Website certificate lifespans will become significantly shorter following an industry vote to reduce the maximum validity of SSL/TLS certificates to 47 days by 2029, affecting every business operating a website.
The ballot measure, passed by the Certification Authority Browser Forum (CA/Browser Forum) – a consortium of certificate authorities, browser vendors and tech companies – will gradually reduce certificate lifespans from the current 398 days with a phased approach.
According to the Forum, the first stage is to shorten TLS certificate lifespans and Domain Control Validation (DCV) reuse periods down to 200 days by March 15th 2026.
A year later, both the TLS lifespan and DCV reuse period will be reduced to 100 days each, with the final phase being reached by March 2029, when TLS certificates will expire after 47 days and the DCV reuse period will shrink to just ten days.
In pushing for the change, Apple wrote in a preamble to the vote that the phased approach would allow the plan to be altered if necessary and ‘shift more unknown unknowns towards known unknowns and known knowns’.
Ultimately, the change – led by early efforts from both Apple and Google – is designed to enhance security by limiting the time private keys can be compromised and exposed to potential threats, reducing the risk of man-in-the-middle attacks and data breaches.
Since every business operating a website will have to replace its certificates much more frequently, the move might also encourage more firms to use automation, already being recognised as best practice, as it encompasses the ability to cut down on time-consuming, error-prone issuance processes while allowing faster adoption of emerging security capabilities.
“The industry’s unified support for reducing certificate lifespans to 47 days reflects a shared commitment to enhancing digital security and trust for all,” said Tim Callan, chief compliance officer at Sectigo and vice-chair of the CA/Browser Forum.
“This pivotal and positive advancement for our industry underscores the importance of agility and proactive risk management in today’s threat landscape while preparing for the risks of the quantum era.
“We believe it’s important for organisations to view this industry shift not as an abrupt or radical change, but rather an incremental step towards future proofing their business.”
Recommended reading
- What Are the Most Commonly Misunderstood Tech Terms?
- Are Organisations Ready for 90-Day TLS Certificates?
- 80% of NEDs Think Current Board Efforts Inadequate for Overseeing AI
Although the Forum’s ballot passed without any ‘No’ votes, five members of the coalition abstained, with Computer World reporting that one unnamed firm wrote a note to the group reading “we are unconvinced that the most restrictive terms are necessary, to go all of the way down to 47 days.”
Among those voting ‘Yes’ were Apple, Google, Mozilla, Amazon, Microsoft, and Visa.
Now passed, the idea remained a hotly debated issue in the IT sphere for more than a year, with a security expert earlier telling Computer World that the firms urging for shorter certificate lifespans stood to gain the most with the move, as IT departments would be forced to update site certificates every six weeks, pay for the privilege every time, resulting in thousands more being spent every year.





