One certificate at 47 days is roughly eight reissue events a year instead of one. The operational cost is that number times every domain you are responsible for.

~8×

more reissue events per certificate at 47 days than under the old 398-day limit.

every ~10 days

you also re-prove domain control by 2029, as validation reuse drops to 10 days.

~400 / year

renewal events for a 50-domain portfolio at 47-day certificates (50 × ~8).

A calendar reminder that worked at one renewal a year does not survive eight. The two durable responses are to automate issuance and to monitor expiry independently — because automation fails silently, and a certificate that lapses takes a site offline for every visitor.

How to prepare

Automate, then verify

Automated issuance (for example via ACME, which many certificate authorities support) handles the reissue. Continuous monitoring is the independent check that catches the renewal that did not happen — a failed ACME hook, an expired validation, a certificate that was never wired to the load balancer — before it becomes an outage.

Check one certificate now

See a domain’s current certificate, its issuer, and exactly how many days remain — free, no signup.

Watch a whole portfolio

Continuous SSL/TLS monitoring across every client domain, with alerts ahead of each expiry and on certificate changes — built for the 47-day cadence.

Common questions

Frequently asked questions

What is the 47-day certificate cliff?

In April 2025 the CA/Browser Forum — the body that sets the rules public certificate authorities and browsers follow — passed Ballot SC-081v3, which shortens the maximum lifetime of a publicly trusted TLS certificate in stages: from 398 days to 200 days on 15 March 2026, 100 days on 15 March 2027, and 47 days on 15 March 2029. The vote passed 29 to 0.

What is happening to domain validation reuse?

The same schedule shortens how long a certificate authority may reuse prior domain-control validation: 200 days from March 2026, 100 days from March 2027, and just 10 days from March 2029. So by 2029 you re-prove domain control roughly every 10 days as well as reissuing the certificate every 47 — which is why manual issuance stops being practical.

How many more renewals does 47 days mean?

A 47-day maximum works out to roughly 8 reissues per certificate per year, versus about 1 under the old 398-day limit — about 8× the renewal events. Across a portfolio of domains the count multiplies: 50 domains at 47-day certificates is on the order of 400 renewal events a year.

How should teams prepare?

Two things: automate issuance (for example with the ACME protocol, which many certificate authorities support) so renewals do not depend on a person remembering, and monitor certificate expiry continuously with alerts ahead of each expiry so a failed or missed automation is caught before the certificate lapses. Automation issues the certificate; monitoring is the independent safety net that tells you when it did not.

Does this affect certificates I already have?

Certificates issued before a given effective date keep the validity they were issued with — the limits apply to newly issued certificates from each date forward. In practice that means the shorter lifetimes phase in as your existing certificates renew, so the operational load ramps up rather than switching overnight.

Don’t let a 47-day certificate lapse on your watch

Merlonix watches every client certificate and alerts you ahead of each expiry — start free, no credit card.