DigiCert: SSL Certificate Validity Change – 199 Days from February 24, 2026

DigiCert SSL

In 2026, the TLS/SSL certificate industry is introducing another major change related to the maximum certificate validity period. DigiCert, as one of the largest certificate authorities, has confirmed that from February 24, 2026, all new public TLS certificates will have a maximum validity of 199 days.

Why is this change happening?

HTTPS/TLS is the foundation of security on the internet. Shorter certificate lifetimes reduce the risk of long term key compromise and limit the potential impact of certificate misuse or errors. This change results directly from decisions made by the CA/Browser Forum and the so called Ballot SC081v3, which gradually reduces the allowed validity periods for certificates and validation data.

What timelines apply from 2026?

Certificate period Maximum validity
Until March 15, 2026 398 days
From February 24, 2026 to March 15, 2027 199 days (DigiCert 1 day less)
From March 15, 2027 100 days
From March 15, 2029 47 days

DigiCert sets certificate validity to 1 day less than the CA/Browser Forum limit to ensure the official maximum is never exceeded.

What exactly changes from February 24, 2026?

  1. New TLS/SSL certificates.
    From this date, DigiCert will not accept any public certificate requests with a validity longer than 199 days. This applies to all major certificate types:

    • DV (Domain Validated).
    • OV (Organization Validated).
    • EV (Extended Validation).
    • QWAC / QWAC PSD2 (qualified website certificates).
  2. Reissues and duplicates.
    Certificates issued before February 24, 2026 with longer validity periods remain trusted until their expiration date. However, any reissues or duplicates created after this date will have a maximum validity of 199 days.
  3. API and automated management.
    When using the CertCentral Services API, validity values exceeding 199 days will be automatically shortened to 199.

What does this mean in practice?

Shorter certificates mean more frequent renewals
For domain owners, administrators, and DevOps teams, this means a significant increase in certificate renewal frequency. For example, a certificate previously renewed annually will now require renewal approximately every 6.5 months.

Certificate lifecycle automation becomes a practical necessity
Manually renewing certificates every 199 days carries a high risk of errors, missed deadlines, or service disruptions. Therefore, a natural step for professional IT environments is:

  • enabling automated certificate renewal processes (ACME, CertCentral, TLM, etc.),
  • implementing certificate expiration monitoring systems,
  • integrating certificate alerts and audits into DevOps and CI/CD processes.

Why does this matter for your organization?

  1. Improved transport security: Shorter certificate lifecycles increase HTTPS resilience against key compromise and PKI related attacks.
  2. High service availability: Reliable renewal processes reduce the risk of certificate expiration and service outages.
  3. Compliance with global standards: The planned changes are part of a broader CA/Browser Forum strategy to raise the overall security level of the internet.

Recommendations for our customers.

  • If you operate a website with a certificate valid for longer than 199 days, plan its renewal before February 24, 2026.
  • Implement automatic certificate renewals.
  • In DevOps environments, automate certificate expiration monitoring and CI/CD integration.
  • Consider integrating CertCentral and DigiCert tools for full certificate lifecycle management.

The reduction of TLS/SSL certificate validity to 199 days from February 2026 is another step toward improving the security of the entire internet. For users and administrators, this requires rethinking certificate issuance and renewal automation strategies to maintain compliance and service continuity.

Do you have questions regarding this change? Contact our sales team.

Add A Knowledge Base Question !

You will receive an email when your question will be answered.

+ = Verify Human or Spambot ?