From March 2026, the maximum validity of public SSL/TLS certificates is reduced to 200 days. This decision represents another stage in the evolution of the global WebPKI trust infrastructure and results from agreements developed within the CA/Browser Forum – the organization that defines standards for the operation of public certification authorities and internet browsers. At first glance, the change may appear technical and relatively minor. In practice, however, it forms part of a long-term strategy to transform the certificate management model on the internet. Importantly, 200 days is not the final target. The market is moving toward even shorter validity periods, which in subsequent stages are expected to be reduced to as little as 47 days.
Table of Contents
ToggleIn recent years, the maximum validity period of public certificates has been systematically shortened. This trend is not accidental – it is a response to increasing cybersecurity requirements and the need to reduce operational risk.
The table below illustrates the direction of these changes:
| Stage | Maximum certificate validity | System significance |
|---|---|---|
| Model applicable until 2026 | 398 days | Certificate as a resource renewed once per year |
| March 2026 | 200 days | Shortened lifecycle and increased rotation frequency |
| Transitional stage (March 2027) | 100 days | Increased pressure for automation |
| Target model (2029) | 47 days | Certificate as part of a continuous process |
The reduction to 200 days is therefore a clear directional signal. Within a few years, the certificate lifecycle will become so short that manual management will no longer be operationally rational.
From a cryptographic perspective, the shorter a given private key remains in use, the smaller the potential window for its exploitation in the event of compromise. A certificate with one-year validity means one year of exposure. A 47-day certificate reduces this risk multiple times. Shorter validity periods also have systemic importance. They enable faster enforcement of migrations to new cryptographic algorithms, updates to trust chains, and adjustments to evolving validation policies. In a dynamic cyber threat environment, the speed of adaptation becomes critical.
Shortening validity is therefore not an obstacle for the market, but a mechanism that limits long-term structural risk.
From the moment the new rules come into force, a single public SSL/TLS certificate may be issued for a maximum of 200 days. After this period, it will be necessary to generate a new CSR and complete the standard renewal process. For small websites, this may simply mean more frequent logins to the administrative panel. In distributed environments – including load balancers, reverse proxies, container clusters, multi-cloud infrastructure, or edge devices – the change increases the importance of precise lifecycle management of certificates.
In practice, every TLS termination point must be under control. Inconsistency in even one infrastructure element may lead to browser warnings, service downtime, or loss of customer trust.
The eventual reduction to 47 days represents a fundamental change in philosophy. The certificate ceases to be an annual event in an administrator’s calendar and becomes an infrastructure component rotated almost continuously. In such a model, manual renewal loses operational sense. Certificate management must be integrated with DevOps processes, deployment pipelines, and monitoring systems. The certificate begins to function similarly to other dynamic resources – containers, secrets, or access tokens.
Organizations that fail to implement automation will face increasing risk of incidents related to certificate expiration. With a 47-day cycle, the operational margin for error practically disappears.
The expiration of an SSL/TLS certificate has a direct impact on reputation and revenue. Security warnings in browsers result in loss of user trust and interruption of the purchasing process in e-commerce. In regulated sectors, they may lead to violations of compliance requirements and contractual consequences. The shorter the certificate lifecycle, the greater the importance of mature security management processes. Shortening validity aligns with the broader global trend of raising cybersecurity standards.
The reduction of maximum validity to 200 days should be viewed as a transitional stage. The target 47-day model means that the WebPKI market is entering a phase in which certificate rotation will become an almost continuous process. For organizations, this means the need to change their approach from reactive certificate renewal to strategic lifecycle management. Companies that adapt their processes today to shorter validity periods will avoid future, costly operational reorganization.
This change is not a revolution, but an evolution toward greater resilience of internet infrastructure. The SSL/TLS certificate is no longer a static element deployed once per year. It becomes a dynamic component of the security architecture that must operate in a continuous, controlled, and automated manner.
Check our information on this topic:
Do you have questions related to the shortened SSL certificate validity period? Check how we can help you and your company: Contact.