SC081v3 passes: the roadmap to shorter TLS certificates
Review the April 2025 ballot result and distinguish certificate validity from validation-data reuse.
Contents of this article
What happened
On April 11, 2025, the CA/Browser Forum published the successful SC081v3 ballot result, supporting phased reductions in publicly trusted TLS certificate validity and validation-data reuse. The roadmap runs from 2026 to 2029 and was incorporated into the TLS Baseline Requirements.
Implications for website operations
For operations teams, subscription term, certificate lifetime and validation reuse are three different concepts. Paying annually does not mean one certificate can remain unchanged for a year. Workflows need more frequent issuance, deployment and external handshake verification.
Operational next steps
Prioritize manual certificate-copy steps and assign ownership for renewal failures. When automating, retain chain validation, permission separation and rollback, then extend coverage to standby nodes and rarely visited subdomains.
