The maximum SSL certificate lifetime is no longer about a year. Since 15 March 2026, publicly trusted SSL/TLS certificates can be valid for at most 200 days, and the first of those certificates started expiring in early October 2026.
The limit keeps shrinking until it reaches 47 days in 2029. For websites with automated renewal this is mostly invisible; for anything renewed by hand, it means more renewals and more chances of an expired certificate taking a site offline.
Key takeaways
The maximum SSL certificate lifetime is 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029.
Certificates issued around mid-March 2026 began expiring in early October 2026.
Automated renewal makes the change painless; manually installed certificates are the main outage risk.
Shorter lifetimes also prepare the web to switch cryptography quickly, including to post-quantum algorithms.
What Is the New SSL Certificate Lifetime Schedule?
The schedule comes from the CA/Browser Forum's Ballot SC-081v3, approved in April 2025. It lowers the maximum SSL certificate lifetime in three steps, and also shortens how long a certificate authority can reuse a previous domain validation.
| From | Maximum certificate lifetime | Domain validation reuse |
| Before March 2026 | 398 days | 398 days |
| 15 March 2026 | 200 days | 200 days |
| 15 March 2027 | 100 days | 100 days |
| 15 March 2029 | 47 days | 10 days |
Under the CA/Browser Forum's Ballot SC-081v3 schedule.
In practice, a site that renewed once a year now renews about twice a year, and by 2029 roughly every six weeks. The 10-day validation reuse in 2029 also means domain ownership checks will run almost every time a certificate is issued.
Why Is the SSL Certificate Lifetime Getting Shorter?
A certificate is only accurate on the day it is issued. Over time, a domain can change owners, a private key can leak or a validation mistake can surface, and revoking certificates has proven unreliable at internet scale. The CA/Browser Forum's answer is to make certificates expire sooner, so wrong information cannot stay trusted for long.
The second reason is crypto-agility: the ability to replace algorithms across the web quickly. That matters because post-quantum cryptography is arriving. If every certificate is replaced every few weeks, moving the whole web to new algorithms becomes a routine renewal rather than a multi-year project.
!
"Harvest now, decrypt later" is already a risk. Encrypted data captured today can be stored and decrypted once quantum computers are capable enough, so long-lived sensitive data needs protection now.
Where Does Post-Quantum Protection Stand Today?
Part of it is already live. Post-quantum key exchange inside the TLS handshake is enabled by major browsers and CDNs; Cloudflare reports that over two-thirds of browser traffic to its network is protected with post-quantum encryption. This protects the connection without any change to your certificate.
Post-quantum certificates themselves, which handle authentication, are not yet broadly available for ordinary websites. Governments are setting deadlines for the move:
- United States: Executive Order 14412 (June 2026) requires federal agencies to move high-value systems to post-quantum encryption by 31 December 2030.
- India: a Department of Science and Technology task force report (February 2026) targets full quantum-safe adoption for critical information infrastructure by 2029, with other organisations following by 2033.
Which Websites Does the Shorter SSL Certificate Lifetime Affect?
Every public HTTPS site is affected, but the effort depends entirely on how certificates are renewed.
Low risk
Automated renewal
Certificates issued and renewed by your host, CDN or an ACME client simply renew more often in the background.
What to doConfirm automation covers every domain and subdomain.
High risk
Manually installed certificates
Certificates copied to a mail server, load balancer, firewall or staging box do not renew themselves and are easy to forget.
What to doAutomate them or track every expiry date.
What Should You Do Now?
Work through these five steps before the next drop to 100 days in March 2027:
01List every certificateInclude all domains, subdomains and internal services, and record the issuer and expiry date of each.
02Check expiry datesUse the free HostGraber SSL checker to see the remaining SSL certificate lifetime for any domain without logging into the server.
03Automate renewalUse your host's managed SSL or an ACME client such as Certbot wherever a certificate is still renewed by hand.
04Find copied certificatesFlag certificates installed on mail servers, appliances and load balancers, which automation often misses.
05Set expiry alertsAdd monitoring that warns you weeks before any certificate expires, as a safety net for automation.
i
Quick test: if you cannot say who renews a certificate and how, treat it as manual. Those certificates cause most expiry outages.
Need a certificate for a new site or server?
HostGraber SSL certificates include free reissuance and installation support.
The Bottom Line
The shorter SSL certificate lifetime is permanent and will keep shrinking until 2029. Automate every renewal you can, keep a list of the certificates you cannot, and check expiry dates regularly with the SSL checker.
FAQ
What is the maximum SSL certificate lifetime in 2026?
From 15 March 2026, the maximum lifetime for a publicly trusted SSL/TLS certificate is 200 days. It drops to 100 days on 15 March 2027 and 47 days on 15 March 2029.
Do I need to do anything if my hosting provider manages SSL?
Usually not, because automated renewal simply runs more often. Confirm with your provider that every domain and subdomain is covered.
Will shorter certificate lifetimes slow down my website?
No. The lifetime only changes how often a certificate is replaced; it does not change how each visitor's connection is encrypted.
What does "harvest now, decrypt later" mean?
It means attackers can store encrypted data today and decrypt it later once quantum computers are powerful enough. It mainly threatens data that must stay confidential for many years.
Is post-quantum cryptography already protecting my website?
Partly. Post-quantum key exchange is already used by major browsers and CDNs, but post-quantum certificates for ordinary websites are not yet broadly available.
Talk to HostGraber
Want your certificates checked before they expire?
Tell us your domains and servers, and our team will help you find manual certificates and plan automated renewal.