Sectigo Blog

How long can digital certificates be valid?

The validity periods for digital certificates are determined by their accepting organizations and always conform to the requirements given by the CA/Browser Forum, a voluntary group of certification authorities (CAs), vendors of Internet browser software, and suppliers of other applications that use X.509 v.3 digital certificates for SSL/TLS, code signing, and S/MIME. Sectigo is an active participant in the CA/B forum and helps shape the standards that govern digital certificate lifespans and trust requirements.

Certificate lifespans have been reduced multiple times over the years as part of industry efforts to improve security and limit risk exposure, and they are scheduled to shorten again. When software or a website presents an expired certificate, it can no longer be authenticated and is rejected by browsers and clients, often resulting in outages, service disruptions, and loss of user trust. Understanding certificate validity periods helps organizations plan renewals in advance and reduce the risk of avoidable downtime.

Sectigo Team