If you still renew TLS certificates by hand from a calendar reminder, the next three years will be rough. The CA/Browser Forum approved Ballot SC-081v3 in April 2025, and the maximum lifetime of publicly trusted certificates is being cut in stages.
The schedule
| From | Maximum validity |
|---|---|
| 15 March 2026 | 200 days |
| 15 March 2027 | 100 days |
| 15 March 2029 | 47 days |
The window for reusing domain validation also shrinks, to 10 days by 2029. In practice that means about two renewals a year per certificate today and about eight a year by 2029. Manual renewal does not scale to that.
Quick answers
- Do I need to replace my current certificates? No. They stay valid until they expire.
- Are free certificates covered? Yes. The limits apply to all publicly trusted certificates.
- What about apps that cannot use ACME? Put them behind a reverse proxy or load balancer that can, or plan an upgrade.
Where to start
- Inventory every certificate: domain, where it is installed, issuer, expiry date and owner.
- Give each certificate an owning team, not a single person.
- Automate issue and renewal with the ACME protocol.
- Add expiry monitoring that is independent of the renewal tool, with alerts at 30, 14 and 7 days.
Full guide with the six-step plan and the common mistakes: https://affixcenter.com/blog/ssl-certificate-validity-2026-renewal
Written by the team at Affix Center, a Mumbai-based IT services company. More on our IT operations and managed services.
Top comments (0)