Digital trust is changing
Understand what changed.
See how it works.
Know what to do next.
rootcerts.com tracks the standards, technologies, and operational practices behind certificates, PKI, automation, and post-quantum security. No gates, no sign-up.
Next deadline
≈ 31 weeks · 2027-03-15
100-day maximum TLS validity
Tracked right now
5
developments
6
milestones
0
paywalls
Current transition
Public TLS validity is collapsing — see what it costs you
Pick a phase and set your certificate count. The workload numbers update instantly.
500
Renewals per year
913
2.0× the 398-day baseline of 459.
Manual renewal is the risk.
At 200 days you renew roughly every 29 weeks per certificate.
Full calculator →Top development
Public TLS certificate validity capped at 200 days
Public TLS certificates issued on or after 15 March 2026 may not exceed 200 days. Two further reductions are already scheduled.
Maximum subscriber certificate validity is reduced in phases: 398 → 200 days (2026-03-15), → 100 days (2027-03-15), → 47 days (2029-03-15). Domain and IP validation reuse periods shrink alongside each phase.
Impact by role
Executive
owns: Budget, risk appetite, board reportingacts within: Planning cycle“What does this cost, and what breaks if we do nothing?”
Implication: Renewal volume roughly doubles this year and rises ~8x by 2029 without automation.
Next action: Fund certificate discovery and lifecycle automation in the current planning cycle.
- Proposed
- 2024-10-09
- Published
- 2025-04-11
- Effective
- 2026-03-15
- Last verified
- 2026-08-01
Source (Standards body): CA/Browser Forum — Ballot SC-081v3 (certificate lifetime reduction). Reviewed by RootCerts editorial — PKI standards desk.
Status mix
- Effective20%
- Published60%
- Experimental20%
Deadline panel
200-day maximum TLS validity
2026-03-15Public TLS certificates capped at 200 days.
in effect
100-day maximum TLS validity
2027-03-15Second phase of the lifetime reduction.
in 219 days
DCV reuse reduced to 100 days
2027-03-15Domain control validation data reuse shortens with validity.
in 219 days
47-day maximum TLS validity
2029-03-15Scheduled end state, with 10-day validation reuse.
in 950 days
NIST target to deprecate 112-bit classical algorithms
2030-12-31Planning target for retiring quantum-vulnerable public-key cryptography.
in 1,606 days
NIST target for completed PQC migration
2035-12-31Government planning horizon for full migration.
in 3,432 days
Standards activity
Recently updated developments
- Published standardACME
ACME Renewal Information (ARI) published as RFC 9773
ACME servers can now tell clients when to renew, so renewals can be rescheduled by the CA during mass-revocation events.
EFFECTIVE 2025-06-01 · IETF
- Published standardPQC
NIST finalizes ML-KEM, ML-DSA and SLH-DSA
The first principal post-quantum standards are final. NIST advises organizations to inventory quantum-vulnerable cryptography and plan migration now.
EFFECTIVE 2024-08-13 · NIST
- Published standardCertificate Transparency
Certificate Transparency v2 (RFC 9162) Merkle tree auditing
CT logs use binary Merkle trees so any client can verify that a certificate was logged without downloading the log.
EFFECTIVE 2021-12-01 · IETF
- Emerging / experimentalPQC
Merkle Tree Certificates explored in IETF PLANTS
An emerging construction that integrates certificate issuance with a public log to cut the overhead of large PQC signatures and very short lifetimes.
NO EFFECTIVE DATE · IETF
Explore by objective
Start from what you need to do
I need to understand certificates.
Certificate Atlas, anatomy, chains and fundamentals.
I need to automate operations.
Lifecycle lab and maturity model.
I need to prepare for 47-day TLS.
Timeline, calculator, action plan.
I need to plan for PQC.
Algorithms, estimates, migration journey.
I need to track standards.
Feed, pipeline and calendar views.
I need to prevent outages.
Chain building and failure modes.
Ready to move from understanding to implementation?
rootcerts.com stays ungated: the calculators, timelines and standards tracking above require no account. When you are ready to operationalize, Sectigo can help.