How long can digital certificates be valid?
The validity periods for digital certificates are determined by their accepting organizations and always conform to the requirements given by the CA/Browser Forum, a voluntary group of certification authorities (CAs), vendors of Internet browser software, and suppliers of other applications that use X.509 v.3 digital certificates for SSL/TLS, code signing, and S/MIME. Sectigo is an active participant in the CA/B forum and helps shape the standards that govern digital certificate lifespans and trust requirements.
Certificate lifespans have been reduced multiple times over the years as part of industry efforts to improve security and limit risk exposure, and they are scheduled to shorten again. When software or a website presents an expired certificate, it can no longer be authenticated and is rejected by browsers and clients, often resulting in outages, service disruptions, and loss of user trust. Understanding certificate validity periods helps organizations plan renewals in advance and reduce the risk of avoidable downtime.
Below, we’ll walk through what digital certificates are, how long they're valid, how you know when they've expired, how you can renew an expired certificate, and the upcoming 47-day validity period adjustment.
What is a digital certificate?
A digital certificate is a file that proves the authenticity of an electronic system, such as a device, server, or user, through the use of public-key cryptography and the public key infrastructure (PKI).
By instituting this method of identification for devices and users, organizations can ensure their networks are secure. One popular type of digital certificate is an SSL/TLS certificate, which is used to confirm the authenticity of a website to a web browser.
Digital certificates contain identifiable information, such as domain name, organization, locality, and device information like IP address or serial number. They also include a public key that corresponds to a private key held by the certificate owner, which is used to verify identity and ensure the certificate has not been altered.
A public key certificate is issued by a certificate authority to bind an identity to a public key. The CA’s digital signature establishes trust, while the corresponding private key enables secure authentication and encryption.
Common types of digital certificates include:
Unless otherwise noted, this article will discuss SSL/TLS certificates specifically.
Do digital certificates expire?
Yes, digital certificates do expire. Validity periods vary by certificate type.
What determines the certificate validity period
Ultimately, the organizations that are accepting the certificates determine the validity period. These usually align with the recommendations from the CA/Browser Forum.
The CA/Browser Forum meets to vote on a variety of issues, often focusing on a set of baseline requirements for the issuance of trusted digital certificates. The CA/Browser Forum is not a governing body and has no enforcement capabilities. Acceptors have the final say and can be more or less strict than the recommendations made by the organization.
An important aspect of digital certificates is that the certificate lifecycle, including the maximum validity periods, is not determined by the issuer but by the acceptor, whose concerns and policies are reflected by the CA/Browser Forum through a ballot process.
Acceptors are organizations that build things, like operating systems and browsers. They are focused on protecting end-user information and not organizational processes. So companies such as Microsoft and Google would prefer to outright reject certificates that do not fit their criteria and deny access temporarily rather than simply accept all certificates.
How long are SSL/TLS certificates valid?
- As of March 15, 2026, public SSL certificates have a maximum validity period of 200 days
- March 15, 2027: Maximum validity will reduce to 100 days
- March 15, 2029: Maximum validity will reduce to 47 days
Starting in September of 2020, Transport Layer Security (SSL/TLS) certificates could not be issued for longer than 13 months (397 days). This change was first announced by Apple at the CA/Browser Forum. Now, we are in another phased reduction timeline that will end with reducing the maximum certificate validity to just 47 days.
Prior to 2015, you could obtain the certificate with a validity period of up to five years. That was reduced to three in 2015, and then two in 2018. At the end of 2019, a ballot was proposed at the CA/Browser Forum that would have reduced validity to one year and was voted down. This decision was then overruled by a change in policy by Apple the following year.
How do I know when my SSL/TLS certificate expires?
Currently, SSL certificates expire at a maximum 200 days from their issuance date. It is important to renew them before they expire. Waiting will cause serious disruptions for organizations and their customers. Certificate expiration dates are clearly communicated by their issuers and each has its own certificate renewal process.
CAs usually provide notification ahead of the expiration date, so it is best practice to renew your certificate when the first notification is received to prevent certificate outages.
Often a certificate renewal applicant will need to re-authenticate portions of the information contained within their old certificate that they would like to see within the new one. The process for this is similar to the original issuing process.
The upcoming shift to 47-Day SSL certificate validity periods
The maximum validity period for SSL/TLS certificates is scheduled to shrink significantly in the coming years as part of an industry-wide effort to improve security and reduce risk. In April 2025, Ballot SC-081v3 formally passed, putting a phased plan into place that will reduce public SSL certificate lifespans to 47 days by 2029.
These changes represent one of the most significant shifts in certificate management in decades and are designed to limit the impact of compromised or mis-issued certificates. However, they also significantly increase the number of renewals organizations must manage each year. As validity periods continue to shrink, automated certificate lifecycle management (CLM) will become critical for maintaining compliance and avoiding outages.
Why the change?
The primary motivation for the shorter validity period is increased security. Shorter certificate lifespans mean that certificates will need to be renewed more frequently, ensuring that encryption standards remain up-to-date and vulnerabilities are promptly addressed.
This change reduces the window of opportunity for attackers to exploit compromised certificates, significantly improving overall cybersecurity. Frequent renewals also mean that any weaknesses in the encryption algorithms or key management practices can be swiftly corrected, maintaining the highest level of protection for sensitive data.
Automated certificate renewal is becoming more important than ever
With shorter validity periods coming, the importance of automating certificate renewals becomes paramount. Manual renewal processes can lead to errors and lapses, which can cause significant disruptions and security risks for businesses. With the renewal process happening much more frequently, these risks will increase. Automated systems help ensure that renewals are completed accurately and on time, reducing the chances of expired certificates causing service interruptions, and allowing IT resources to focus on more critical tasks.
Additionally, automated Certificate Lifecycle Management tools can provide real-time monitoring and alerts, ensuring that organizations are always aware of upcoming expirations and can act promptly. Incorporating automation into certificate renewal processes not only improves efficiency but also enhances security. Automated systems are less prone to human error and will consistently apply the latest security practices and policies. This is especially crucial with shorter validity periods, where the frequency of renewals increases, and the margin for error narrows.
Prepare for shorter SSL validity periods with a trusted solution
As a global leader in digital certificates, Sectigo helps organizations stay ahead of evolving certificate requirements. Alongside our trusted SSL/TLS certificates, our Sectigo Certificate Manager (SCM) platform enables automated certificate lifecycle management, providing the visibility and control needed to manage frequent renewals reliably as validity periods continue to shrink. Smaller organizations and lean IT teams can use SCM Pro to discover and manage certificates and automate issuance and renewals through ACME.
Contact our team today to learn more about our digital certificate offerings or to demo our SCM platform.