200 days until TLS certificate lifetimes are cut in half…again!

Today marks 200 days until the next phase of the industry’s transition to shorter TLS certificate lifespans

On 15 March 2027, the maximum validity period for publicly trusted TLS certificates drops from 200 days to 100. The domain control validation (DCV) reuse period is halved on the same date, from 200 days to 100.

That second part is the one most people miss. DCV is how a certificate authority confirms you control the domain before anything is issued. That period is halved too, so it’s two processes accelerating at once.

Our partner Sectigo puts numbers on the operational impact. Measured against the annual renewal cycle most manual processes were originally designed around:

  • March 2026 — 200-day certificates: 2x renewals per year
  • March 2027 — 100-day certificates: 4–5x per year
  • March 2029 — 47-day certificates: 12x per year

Twelve, not eight, because you don’t run a certificate to its expiry date. Build in a two-week grace period so a failed renewal doesn’t become an outage, and 47-day certificates mean renewing roughly every month.

Multiply that by every certificate in your estate, then by every hand-off, ticket, change window and reinstallation each renewal drags along. Small environments absorb this. Large and distributed ones don’t. When a certificate expires, customers hit a browser warning telling them the site can’t be trusted. Most don’t come back.


The good news: 200 days until the next phase is enough, if you start now. Follow the steps below:

Step 1 — Awareness and discovery

First, make sure the organisation understands what’s coming. Run workshops, brief leadership as well as engineers, share material from credible sources so other departments grasp the business impact. Identify who actually owns public certificates today, admins, IT architects, engineers.

Second, discover every SSL/TLS certificate across the infrastructure. The goal is full visibility, so that no unmonitored or rogue certificate is left to cause an outage or a vulnerability.

Step 2 — Vendor technology inventory

Once you know which certificates exist, inventory the vendor technologies that depend on them. The purpose is prioritisation: knowing which systems and applications are business-critical, so nothing important is missed. Knowing which technologies depend on certificates lets you prepare for renewal cycles properly and avoid disruption to essential services.

Step 3 — Automation mapping

ACME is the preferred automation protocol for public certificate issuance, and Google treats it as central to automating certificate lifecycles. Source a list of ACME clients and map the available automation against the technology inventory from step 2.

Step 4 — Rollout plan

Set clear objectives and identify the resources, requirements and priorities needed for a smooth transition. Determine which systems and certificates are affected and make sure the right automation tooling is in place to handle frequent renewals. Sectigo’s four conditions for success: set the objective, establish timelines, assign responsibilities, allocate the necessary resources — software, people and processes.

Step 5 — Crypto agility

With the previous steps in place, the task is to make readiness permanent rather than a one-off project. Our digital certificate partner Sectigo recommends establishing a Cryptographic Center of Excellence: a dedicated team owning cryptographic policy, certificate management and compliance, with active backing from the C-suite so it stays a priority across departments instead of sitting with one team.

So what’s the bigger picture? Shorter lifetimes are good for internet security. A compromised certificate has less time to do damage. Certificates left behind by company closures, staff departures, mergers, domain transfers and rebrands age out on their own instead of lingering as forgotten liabilities.

But it requires a different operating model. Certificate management is moving from occasional manual renewals to continuously managed lifecycles. Certificate lifecycle management are shifting from nice-to-have to load-bearing infrastructure.

For most IT teams the question is no longer whether certificate management should be automated. It’s how much of it can be automated before the next phase begins.

Contact us to learn more about what you can start doing now!