Shorter TLS certificate lifetimes: what website teams should change in 2026

Publicly trusted TLS certificates now have a maximum lifetime of 200 days for new issuance. Review the next milestones and practical steps for inventory, renewal and multi-node deployment.

Contents of this article

The 200-day limit is already in effect

Under the CA/Browser Forum TLS Baseline Requirements, publicly trusted TLS server certificates issued from March 15, 2026 until March 15, 2027 must not exceed 200 days. This limits newly issued certificates; it does not invalidate every previously issued certificate on that date or limit subscription purchases to 200 days.

The next milestones

From March 15, 2027 until March 15, 2029, the maximum becomes 100 days. From March 15, 2029, it falls to 47 days. A CA may issue shorter-lived certificates. Domain validation reuse has its own limits and should not be confused with certificate expiration.

Inventory every certificate termination point

A website may terminate TLS at a CDN, load balancer, origin and standby endpoint. Maintain a record of domains, certificate SANs, deployment locations, owners and expiry dates, including www, API subdomains and legacy endpoints. A complete purchase history does not prove that every node serves the current certificate.

Make renewal a verifiable workflow

Where supported, use ACME or the provider API to connect issuance, validation, deployment and service reloads. Restrict DNS validation credentials and send failure alerts to an accountable owner. Leave time for retries and manual recovery instead of scheduling renewal for the day of expiry.

Verify the certificate clients actually receive

After each renewal, verify hostname coverage, the certificate chain, expiry and handshakes from key regions. Then check HTTPS redirects and origin connections. Confirm multi-node updates in batches: successful issuance can still leave intermittent failures if some nodes continue serving an old certificate.

Related products and references

SSL certificates and deployment

CA/Browser Forum: TLS Baseline Requirements, section 6.3.2

Back to industry insights Contact technical support