DEV Community

47-Day TLS Certificates Are Coming: What Ops Teams Should Automate Now

If you still renew TLS certificates by hand from a calendar reminder, the next three years will be rough. The CA/Browser Forum approved Ballot SC-081v3 in April 2025, and the maximum lifetime of publicly trusted certificates is being cut in stages.

The schedule

From Maximum validity
15 March 2026 200 days
15 March 2027 100 days
15 March 2029 47 days

The window for reusing domain validation also shrinks, to 10 days by 2029. In practice that means about two renewals a year per certificate today and about eight a year by 2029. Manual renewal does not scale to that.

Quick answers

  • Do I need to replace my current certificates? No. They stay valid until they expire.
  • Are free certificates covered? Yes. The limits apply to all publicly trusted certificates.
  • What about apps that cannot use ACME? Put them behind a reverse proxy or load balancer that can, or plan an upgrade.

Where to start

  1. Inventory every certificate: domain, where it is installed, issuer, expiry date and owner.
  2. Give each certificate an owning team, not a single person.
  3. Automate issue and renewal with the ACME protocol.
  4. Add expiry monitoring that is independent of the renewal tool, with alerts at 30, 14 and 7 days.

Full guide with the six-step plan and the common mistakes: https://affixcenter.com/blog/ssl-certificate-validity-2026-renewal

Written by the team at Affix Center, a Mumbai-based IT services company. More on our IT operations and managed services.

Top comments (0)