Site icon Netrust

It’s Official – TLS Certificate Lifespans Shortening to 47 Days

[vc_row][vc_column]

[vc_column_text]Home > Resources > Articles > Shorter Certificate Lifespans[/vc_column_text][/vc_column][/vc_row][vc_row][vc_column]

It’s Official – TLS Certificate Lifespans Shortening to 47 Days

[/vc_column][/vc_row][vc_row equal_height=”yes” column_spacing=”30px” canvas=”%5B%7B%22element%22%3A%22image%22%2C%22shape%22%3A%22shape-1%22%2C%22image_effect%22%3A%22style-1%22%2C%22smoothness%22%3A%2230%22%7D%5D”][vc_column]
[vc_single_image image=”11699″ img_size=”full” alignment=”center” css=””]
Article updated on 28 Apr 2025 to reflect the latest CA/Browser Forum announcement.
On 11 Apr 2025, the CA/Browser Forum has voted for and approved Ballot SC-081v3, a proposal led by Apple to shorten the lifespan of SSL/TLS certificates. This move aims to enhance web security and reduce the risk of vulnerabilities.
[vc_row_inner][vc_column_inner width=”1/2″]

What exactly is the big change?

  • The current maximum public TLS certificate you can request is 13 months (398 days).
  • Certificate lifespans will be progressively reduced over the next few years, culminating in a maximum lifespan of 47 days by 2029.

Official Schedule

[vc_table][align-center;bg#000000;c#ffffff;b]Maximum%20Certificate%20Lifespan,[align-center;bg#000000;c#ffffff;b]Date|[align-center;c#000000]200%20Days,[align-center;c#000000]15%20Mar%202026|[align-center;c#000000]100%20Days,[align-center;c#000000]15%20Mar%202027|[align-center;c#000000]47%20Days,[align-center;c#000000]15%20Mar%202029[/vc_table]
[/vc_column_inner][vc_column_inner width=”1/2″]

Keep certificates current, effortlessly.
Ask us how to manage the new 47-day change.

[/vc_column_inner][/vc_row_inner]

How does this affect me?

This accelerated timeline for certificate lifespan reduction will have a direct impact on organisations:
  • Increased Management Overhead: IT teams will need to manage the renewal of certificates at a higher frequency rate thus increasing the volume of certificate renewals.
  • Potential for Disruptions: Manual processes may not be sufficient to keep up with the rapid pace of certificate expiration.
  • Increased Chance of Mistake: With the increased manual generation of certificate requests, administrators are potentially exposed to increased chances of making mistakes.

Why the change?

The shortening of certificate lifespans is driven by the need to mitigate security risks associated with compromised certificates. Shorter lifespans make it more difficult for attackers to exploit vulnerabilities and compromise websites.

Stricter DCV Reuse

In addition to the shorter lifespans, there will also be a stricter DCV reuse period.

Understanding DCV

Domain Control Validation (DCV) is a security measure used by CAs to verify domain ownership. It involves adding a specific HTML file to the website’s root directory. This file proves that the applicant has control over the domain.
DCV reuse period will also be shortened, reaching a minimum of 10 days in 2029.
[vc_table][align-center;bg#000000;c#ffffff;b]DCV%20Reuse%20Period,[align-center;bg#000000;c#ffffff;b]Date|[align-center;c#000000]200%20Days,[align-center;c#000000]15%20Mar%202026|[align-center;c#000000]100%20Days,[align-center;c#000000]15%20Mar%202027|[align-center;c#000000]10%20Days,[align-center;c#000000]15%20Mar%202029[/vc_table]

The impact of shorter DCV reuse periods

With shorter DCV reuse periods, certificates issued using the same DCV challenge will have shorter lifespans. This means that CAs will need to perform more frequent validation checks to ensure that certificates remain valid and secure.

The Solution: Automated Certificate Lifecycle Management

To address these challenges, organisations should adopt automated certificate lifecycle management (CLM) solutions. CLM tools can:
  • Automate Renewals: Automatically renew certificates before they expire.
  • Monitor Expirations: Proactively track certificate expiration dates.
  • Centralise Management: Consolidate certificate management into a single platform.
[vc_single_image image=”11555″ img_size=”full” alignment=”center” onclick=”custom_link” css=”” link=”https://www.netrust.net/products/consultancy/ca-consultancy-services/pki-health-check/”]

Netrust: Your Partner in Certificate Management

Netrust offers a suite of comprehensive solutions to address the evolving landscape of certificate management.
Don’t let shorter certificate lifespans disrupt your operations. Contact Netrust today to learn how our Next-Generation SSL solution can help you maintain security and compliance.
[/vc_column][/vc_row][vc_row][vc_column]
[/vc_column][/vc_row][vc_row equal_height=”yes” content_placement=”middle” column_spacing=”30px” canvas=”%5B%7B%22element%22%3A%22image%22%2C%22shape%22%3A%22shape-1%22%2C%22image_effect%22%3A%22style-1%22%2C%22smoothness%22%3A%2230%22%7D%5D” el_id=”contact-us”][vc_column width=”1/2″]
[/vc_column][vc_column width=”1/2″]

Keep certificates current, effortlessly.
Ask us how to manage the new 47-day change.

[/vc_column][/vc_row]
Exit mobile version