As of March 15, every publicly trusted certificate authority is required to cap new TLS certificates at 200 days maximum validity, down from the 398-day ceiling that had been standard since 2020. This is the first of three scheduled reductions under Ballot SC-081v3, which the CA/Browser Forum passed with unanimous support (29 votes in favor, zero opposed) back in April 2025.
The full schedule
- March 15, 2026 — 200 days (now in effect)
- March 15, 2027 — 100 days
- March 15, 2029 — 47 days, the final target
Domain validation reuse periods are shrinking on the same schedule, meaning re-verification of domain control will need to happen far more often too — by the 2029 milestone, every 10 days rather than the current 398.
Why 47 days specifically
The number isn't arbitrary. It reflects a deliberate design goal: short enough that manual certificate renewal becomes impractical at scale, forcing automation, but long enough that automated systems have comfortable room to operate without excessive renewal overhead. It also roughly halves again from the 100-day milestone, continuing the pattern.
What this actually changes for a well-automated site
If your renewal process is already automated — the exact scenario our own Certbot automation guide walks through — this milestone is close to invisible. The real-world impact falls hardest on organizations still relying on manual renewal or long-lived certificates bought once and forgotten, since the gap between "how often you're used to thinking about this" and "how often it now actually needs to happen" just widened considerably. If you haven't audited how many of your certificates are actually under working automation, this milestone is a reasonable prompt to do it.
This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.