Skip to content
rcrootcerts.com

Digital trust is changing

Understand what changed.
See how it works.
Know what to do next.

rootcerts.com tracks the standards, technologies, and operational practices behind certificates, PKI, automation, and post-quantum security. No gates, no sign-up.

Next deadline

219days

31 weeks · 2027-03-15

100-day maximum TLS validity

Tracked right now

5

developments

6

milestones

0

paywalls

Current transition

Public TLS validity is collapsing — see what it costs you

Pick a phase and set your certificate count. The workload numbers update instantly.

500

5010,000

Renewals per year

913

2.0× the 398-day baseline of 459.

2.0×vs. 2020

Manual renewal is the risk.

At 200 days you renew roughly every 29 weeks per certificate.

Full calculator →

Top development

Public TLS certificate validity capped at 200 days

EffectiveTLS · CA/Browser Forum

Public TLS certificates issued on or after 15 March 2026 may not exceed 200 days. Two further reductions are already scheduled.

Maximum subscriber certificate validity is reduced in phases: 398 → 200 days (2026-03-15), → 100 days (2027-03-15), → 47 days (2029-03-15). Domain and IP validation reuse periods shrink alongside each phase.

Impact by role

Executive

owns: Budget, risk appetite, board reportingacts within: Planning cycle

What does this cost, and what breaks if we do nothing?

Implication: Renewal volume roughly doubles this year and rises ~8x by 2029 without automation.

Next action: Fund certificate discovery and lifecycle automation in the current planning cycle.

Proposed
2024-10-09
Published
2025-04-11
Effective
2026-03-15
Last verified
2026-08-01

Source (Standards body): CA/Browser Forum — Ballot SC-081v3 (certificate lifetime reduction). Reviewed by RootCerts editorial — PKI standards desk.

Status mix

  • Effective20%
  • Published60%
  • Experimental20%

Deadline panel

  • 200-day maximum TLS validity

    2026-03-15

    Public TLS certificates capped at 200 days.

    in effect

  • 100-day maximum TLS validity

    2027-03-15

    Second phase of the lifetime reduction.

    in 219 days

  • DCV reuse reduced to 100 days

    2027-03-15

    Domain control validation data reuse shortens with validity.

    in 219 days

  • 47-day maximum TLS validity

    2029-03-15

    Scheduled end state, with 10-day validation reuse.

    in 950 days

  • NIST target to deprecate 112-bit classical algorithms

    2030-12-31

    Planning target for retiring quantum-vulnerable public-key cryptography.

    in 1,606 days

  • NIST target for completed PQC migration

    2035-12-31

    Government planning horizon for full migration.

    in 3,432 days

Standards activity

Recently updated developments

  • Published standardACME

    ACME Renewal Information (ARI) published as RFC 9773

    ACME servers can now tell clients when to renew, so renewals can be rescheduled by the CA during mass-revocation events.

    EFFECTIVE 2025-06-01 · IETF

  • Published standardPQC

    NIST finalizes ML-KEM, ML-DSA and SLH-DSA

    The first principal post-quantum standards are final. NIST advises organizations to inventory quantum-vulnerable cryptography and plan migration now.

    EFFECTIVE 2024-08-13 · NIST

  • Published standardCertificate Transparency

    Certificate Transparency v2 (RFC 9162) Merkle tree auditing

    CT logs use binary Merkle trees so any client can verify that a certificate was logged without downloading the log.

    EFFECTIVE 2021-12-01 · IETF

  • Emerging / experimentalPQC

    Merkle Tree Certificates explored in IETF PLANTS

    An emerging construction that integrates certificate issuance with a public log to cut the overhead of large PQC signatures and very short lifetimes.

    NO EFFECTIVE DATE · IETF

Explore by objective

Start from what you need to do

Ready to move from understanding to implementation?

rootcerts.com stays ungated: the calculators, timelines and standards tracking above require no account. When you are ready to operationalize, Sectigo can help.