Why Are SSL Certificate Lifespans Shrinking?
· Industry
Over the past several years, SSL/TLS certificate validity periods have kept shrinking. Certificates that once lasted up to 5 years were cut to 2 years, then to 398 days. Now a new phased reduction schedule is in effect: 200 days today, 100 days as of March 15, 2027, and down to 47 days by March 15, 2029.
This isn't a decision made by a single company — it comes from the CA/Browser Forum, the body where browser vendors (Google, Apple, Mozilla, Microsoft) and certificate authorities jointly set the rules that bind the entire industry. So why is this happening?
Why Is It Shrinking? The Real Reasons
- Smaller breach/error window: If a certificate's private key is stolen, or a CA mistakenly issues a faulty certificate, the longer that certificate remains valid, the longer an attacker can exploit it. Shorter lifespans automatically shrink this "risk window."
- Revocation doesn't reliably work: In theory, a stolen certificate can be revoked and browsers notified via OCSP/CRL. In practice, most browsers don't check this reliably, or don't check at all. Short-lived certificates compensate for this gap in revocation infrastructure with a simple guarantee: it expires on its own soon anyway.
- It forces automation: As long as certificates are renewed manually every year or two, human error (forgetting, misconfiguration, last-minute scrambling) is inevitable. Shorter lifespans make manual management impractical, pushing the whole industry toward automated protocols like ACME — which means a more secure web in the long run.
- Cryptographic agility: When a new vulnerability is found or an encryption algorithm is weakened, updating millions of long-lived certificates can take years. With short-lived certificates, the industry can roll out new standards much faster.
Timeline
- Today: 200 days
- March 15, 2027: 100 days
- March 15, 2029: 47 days
How Is pekiSSL Preparing for This?
Shrinking certificate lifespans mean two things are no longer the same for our customers: the certificate's own validity period, and the subscription period you pay for (e.g., 1 year). This means your certificate may need to be reissued multiple times within a single paid subscription term.
To make this invisible to you, pekiSSL has built:
• A system that automatically tracks the real expiration date issued by the CA.
• A dashboard for our team listing certificates approaching expiration.
• We handle the reissue ourselves, and automatically email you the new files to download once ready.
You simply keep an up-to-date certificate for as long as your subscription is active (e.g., 1 year) with no extra charge — shrinking lifespans create no extra work on your end.