Follow us :
Managed IT

TLS Certificates Now Last 200 Days at Most: Who Tracks Your Renewals?

Laptop screen showing a cloud with a padlock, certificate renewal tracking — Xen Bilişim

If you bought a one-year SSL certificate in September last year, it is about to expire. The replacement will not last a year. Since 15 March 2026, the maximum lifetime of publicly trusted TLS certificates has been 200 days, down from 398. That was the first step of CA/Browser Forum ballot SC-081, adopted in April 2025, and more steps follow.

The schedule: 200, 100, 47

DateMaximum certificate lifetimeDomain validation reuse
Before 15 March 2026398 days398 days
15 March 2026200 days200 days
15 March 2027100 days100 days
15 March 202947 days10 days

These limits apply only to certificates from publicly trusted authorities. Certificates issued by your own internal CA are not affected. Certificates issued before March 2026 also keep working until their natural expiry, so nothing breaks overnight.

What changes on your calendar

Renewals per year, for a single certificate:

  • 398-day certificate: about 1
  • 200-day: 2
  • 100-day: about 4
  • 47-day: about 8

A company with a website, a mail gateway, a VPN portal, a remote desktop gateway, a customer portal and a few subdomains is looking at more than 50 renewals a year by 2029. One renewal a year can be done by hand. One every few weeks cannot; somebody will forget.

What an expired certificate actually breaks

The server does not crash. Visitors get a full-page browser warning, and most turn back. The more painful failures are elsewhere:

  • Accounting, e-invoicing or warehouse software calling a certificate-protected API starts failing without a clear error.
  • The SSL VPN or remote desktop gateway throws warnings and the home-working team cannot connect.
  • TLS between mail servers fails, and some counterparties reject the mail.
  • A mobile app fails certificate validation and nobody knows why.

These tend to surface on a Friday evening or the day before a public holiday. The cause is usually mundane: the person who bought the certificate left, and the reminders go to their old mailbox.

Manual tracking or automation?

MethodEnough whenWeak spot
Calendar reminder / spreadsheetUnder 5 certificates, 2 renewals a yearDepends on one person, records go stale
Provider’s warning emailsOne provider onlyNobody knows whose inbox gets them
ACME auto-renewalWeb servers, reverse proxiesAppliances and legacy software may not support it
Expiry checks in remote monitoringMany certificates, mixed devicesNeeds one-time setup

ACME automates requesting, validating and installing a certificate. Let’s Encrypt already issues 90-day certificates, so teams using it are well placed for shorter lifetimes. The hard part is anything that does not speak ACME, such as firewalls, load balancers and older mail gateways. Those need either the provider’s management tool or a reverse proxy placed in front.

What to do in the next two months

  1. Build an inventory. For every externally reachable domain and subdomain: who bought the certificate, from which provider, when it expires, which device it sits on.
  2. Name a real owner. Notifications should go to a shared address (a bt@ style mailbox) that at least two people can see, not to an individual.
  3. Hook expiry dates into monitoring. Alerts at 30, 14 and 7 days. Certificate checks come built into remote monitoring tools.
  4. Separate what can be automated. Websites and reverse proxies move to ACME; plan the appliances separately.
  5. Reflect it in the budget. A multi-domain or wildcard certificate often creates less work than many single ones. As renewals multiply, staff time becomes a real cost line.

Frequently asked questions

Is my existing 398-day certificate invalid right now? No. Certificates issued before March 2026 stay valid until their expiry date. The new limit applies when you renew.

Can I still ask for a longer lifetime? No. However long a package the provider sells, a single certificate cannot exceed the cap. Even with a multi-year plan you will reissue and install the certificate at intervals.

Does this apply to internal servers? Certificates from your own internal CA are outside these rules. Any certificate from an authority that browsers trust is in scope.

Sources? The schedule follows CA/Browser Forum ballot SC-081 and summaries published by DigiCert and GlobalSign.

If you do not know how many certificates your company has or who tracks them, an inventory is half a day of work. For help, get in touch.

Share this post
Türkçe oku

Related Posts