In 2025, Sectigo initiated one of the most significant infrastructure changes in its PKI ecosystem, namely the migration of certificate issuance to new, proprietary Public Root Certification Authorities. This change affects all major product lines, including SSL/TLS certificates (DV, OV, EV) and S/MIME, and has a direct impact on how trust chains are built in browsers, operating systems, and server environments.
While for most end users the migration will be largely invisible, from the perspective of administrators, DevOps teams, security architects, and hosting providers it is a change that must be consciously considered when planning compatibility and service continuity.
Table of Contents
ToggleA Public Root CA represents the highest trust anchor in the PKI model. Every browser and operating system maintains its own root trust store, which determines whether a given certificate is considered trustworthy. Changing a root CA is therefore not cosmetic and directly affects:
The Sectigo migration aligns with a broader trend of cleaning up and simplifying CA hierarchies, in line with current trust program requirements from Mozilla, Apple, Microsoft, and Google, as well as CA/B Forum recommendations.
Until now, Sectigo relied on historical and widely distributed root CAs, including USERTrust, often combined with extensive cross-signing. The new strategy assumes:
In practice, this results in a more predictable and controlled trust environment, while simultaneously requiring compatibility verification on the relying party side.
Sectigo is rolling out the changes in stages, depending on the certificate type:
After these dates, newly issued certificates will by default rely on the new root CAs. Existing certificates remain valid until the end of their validity period.
In modern systems such as current versions of Windows, macOS, Linux, Android, iOS, and contemporary browsers, the change is in most cases transparent. Issues may arise in environments that:
In such cases, root CA migration may manifest as TLS errors, certificate validation failures, or broken API connections.
To reduce the risk of incompatibility, Sectigo applies cross-signing of new roots by older, widely recognized CAs. This mechanism allows certificates to be accepted by both modern and older environments.
However, cross-signing should be treated as a temporary solution, not a long-term strategy. Ultimately, organizations should aim to update systems and simplify their trust chains.
The changes introduced by Sectigo are consistent with the overall direction of the PKI ecosystem:
For organizations managing a larger number of certificates, this is a good moment to review internal processes related to certificate installation, monitoring, and renewal.
No. Certificates issued before the migration dates remain valid until they expire. The migration applies only to newly issued certificates and reissues.
Not directly. As long as the certificate is correctly installed and the browser trusts the new root CA, the migration has no impact on SEO. Issues may arise only in the case of incorrect TLS configuration resulting in security warnings.
Yes, in extreme cases. This mainly affects very old systems, embedded devices, and applications with their own outdated trust stores. In such environments, updates or manual trust chain management may be required.
Yes. Pinning at the root or specific intermediate CA level may lead to failures after migration. Sectigo explicitly discourages this approach and recommends relying on standard PKI validation.
In the case of multi-year subscriptions, certificates will be reissued according to the new root CA hierarchy once the migration dates are reached.
In most cases, no. However, it is worth verifying that the server provides a complete and correct certificate chain and does not rely on manually defined, outdated CA bundles.
The migration of Sectigo Public Root CAs is a good moment not only to ensure that a certificate works, but also to verify the entire TLS environment in a systematic way. In practice, this means combining analysis, monitoring, and automated diagnostics. This is exactly where HEXSSL serves as a control layer between the certificate authority and the production environment.
The first step should be checking which certificate chain is actually delivered by the server to the TLS client, not just which certificate was installed.
➡ Use the SSL Checker to:
This is the baseline reference point before making any changes.
During the Sectigo migration, some certificates may be reissued under the new hierarchy, especially within multi-year subscriptions or automated renewals. Without monitoring, such changes often go unnoticed until problems occur.
➡ Enable continuous monitoring with SSL Monitor to:
Monitoring is especially critical in production and multi-domain environments.
If you manage a larger number of domains, APIs, or test environments, manual verification does not scale. Root CA migration should be treated as an infrastructure change, not a one-off incident.
➡ Use HEXSSL-CLI to:
This approach minimizes the risk of errors after deploying new certificates.
The migration of Sectigo Public Root CAs often exposes a lack of centralized visibility. Certificates may be scattered, documentation outdated, and responsibilities unclear.
HEXSSL enables you to:
This is particularly important for organizations that treat certificates as critical infrastructure rather than a one-time purchase.
The migration of Sectigo Public Root CAs is a fundamental but predictable and well-planned change. For modern environments it will be nearly invisible, while for legacy systems it may serve as a catalyst for necessary updates. From the perspective of security and long-term PKI stability, this is a step in the right direction. The migration itself does not constitute a threat. However, it is a moment when imperfections in TLS configuration and PKI management become visible. Instead of reacting only after problems occur, it is worth using this stage to strengthen control over certificates.
➡ Check your domain now with the SSL Checker.
➡ Enable monitoring with SSL Monitor.
➡ Automate audits with HEXSSL-CLI.
This approach allows you to go through the Sectigo Root CA migration in a predictable, controlled, and standards-compliant manner. Have questions about the migration? Feel free to contact us.
Additional information about the planned migration: Sectigo Public Root CAs Migration.