In 2026, the TLS/SSL certificate industry is introducing another major change related to the maximum certificate validity period. DigiCert, as one of the largest certificate authorities, has confirmed that from February 24, 2026, all new public TLS certificates will have a maximum validity of 199 days.
Table of Contents
ToggleHTTPS/TLS is the foundation of security on the internet. Shorter certificate lifetimes reduce the risk of long term key compromise and limit the potential impact of certificate misuse or errors. This change results directly from decisions made by the CA/Browser Forum and the so called Ballot SC081v3, which gradually reduces the allowed validity periods for certificates and validation data.
| Certificate period | Maximum validity |
|---|---|
| Until March 15, 2026 | 398 days |
| From February 24, 2026 to March 15, 2027 | 199 days (DigiCert 1 day less) |
| From March 15, 2027 | 100 days |
| From March 15, 2029 | 47 days |
DigiCert sets certificate validity to 1 day less than the CA/Browser Forum limit to ensure the official maximum is never exceeded.
Shorter certificates mean more frequent renewals
For domain owners, administrators, and DevOps teams, this means a significant increase in certificate renewal frequency. For example, a certificate previously renewed annually will now require renewal approximately every 6.5 months.
Certificate lifecycle automation becomes a practical necessity
Manually renewing certificates every 199 days carries a high risk of errors, missed deadlines, or service disruptions. Therefore, a natural step for professional IT environments is:
The reduction of TLS/SSL certificate validity to 199 days from February 2026 is another step toward improving the security of the entire internet. For users and administrators, this requires rethinking certificate issuance and renewal automation strategies to maintain compliance and service continuity.
Do you have questions regarding this change? Contact our sales team.