SSL certificate lifetimes officially shrank to 200 days starting March 2026, on a path to just 47 days by 2029. Here's why it's happening, what post-quantum cryptography has to do with it, and what your website actually needs to do.
SSL certificate lifetime rules changed for good on March 15, 2026 — that's the date a CA/Browser Forum rule change quietly took effect, cutting the maximum lifetime of publicly trusted SSL certificates, with more cuts already scheduled. Cloudflare's own analysis of the related U.S. executive order lays out just how far-reaching this shift already is.
Certificates issued right around the March 2026 cutover are worth checking specifically — anything issued between mid-March and early April 2026 is already expiring within weeks of when many teams would have expected a full year of runway.
Shorter certificate lifetimes aren't really about SSL security in isolation — they're infrastructure preparation for something bigger. When publicly trusted post-quantum certificates become available, expected in late 2026 or 2027, the entire web will need the ability to rotate its whole certificate population in weeks, not years. A 47-day certificate lifetime makes that possible. A 398-day one, the old standard, does not.
Encrypted traffic and data captured today can be stored indefinitely and decrypted later, once quantum computing capability catches up — a strategy called "harvest now, decrypt later." Data with long-term sensitivity — personal information, financial records, trade secrets, health data — carries risk today even though decryption capability doesn't exist yet.
Post-quantum key exchange (ML-KEM) inside TLS handshakes is already deployed by Cloudflare, Chrome, Firefox, Microsoft, AWS, and major CDN providers — protecting the session layer automatically, without changing anything about your certificate.
Post-quantum certificate signatures for publicly trusted certificates aren't finalized yet — that's expected in late 2026 or 2027, which is exactly why shorter lifetimes are rolling out now, so infrastructure is ready to rotate quickly once they arrive.
The practical impact depends heavily on how your certificates are managed. For most website owners, it's less disruptive than it sounds — SSL certificate lifetime shrinking mainly matters if renewal isn't automated.
HostGraber's SSL certificate plans include managed options with automated renewal, so this transition happens in the background.
Get a quick check on your current SSL setup.
From your first website to production-grade cloud, dedicated servers and your own infrastructure.
Tell us what you're building and we'll help you find the right HostGraber solution.
Choose the option that best matches what you're looking for.
Choose the closest option.
This helps us estimate the right level of infrastructure.
Send them to our team and we'll recommend the most suitable HostGraber setup.