Skip to content
rcrootcerts.com

Change · TLS

47-Day TLS Center

Shorter certificate lifetimes are not a new duration setting. They change who owns certificates, how they are issued, and what happens when a renewal is missed.

200-day phase in effect100 days from 2027-03-1547 days from 2029-03-15

One-sentence answer

Public TLS certificates shrink to 47 days by March 2029

Manual renewal becomes untenable, discovery becomes a prerequisite for reliability, and validation-data reuse windows shrink alongside validity — so certificate operations must become a continuous system rather than an annual administrative task.

Live transition timeline

Where the maximum validity stands

  1. 2020-09-01

    398 days

    1.0 renewals per certificate per year

    Previous state

  2. 2026-03-15

    200 days

    2.1 renewals per certificate per year

    You are here

  3. 2027-03-15

    100 days

    5.2 renewals per certificate per year

    Next transition

  4. 2029-03-15

    47 days

    21.5 renewals per certificate per year

    Scheduled end state

Tool

Renewal workload calculator

All assumptions are visible and editable. Nothing is stored or sent anywhere.

Renewal events / year

2,576

Renewal events / week

50

Human hours / year

827

≈ 0.52 FTE

Expected failed renewals

28

Manual renewals only

Estimated risk exposure

255,071

Failures × incident cost

Automation gap

660

Certificates still renewed by hand

Assessment

Certificate automation maturity

  • Certificate discovery across all networks and cloud accounts
  • Every certificate has a named owner
  • Renewal is automated (ACME or CLM orchestration)
  • Deployment of renewed certificates is automated
  • Domain and IP validation is automated
  • Expiry and chain monitoring alerts before failure
  • Revocation and mass-replacement is a rehearsed process
  • Key rotation happens on renewal
  • Multi-CA visibility in a single inventory
  • Policy is enforced at issuance, not by review
  • Certificate incidents have a documented response runbook

Result

0%

Manual

Renewals depend on people remembering. 47-day validity is not survivable in this state.

  1. 0%+ · Manual
  2. 30%+ · Scripted
  3. 55%+ · Partially orchestrated
  4. 78%+ · Fully managed
  5. 93%+ · Crypto-agile

Architecture walkthrough

Certificate operations as one continuous system

  1. Discovery
  2. Inventory
  3. Ownership
  4. Policy
  5. Issuance
  6. Deployment
  7. Monitoring
  8. Renewal
  9. Revocation
  10. Evidence

Role-based action plan

What to do next

CISO

  • Fund discovery and automation now
  • Track renewal failure as an availability risk
  • Set a dated target for full automation coverage

PKI team

  • Re-tune issuance profiles for shorter validity
  • Enable ACME and ARI everywhere possible
  • Shorten validation reuse assumptions

Platform

  • Inventory every termination point
  • Automate deployment, not just issuance
  • Alert on chain and expiry before users notice

App owners

  • Claim ownership of your certificates
  • Remove certificate pinning
  • Test renewal in a non-production environment