Change · TLS
47-Day TLS Center
Shorter certificate lifetimes are not a new duration setting. They change who owns certificates, how they are issued, and what happens when a renewal is missed.
One-sentence answer
Public TLS certificates shrink to 47 days by March 2029
Manual renewal becomes untenable, discovery becomes a prerequisite for reliability, and validation-data reuse windows shrink alongside validity — so certificate operations must become a continuous system rather than an annual administrative task.
Live transition timeline
Where the maximum validity stands
2020-09-01
398 days
≈ 1.0 renewals per certificate per year
Previous state
2026-03-15
200 days
≈ 2.1 renewals per certificate per year
You are here
2027-03-15
100 days
≈ 5.2 renewals per certificate per year
Next transition
2029-03-15
47 days
≈ 21.5 renewals per certificate per year
Scheduled end state
Tool
Renewal workload calculator
All assumptions are visible and editable. Nothing is stored or sent anywhere.
Renewal events / year
2,576
Renewal events / week
50
Human hours / year
827
≈ 0.52 FTE
Expected failed renewals
28
Manual renewals only
Estimated risk exposure
255,071
Failures × incident cost
Automation gap
660
Certificates still renewed by hand
Assessment
Certificate automation maturity
- Certificate discovery across all networks and cloud accounts
- Every certificate has a named owner
- Renewal is automated (ACME or CLM orchestration)
- Deployment of renewed certificates is automated
- Domain and IP validation is automated
- Expiry and chain monitoring alerts before failure
- Revocation and mass-replacement is a rehearsed process
- Key rotation happens on renewal
- Multi-CA visibility in a single inventory
- Policy is enforced at issuance, not by review
- Certificate incidents have a documented response runbook
Result
0%
Manual
Renewals depend on people remembering. 47-day validity is not survivable in this state.
- 0%+ · Manual
- 30%+ · Scripted
- 55%+ · Partially orchestrated
- 78%+ · Fully managed
- 93%+ · Crypto-agile
Architecture walkthrough
Certificate operations as one continuous system
- Discovery
- Inventory
- Ownership
- Policy
- Issuance
- Deployment
- Monitoring
- Renewal
- Revocation
- Evidence
Role-based action plan
What to do next
CISO
- Fund discovery and automation now
- Track renewal failure as an availability risk
- Set a dated target for full automation coverage
PKI team
- Re-tune issuance profiles for shorter validity
- Enable ACME and ARI everywhere possible
- Shorten validation reuse assumptions
Platform
- Inventory every termination point
- Automate deployment, not just issuance
- Alert on chain and expiry before users notice
App owners
- Claim ownership of your certificates
- Remove certificate pinning
- Test renewal in a non-production environment