Certificate Lifecycle Management

The 100-Day Certificate Validity Countdown: What Changes and How to Prepare

Executive Summary

  • What changes: From 15 March 2027, publicly trusted TLS certificates can be valid for a maximum of 100 days, down from 200 days today. By 15 March 2029, the limit falls to 47 days.
  • Why it matters: Renewal volume roughly doubles in 2027 and keeps climbing. Manual tracking will not scale, and every missed renewal is a potential outage.
  • What to do: Discover every certificate, automate issuance and renewal, and validate the process before March 2027. Build for 47 days, not just 100.

On 1 October 2026, the first wave of 200-day TLS certificates issued under the new CA/Browser Forum rules reached the end of their life. That milestone is a preview. In under six months, 100-day certificate validity becomes the ceiling for every publicly trusted TLS certificate, and organisations that are still renewing certificates by spreadsheet and calendar reminder will feel the pressure first.

This guide breaks down the full CA/Browser Forum schedule, explains why the industry is moving this way, quantifies what it costs to ignore, and sets out a practical plan to get ahead of the deadline.

The CA/Browser Forum Schedule at a Glance

In April 2025, the CA/Browser Forum adopted Ballot SC-081v3 with 25 votes in favour, none against and five abstentions. Apple proposed the ballot, and Google, Mozilla and Microsoft supported it. The ballot shortens three timelines in phases.

Effective date Max certificate validity Domain validation (DCV) reuse
Before 15 March 2026 398 days 398 days
15 March 2026 200 days 200 days
15 March 2027 100 days 100 days
15 March 2029 47 days 10 days

Source: CA/Browser Forum Ballot SC-081v3

Certificate validity

The headline change is the maximum lifetime. An organisation that renewed once a year under 398-day certificates now renews about twice a year, will renew about four times a year from March 2027, and roughly eight or more times a year from 2029.

Domain control validation reuse

DCV reuse defines how long a CA can rely on an earlier proof that you control a domain. At 10 days in 2029, nearly every renewal will need fresh validation. That makes DNS- or HTTP-based automated validation essential, not optional.

Subject identity information reuse

For OV and EV certificates, the period a CA can reuse validated organisation details has also fallen to 398 days. Expect organisation re-verification annually.

One point of scope: SC-081v3 applies only to publicly trusted certificates. Certificates issued by a private, internal PKI are not bound by these limits, although many security teams are choosing to align with them.

Why the Industry Is Moving to Shorter Certificate Lifetimes

Revocation does not work reliably

When a private key is compromised or a certificate is mis-issued, revocation is meant to remove trust. In practice, browsers check revocation inconsistently. A shorter lifetime caps the damage window automatically, whether or not revocation reaches every client.

Crypto agility and post-quantum readiness

Short lifetimes force organisations to build repeatable, automated replacement. That same muscle is what will be needed to move to post-quantum algorithms, or to replace a distrusted CA, across thousands of endpoints in weeks rather than years — the crypto-agility that the post-quantum transition depends on.

What 100-Day Certificate Validity Changes Operationally

  • Renewal volume doubles. An estate of 5,000 public certificates moves from roughly 10,000 renewals a year to roughly 20,000.
  • Margins shrink. Most teams renew 30 days before expiry. On a 100-day certificate, that leaves a 70-day working life and less time to recover from a failed renewal.
  • Inventory accuracy becomes critical. A certificate nobody knows about cannot be renewed on time, and shorter lifetimes surface those blind spots faster.

Planning your move to 100-day certificates? CertiNext discovers every certificate in your estate and automates renewal before the deadline. Request a readiness assessment.

What It Costs to Ignore the Countdown

Outages

Expired certificates have caused some of the most visible service failures of recent years. An expired certificate in network software disrupted mobile data for an estimated 32 million O2 customers in the UK in December 2018. Microsoft Teams went down in February 2020 for the same reason, and Starlink suffered a global outage in April 2023 after a ground-station certificate expired. More examples are collected in eMudhra's certificate expiry outage case studies.

A commissioned 2026 Forrester Total Economic Impact study modelled a composite enterprise facing 18 to 22 certificate-related incidents a year, at an average of about USD 100,000 per incident. More renewals without automation means more chances for that to happen.

Compliance and audit exposure

Unplanned downtime undermines availability and resilience obligations under frameworks such as RBI and MAS TRM guidelines, BNM RMiT, SOC 2 and ISO 27001. A lapsed certificate can also expose data in transit, creating questions under privacy laws including the DPDP Act and GDPR.

Operational drag

Every manual renewal consumes engineering time across request, validation, installation and testing. Multiply that by four renewals per certificate per year and the hidden labour cost quickly exceeds the cost of automation.

