India
Global
SSL certificate lifetime timeline 2026 to 2029

Your SSL Certificate Now Expires in 200 Days, Not a Year

SSL certificate lifetimes officially shrank to 200 days starting March 2026, on a path to just 47 days by 2029. Here's why it's happening, what post-quantum cryptography has to do with it, and what your website actually needs to do.

The New Certificate Lifetime Schedule

SSL certificate lifetime rules changed for good on March 15, 2026 — that's the date a CA/Browser Forum rule change quietly took effect, cutting the maximum lifetime of publicly trusted SSL certificates, with more cuts already scheduled. Cloudflare's own analysis of the related U.S. executive order lays out just how far-reaching this shift already is.

March 2026
200 days
March 2027
100 days
March 2029
47 days

Certificates issued right around the March 2026 cutover are worth checking specifically — anything issued between mid-March and early April 2026 is already expiring within weeks of when many teams would have expected a full year of runway.

Why This Is Happening: The Post-Quantum Connection

Shorter certificate lifetimes aren't really about SSL security in isolation — they're infrastructure preparation for something bigger. When publicly trusted post-quantum certificates become available, expected in late 2026 or 2027, the entire web will need the ability to rotate its whole certificate population in weeks, not years. A 47-day certificate lifetime makes that possible. A 398-day one, the old standard, does not.

The Real Risk Driving Urgency: "Harvest Now, Decrypt Later"

Encrypted traffic and data captured today can be stored indefinitely and decrypted later, once quantum computing capability catches up — a strategy called "harvest now, decrypt later." Data with long-term sensitivity — personal information, financial records, trade secrets, health data — carries risk today even though decryption capability doesn't exist yet.

60%+
post-quantum-capable client traffic, Feb 2026 (up from under 3% in 2024)
13%
of enterprises have actually deployed post-quantum cryptography

Where Post-Quantum Protection Actually Stands Today

Already live at scale

Post-quantum key exchange (ML-KEM) inside TLS handshakes is already deployed by Cloudflare, Chrome, Firefox, Microsoft, AWS, and major CDN providers — protecting the session layer automatically, without changing anything about your certificate.

Not yet available to ordinary site owners

Post-quantum certificate signatures for publicly trusted certificates aren't finalized yet — that's expected in late 2026 or 2027, which is exactly why shorter lifetimes are rolling out now, so infrastructure is ready to rotate quickly once they arrive.

Government Deadlines Are Already Locked In

  • United States — Executive Order 14412 (June 2026) sets a Dec 31, 2030 deadline for federal agencies to migrate sensitive systems to post-quantum encryption.
  • NIST — moves all remaining FIPS 140-2 module certifications to "historical" status on September 21, 2026.
  • India — MeitY and CERT-In published a national roadmap (July 2025) directing finance, defense, and healthcare to migrate first, with a national task force following in early 2026.

What This Actually Means for Your Website

The practical impact depends heavily on how your certificates are managed. For most website owners, it's less disruptive than it sounds — SSL certificate lifetime shrinking mainly matters if renewal isn't automated.

  • Managed hosting with automated SSL just runs the renewal cycle more often — no manual action needed.
  • Manually managed or copied certificates are the real risk. A certificate copied onto a mail server, a wildcard pasted into a load balancer, a staging box nobody logs into — these don't renew themselves, and under a 47-day cycle they'll break within weeks.
  • An inventory now beats a fire drill later. The certificates most likely to cause an outage are the ones nobody remembers exists.

The Practical Checklist

  1. Inventory every certificate you actually have — every domain, subdomain, and internal service, pulled from the certificates themselves. HostGraber's free SSL checker tool is a quick way to spot-check expiration dates without logging into every server individually.
  2. Identify anything issued in the March-April 2026 window specifically, since those hit shorter expiry sooner than expected.
  3. Set up automated renewal wherever it isn't already in place — the single highest-leverage step.
  4. Flag manually installed or copied certificates — the ones automation typically misses.
  5. Confirm with your hosting provider how they handle this — platform-managed SSL means much lower exposure.

Not sure your certificates are set up for automated renewal?

HostGraber's SSL certificate plans include managed options with automated renewal, so this transition happens in the background.

Frequently Asked Questions

Q. Do I need to do anything if my SSL is managed by my hosting provider?
In most cases, no — if your host handles certificate issuance and renewal automatically, the shorter lifetime is handled by their automation without any action needed. Worth confirming directly with your provider rather than assuming.
Q. What's the actual danger of "harvest now, decrypt later"?
Data encrypted today with current algorithms could be captured and stored by an adversary now, then decrypted later once quantum computing capability exists — a real concern for long-term sensitive data even though decryption capability doesn't exist yet.
Q. Is post-quantum cryptography already protecting my website?
Partially, and probably without you doing anything. If you're behind a major CDN or hosted on large platforms, post-quantum key exchange protection is likely already active. Certificate signatures specifically are still emerging, expected late 2026 or 2027.
Q. Will shorter certificate lifetimes slow down my website?
No — research on shortened-lifetime and post-quantum TLS handshakes shows negligible performance impact, generally one to two milliseconds under realistic conditions. The real challenge is renewal automation, not runtime performance.

Want your certificates audited before something expires?

Get a quick check on your current SSL setup.

Talk to Our Team →