Google and Apple's push for shorter certificate lifecycles: what to expect before the transition
November 20, 2024
On March 15, 2026, the first major stepdown in the move toward 47-day certificate lifespans took effect, reducing the maximum SSL/TLS certificate validity period to 200 days. This is a dramatic first move towards shorter maximum validity periods and acts as a wake-up call for organizations that have not yet started automating their Certificate Lifecycle Management (CLM). Sectigo is here to inform, educate, and provide solutions for businesses that are ready to tackle the future of CLM.
The clock is ticking.
On March 15 2026, the maximum lifespan of newly issued public SSL/TLS certificates shrank from 398 days to 200 days, nearly a 50% reduction in certificate validity. This is one of the most significant changes to affect digital certificate management in over five years, and it's coming fast.
If your organization is still managing certificates manually, this shift will double your workload overnight, leaving you vulnerable to outages, compliance failures, and reputational damage. The only way to keep up? Automate your certificate lifecycle today.
Right now, SSL/TLS certificates are valid for up to 200 days.
This shift has immediate operational consequences:
Shorter certificate lifespans are being pushed by major browser vendors to strengthen internet security, promote faster cryptographic agility, and limit exposure when certificates are misissued or compromised. This change in certificate validity is crucial for when postquantum cryptography (PQC) takes hold, ensuring organizations can rapidly adopt new cryptographic algorithms as standards evolve.
While these changes are good for the overall ecosystem and digital security, they create serious operational strain for organizations without a plan.
Let’s break it down:
This isn’t just a browser policy update, it’s a fundamental change in how the internet handles trust. And while shorter certificate lifespans improve cybersecurity, they also demand real-time visibility and automated lifecycle management to avoid disruption.
This is the first stepdown in a four-year shift to 47-day certificate lifespans. You may be thinking that there is time to wait, but the longer automation is delayed, the greater the operational risk becomes. While 200 days may seem like a manageable renewal window, the implications of continuing with manual certificate management are significant.
If you're not ready for this shift, here's what’s at stake:
This change happened in early 2026, but if you wait until then, it will be too late. Implementing automation takes time:
Organizations that delay will face increasing renewal pressure, delayed renewals, missed expirations, and avoidable outages. Manual certificate management was risky at 398 days. At 200 days, it becomes unsustainable.
The move to 200-day certificate lifespans is only the beginning. Under the CA/Browser Forum’s approved timeline, publicly trusted SSL certificates will continue to shrink in a series of planned stepdowns over the next several years:
By 2029, certificates will need to be renewed every month and a half. Each phased reduction compounds the operational impact.
Many IT organizations are reluctant to automate due to the perceived costs and complexities. While automation requires an upfront investment, the payoff speaks for itself: With native ACME support plus EST, SCEP, REST APIs, agents, and third-party automation integrations, Sectigo Certificate Manager (SCM) makes certificate automation far easier than many organizations expect.
Organizations using automated Certificate Lifecycle Management see a 3x return on investment over three years, according to a commissioned Forrester Consulting Total Economic Impact™ study of Sectigo Certificate Manager (SCM).
Here’s what automation delivers in measurable value:
The TEI study found that SCM helps teams focus on strategic initiatives instead of certificate firefighting, while improving their overall security posture.
Bottom line: Automation doesn’t just future-proof security; it pays for itself.
Certificate authorities like Sectigo are not just keeping up with these changes, they’re leading them. As an intellectual leader in the digital trust space, Sectigo is actively working to raise awareness about the 200-day shift, helping enterprises understand the urgency, the risks, and the automation solutions available.
Through ongoing industry education in the form of blogs, whitepapers, webinars, and standards committee participation, Sectigo is helping to prepare the global community before the impact of shorter certificate lifespans becomes a crisis.
The move to 200-day SSL/TLS certificates is one of the most urgent and disruptive changes in digital identity management today. It demands a strategic response, and that response starts with automation. Automation ensures business continuity, protects customer trust, and lets your teams focus on innovation, rather than certificate firefighting.
You now have 200 days to fix this. Don’t wait.
Discover why now is the time to automate your certificates. Watch our webinar or schedule a demo of Sectigo Certificate Manager today.