Where Organisations Are Most Exposed

Shadow and unmanaged certificates

Certificates bought on a corporate card, issued by a cloud provider or deployed by a third party often sit outside central inventory. They are the most likely to expire unnoticed, as eMudhra's guide to certificate discovery explains.

Hard-to-automate endpoints

Load balancers, network appliances, legacy servers and embedded devices often lack native ACME support. These need agent-based or API-based connectors to be included in automated renewal.

Hardcoded and pinned certificates

Mobile apps and integrations that pin a specific certificate or intermediate will break when certificates rotate more often. Pinning strategies should be reviewed well before March 2027.

How to Get Ahead: A Readiness Plan Before March 2027

With roughly 165 days remaining, a phased plan keeps the work manageable.

  1. Discover (October to November 2026): Scan networks, cloud accounts and CT logs to build a complete inventory of public and private certificates, with owners, expiry dates and issuing CAs.
  2. Prioritise (November 2026): Rank certificates by business impact. Customer-facing, payment and API endpoints come first.
  3. Automate (December 2026 to January 2027): Deploy ACME, DNS-based validation and connectors for load balancers, web servers and cloud services. Remove manual hand-offs from renewal.
  4. Validate (February 2027): Run renewal drills on 100-day certificates, test alerting and escalation, and confirm rollback steps.
  5. Operate (from March 2027): Track renewal success rates and time to replace as standing KPIs, and report them to leadership.

Build for 47 Days, Not Just 100

Treating March 2027 as the finish line creates a second scramble in 2029. A process that handles 100-day certificates manually will not survive 47-day certificates with 10-day DCV reuse. Design now for full automation: ACME with ACME Renewal Information (ARI) so CAs can signal renewal windows, DNS-based validation that runs without human input, and policy that blocks non-compliant certificates at request time. eMudhra's guide to automating certificate renewal with ACME covers the protocol in detail.

How Certificate Lifecycle Management Automation Closes the Gap

A full-feature certificate lifecycle management platform turns the countdown into routine operations. CertiNext from eMudhra discovers certificates across on-premises, cloud and hybrid environments, then automates issuance, renewal, provisioning and revocation through ACME, APIs and native connectors.

CertiNext supports multiple public and private CAs from a single console, which simplifies CA migration if ever needed. Policy enforcement, alert escalation and trust-store monitoring help teams catch problems before they become outages. eMudhra operates as a WebTrust-audited, publicly trusted CA and is India's largest licensed CA, bringing issuance and lifecycle management expertise together.

Key Takeaways

  • 100-day certificate validity takes effect on 15 March 2027; 47-day validity follows on 15 March 2029.
  • Renewal volume doubles in 2027 and roughly doubles again by 2029.
  • Expired certificates cause real outages, audit findings and wasted engineering time.
  • Complete discovery is the first step; full automation is the only sustainable end state.
  • Plan for 47 days now to avoid repeating the effort in 2029.

Frequently Asked Questions

When does 100-day certificate validity take effect?

From 15 March 2027, publicly trusted TLS certificates cannot be issued with a validity longer than 100 days. Certificates issued before that date keep their original validity.

Does the CA/Browser Forum schedule apply to private certificates?

No. SC-081v3 covers publicly trusted TLS certificates only. Internal PKI certificates are governed by your own policy, though aligning with shorter lifetimes is good practice.

What is DCV reuse and why is it shrinking?

DCV reuse is the period a CA can rely on an earlier proof of domain control. It falls to 100 days in 2027 and 10 days in 2029, so validation must be automated.

Will 100-day certificates cost more?

Pricing depends on the CA, and many offer subscription plans that cover repeated reissuance within a term. The real cost increase comes from manual renewal labour and outage risk.

Is ACME enough to prepare?

ACME automates issuance and renewal for supported servers. Most enterprises also need discovery, connectors for non-ACME devices, policy control and reporting, which a CLM platform provides.

How long does it take to automate certificate renewal?

It depends on estate size and complexity. Many organisations complete discovery in weeks; full automation of a large estate typically takes several months, so starting now matters.

Get Ahead of the 100-Day Deadline

March 2027 is closer than it looks. CertiNext discovers every certificate in your estate and automates renewal end to end, so shorter lifetimes never become outages. Explore CertiNext certificate lifecycle management or talk to eMudhra about a readiness assessment.

CertiNext Editorial
About the Author

CertiNext Editorial

CertiNext Editorial represents the collective voice of CertiNext, delivering expert insights on PKI modernization, crypto-agility, and the future of machine identity. Our team of industry specialists curates and delivers thought-provoking content aimed at helping enterprises navigate certificate lifecycle management with confidence.

Ready to Try?

Talk to our team about how eMudhra can help secure your digital workflows with PKI, eSignatures and identity solutions.

Connect with sales