DEV Community

Cover image for The October SSL Certificate Expiry Wave Nobody Planned For
MonstaDomains
MonstaDomains

Posted on Originally published at monstadomains.com

The October SSL Certificate Expiry Wave Nobody Planned For

Originally published at https://monstadomains.com/blog/ssl-certificate-expiry-wave/

On 15 March 2026 the maximum lifetime of a public TLS certificate fell from 398 days to 200. Nearly every certificate issued in that first week comes due around 1 October, which means the web is about to run its first genuinely synchronised SSL certificate expiry event. Certificate authorities have been warning about it since spring. Most site owners have not listened. If your renewal process still involves a human remembering a date, that human is now the single point of failure standing between your visitors and a full page browser warning.

What Actually Changed On 15 March 2026

The change came from ballot SC-081v3, adopted by the CA/Browser Forum in April 2025 with 25 votes in favour, none against and five abstentions. Near unanimity is rare in that room, and it signalled that browser vendors and certificate authorities had stopped arguing about whether short certificate lifetimes were coming and started arguing about how fast.

The ballot phases maximum validity down in three steps. From 15 March 2026, 200 days. From 15 March 2027, 100 days. From 15 March 2029, 47 days. You can read the full text of ballot SC-081v3 on the CA/Browser Forum site. Nothing about it is provisional.

DigiCert moved ahead of the deadline, capping new certificates at 199 days from 24 February 2026. Sectigo held to the 15 March date with a 200 day ceiling. That two week gap matters less than the fact that both of the largest commercial issuers now hand out certificates that expire inside a single business half year.

The SSL Certificate Expiry Math Behind 1 October

Count 200 days forward from 15 March 2026 and you land on 1 October 2026. Every organisation that renewed a certificate in that first compliance window, and every organisation whose annual renewal happened to fall in mid March, now shares a single SSL certificate expiry date. This is not a gradual slope. It is a cliff, and it arrives in weeks.

The clustering is the story. Under the old 398 day regime, renewals scattered across the calendar because certificates were bought whenever a site launched. The March cutover pulled a large slice of the web onto one clock. Any SSL certificate expiry failure that would once have been an isolated embarrassment now has company, and support teams will be handling several at once.

Who Is Most Exposed Right Now

The highest risk group is not the one you would guess. Large enterprises have certificate lifecycle tooling and dedicated staff. Hobby projects on managed hosting inherit automation from their provider. The exposure sits with mid sized self hosted setups, appliances with web interfaces, internal tools published to the open internet, and load balancers configured once and never revisited. Those are precisely the systems where nobody owns the SSL certificate expiry calendar, and precisely the systems that will surface in early October.

Why Manual Renewal Stopped Being Viable

The CA/Browser Forum was explicit that the point of the schedule is to force automation. Shorter lifetimes limit the damage from a stolen private key and let deprecated cryptography age out of the ecosystem quickly instead of lingering for a year. Both benefits only materialise if renewal is machine driven.

Let’s Encrypt has demonstrated for a decade that automated issuance works at scale, serving hundreds of millions of active certificates through ACME clients that renew without anyone filing a ticket. The Let’s Encrypt statistics page tracks that volume publicly. Organisations that adopted ACME years ago will not notice 1 October at all. Organisations running a spreadsheet of SSL certificate expiry dates will notice it acutely.

The 2027 Squeeze Is The Real Deadline

March 2027 halves the window again to 100 days. At that point a manual process means four renewals a year per certificate, and by 2029 it means roughly eight. Any team treating October as a one off scramble is solving the wrong problem. The correct response is to remove humans from the SSL certificate expiry path entirely, before the cadence makes that impossible.

SSL certificate expiry - a glowing digital padlock and countdown ring representing shortened TLS certificate lifetimes

The Validation Changes Riding Alongside SSL Certificate Expiry Limits

Validity is only half of SC-081v3. The ballot also shrinks how long a certificate authority may reuse previously validated domain control and identity data, which means proving you own a domain becomes a recurring task rather than an annual one. Several validation methods are being retired on a fixed schedule alongside the SSL certificate expiry reductions.

