CA/Browser Forum Ballot SC-081

The clock is already running on 47-day certificates

Public TLS certificate lifetimes are shrinking on a fixed schedule, driven by Apple, Google, and Mozilla through the CA/Browser Forum. Manual renewal does not scale to this cadence. Automation does.

Talk to Our Automation Team
The shift, by the numbers

From 398 days to 47, on a published timeline

Domain validation reuse periods shrink on the same schedule, so the compression hits both issuance and the verification work behind it.

398
Days
Historical maximum, pre-2020
200
Days
Live since March 15, 2026
100
Days
Effective March 15, 2027
47
Days
Effective March 15, 2029

We're already living in the 200-day step. Every certificate issued today needs a renewal plan built for the 47-day endpoint, not the current window.

The operational reality

What breaks at a 47-day cadence

None of this is hypothetical. Teams running annual or quarterly renewal habits hit these limits first.

Spreadsheet tracking

A renewal reminder that works once a year does not hold up to a renewal every 47 days across hundreds of endpoints.

Manual provisioning

A ticket-based request-and-issue workflow that used to take days becomes the bottleneck itself at this frequency.

Single-owner knowledge

When one person on the team "handles certificates," a 47-day clock turns their time off into an outage risk.

Change-control friction

A manual install that has to clear a change board cannot keep pace with a cycle shorter than most change windows.

Where SSL.com fits

Automation is the price of entry. Here's what mature automation looks like.

The answer is not "trust us to handle it." It's building the certificate lifecycle into your infrastructure the same way you'd build any other automated process.

ACME protocol automation

Issue and renew certificates programmatically. No manual CSR generation, no portal logins, no missed renewal.

CLM (Certificate Lifecycle Management)

Discover, monitor, and automate every certificate across your infrastructure from one platform, replacing ad hoc per-team requests. See how it works →

Hosted PKI

Centralize certificate lifecycle management across teams without standing up and maintaining your own CA infrastructure. See how it works →

Private CA

Issue and manage internal-use certificates on your own validity terms, separate from the public trust timeline.

The 47-day requirement isn't optional. The path to it is.

Tell us how certificates get issued and renewed today, and we'll help you find the automation path that fits your infrastructure.

Talk to Our Automation Team

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details