The clock is already running on 47-day certificates
Public TLS certificate lifetimes are shrinking on a fixed schedule, driven by Apple, Google, and Mozilla through the CA/Browser Forum. Manual renewal does not scale to this cadence. Automation does.
Talk to Our Automation TeamFrom 398 days to 47, on a published timeline
Domain validation reuse periods shrink on the same schedule, so the compression hits both issuance and the verification work behind it.
We're already living in the 200-day step. Every certificate issued today needs a renewal plan built for the 47-day endpoint, not the current window.
What breaks at a 47-day cadence
None of this is hypothetical. Teams running annual or quarterly renewal habits hit these limits first.
Spreadsheet tracking
A renewal reminder that works once a year does not hold up to a renewal every 47 days across hundreds of endpoints.
Manual provisioning
A ticket-based request-and-issue workflow that used to take days becomes the bottleneck itself at this frequency.
Single-owner knowledge
When one person on the team "handles certificates," a 47-day clock turns their time off into an outage risk.
Change-control friction
A manual install that has to clear a change board cannot keep pace with a cycle shorter than most change windows.
Automation is the price of entry. Here's what mature automation looks like.
The answer is not "trust us to handle it." It's building the certificate lifecycle into your infrastructure the same way you'd build any other automated process.
ACME protocol automation
Issue and renew certificates programmatically. No manual CSR generation, no portal logins, no missed renewal.
CLM (Certificate Lifecycle Management)
Discover, monitor, and automate every certificate across your infrastructure from one platform, replacing ad hoc per-team requests. See how it works →
Hosted PKI
Centralize certificate lifecycle management across teams without standing up and maintaining your own CA infrastructure. See how it works →
Private CA
Issue and manage internal-use certificates on your own validity terms, separate from the public trust timeline.
The 47-day requirement isn't optional. The path to it is.
Tell us how certificates get issued and renewed today, and we'll help you find the automation path that fits your infrastructure.
Talk to Our Automation TeamAlso see how this shift fits into the broader move to a Digital Trust Platform →