The crossover validation method phased out on 15 March 2026. Phone based verification disappears on 15 March 2027. Email based domain validation is gone entirely by 15 March 2028. Separately, the Client Authentication EKU was removed from public TLS certificates on 15 June 2026, which broke a number of setups that had quietly been using web certificates for mutual authentication.

For anyone running a domain under privacy protection, the validation squeeze deserves attention. If your validation contact is a forwarding address you rarely check, an SSL certificate expiry event can become an SSL certificate reissuance event you cannot complete. Verify that the address attached to your certificate orders still reaches you before October, not after.

How Registrars And Hosts Have Responded

Most hosting providers rolled ACME support into their control panels well before March and have been auto renewing quietly since. The friction is concentrated where certificates are purchased separately from where they are deployed, which is common for extended validation and organisation validated certificates that cannot be issued through a free automated authority. If you buy a certificate in one place and install it in another, the SSL certificate expiry cycle now demands a documented handoff rather than an annual habit.

What An SSL Certificate Expiry Failure Costs A Private Site

For a commercial site, an expired certificate means a scary interstitial and lost revenue. For a site run by a journalist, an activist or anyone operating pseudonymously, the cost is different and worse.

An SSL certificate expiry failure pushes visitors into a browser warning screen that invites them to click through on an unauthenticated connection. That is exactly the state a network observer wants. Traffic to a site with a broken certificate is easier to fingerprint, easier to tamper with, and the warning itself trains an audience to ignore the one signal that tells them a connection is genuine.

There is a second, quieter cost. Emergency reissuance under time pressure is when people make identity mistakes. They pay with a card because the crypto payment would take longer. They use a real email address because the alias is not receiving. A rushed response to an SSL certificate expiry deadline is a common way that carefully maintained separation between a person and a project collapses.

Reading The Wider Shift In Certificate Policy

The 200 day cap did not arrive in isolation. Over the past year the same standards process has pushed long lived sources of trust out of the public web PKI, and browser vendors have grown steadily less patient with certificate authorities that cannot demonstrate rapid revocation. The direction is consistent. Trust is becoming something you renew constantly rather than something you buy once.

That shift is broadly good for privacy. Short lived certificates make key compromise less valuable and make it far harder for a legal order against a certificate authority to yield anything durable. The tradeoff is operational, and it lands hardest on small independent operators who never had a certificate lifecycle team. Our earlier coverage of the Let’s Encrypt certificate changes traced the beginning of this same trend.

What To Do Before The Next SSL Certificate Expiry Deadline

Start by finding out what you actually have. Run every domain and subdomain you control through an SSL certificate checker and write down the real expiry dates rather than the ones you assume. Wildcard certificates and forgotten staging subdomains are where the October surprises will come from.

Then move anything renewable onto ACME. Caddy, Traefik, most modern hosting panels and certbot all handle it, and the setup cost is an afternoon. Configure monitoring that alerts at 30 days and again at 7, because automation fails silently more often than people expect. Check that the contact address on your certificate orders is one you still read, and confirm your DNS provider will not rate limit the validation challenges that a 100 day cycle will generate next year. Our guide to private DNS management covers the configuration side.

Finally, treat the SSL certificate expiry calendar as infrastructure rather than admin. Record every certificate, the system it lives on, the account that can reissue it and the person who gets the alert. If any certificate is tied to an account you can no longer access, replace it now. An SSL certificate expiry date sitting on an orphaned account is simply a scheduled outage with a known start time.

Where To Go From Here

Three things are worth carrying away. The 1 October cluster is a direct arithmetic consequence of the 15 March cutover, so it is predictable and entirely preventable. The 100 day limit arriving in March 2027 makes manual renewal permanently untenable, which means October is a rehearsal rather than a finish line. And for privately operated sites, a rushed SSL certificate expiry response is a genuine deanonymisation risk, not merely a downtime problem.

Audit your certificates this week, automate what you can, and if you need certificates that are not tied to a verified corporate identity, MonstaDomains issues privacy first SSL certificates alongside domains paid for in crypto.

Top comments (0)