2026 updates that affect certificate issuance, validation, trust, and renewals
Stay ahead of changing certificate requirements with key dates, impacts, and actions.
What's driving these changes
Across the industry, standards bodies and browser vendors are responding to:
• Increasing automation and scale of certificate issuance
• Greater reliance on certificates for identity, access, and software trust
• The risk posed by long-lived validations and credentials
• The need for stronger, verifiable domain and organizational controls
• Evolving cryptographic and regulatory requirements for qualified trust services
The result is a shift toward:
• Shorter certificate term
• More frequent validation
• Stronger, auditable verification
• Automation-first operational models
• Stronger cryptographic requirements
• Clearer separation of certificate trust models and intended use
Overview of key compliance changes
Multi-year TLS subscriptions still work the same
Essentially you can still purchase a 1-5 year TLS subscription.
Your subscription has an end date, and you need to re-issue certificates as needed up to that date.
What's changing is ithe issued certificate term. After March 12, 2026, each issued certificate is valid for up to 199 days, so what is changing is that you'll be required to re-issue those certificates within your subscription more frequently.
The updates
What's changing
Beginning March 11, 2026, Domain Control Validation reuse will be limited to approximately 6 months (198 days).
DCV records older than this limit must be revalidated before certificate issuance
Applies to both existing and newly created DCV records
Although the Certification Authority Browser Forum (CA/Browser Forum) has set this mandate for March 15, 2026, Sectigo’s operational enforcement begins March 12, 2026
Why this change is happening
DCV confirms that a requester controls a domain. Historically, DCV could be reused for longer periods, which increased risk if domain ownership or control changed over time.
Reducing DCV reuse:
- Limits the impact of stale validations
- Reduces attack windows by limiting how long a “one-time” validation could be reused and therefore, reducing the chance of ongoing misuse
- Improves overall trust in the certificate ecosystem
What customers should know
- Existing certificates remain valid until expiration
- No new certificate may be issued after March 12th relying on the DCV that was completed more than 198 days ago
- Validation will need to happen more frequently going forward
The updates
What's changing
Beginning March 11, 2026, Domain Control Validation reuse will be limited to approximately 6 months (198 days).
DCV records older than this limit must be revalidated before certificate issuance
Applies to both existing and newly created DCV records
Although the Certification Authority Browser Forum (CA/Browser Forum) has set this mandate for March 15, 2026, Sectigo’s operational enforcement begins March 12, 2026
Why this change is happening
DCV confirms that a requester controls a domain. Historically, DCV could be reused for longer periods, which increased risk if domain ownership or control changed over time.
Reducing DCV reuse:
- Limits the impact of stale validations
- Reduces attack windows by limiting how long a “one-time” validation could be reused and therefore, reducing the chance of ongoing misuse
- Improves overall trust in the certificate ecosystem
What customers should know
- Existing certificates remain valid until expiration
- No new certificate may be issued after March 12th relying on the DCV that was completed more than 198 days ago
- Validation will need to happen more frequently going forward
What's changing
Public TLS/SSL certificates are moving toward progressively shorter maximum term, beginning with a 6-month (199-day) limit starting March 12, 2026 and decreasing further in future phases.
Why this change is happening
Shorter certificate terms:
- Reduce exposure from compromised keys
- Limit the impact of mis-issuance
- Encourage automation and rapid remediation
- Enhance crypto agility
What customers should know
- Manual certificate management becomes increasingly difficult
- Automation is no longer optional at scale
- Renewal frequency will continue to increase over time
What’s changing
Newly issued RSA-based eIDAS QWAC certificates, including PSD2 QWAC certificates, will require a minimum RSA key size of 3072 bits.
The change will be introduced in two phases:
- November 30, 2026: All new RSA-based eIDAS QWAC certificate requests must use RSA keys of at least 3072 bits. Requests submitted with smaller RSA keys may require a new Certificate Signing Request (CSR) before issuance can proceed.
- December 15, 2026: Sectigo will no longer issue RSA-based eIDAS QWAC certificates using RSA keys smaller than 3072 bits. This applies to new certificate requests, renewals, replacements, and reissues.
Customers using Elliptic Curve Cryptography (ECC) keys are not affected by this RSA key size requirement.
Why this change is happening
The increased minimum RSA key size aligns with evolving cryptographic standards and supervisory requirements applicable to qualified trust services.
What customers should know
- Existing certificates remain valid until their expiration date unless otherwise communicated.
- Review systems, tooling, and automation that generate RSA-based CSRs for eIDAS QWAC certificates.
- Update affected processes to generate RSA keys of at least 3072 bits before November 30, 2026.
- The requirement also applies to PSD2 QWAC certificates.
What’s changing
Effective September 30, 2026, newly issued PSD2 QWAC certificates will no longer be trusted by Google Chrome and Mozilla/NSS.
Existing certificates are not affected by this change.
In time, PSD2 QWAC certificate issuance will be migrated to a hierarchy only in scope of the EUTL.
Why this change is happening
PSD2 QWAC certificates are intended for PSD2 and Open Banking ecosystems, where they support authenticated and trusted communications between regulated payment service providers.
They are not intended to secure public websites or provide browser trust.
What customers should know
- Existing PSD2 QWAC certificates are not affected by this change.
- Review where and how your organization currently deploys PSD2 QWAC certificates.
- If you use a PSD2 QWAC certificate to secure a publicly accessible website, begin planning to migrate that use case to a standard eIDAS QWAC certificate (non-PSD2) for public website authentication.
- Newly issued PSD2 QWAC certificates should be used for their intended PSD2 and Open Banking use cases.
How Sectigo helps customers stay ahead
Sectigo’s platform and services are designed for continuous compliance. Not one-off changes.
Key principles:
- Early adoption of standards
- Automation-first design
- Clear visibility into validation and lifecycle status
- Continuous alignment with browser and industry requirements
As standards continue to evolve, Sectigo customers benefit from a platform built to adapt.
What you should do now
The most important thing is to assess your needs and start planning by leveraging automation.
We recommend:
Identify how you are currently managing your certificate inventory. If you rely on manual renewals, plan for more frequent certificate replacement in 2026.
Remain vigilant on the ever-evolving mandates and changes. While reselling partners, must keep their customers educated.
- TLS certificates can still be purchased in multi-year products, but issuance is up to 199 days per certificate.
- DCV reuse is up to 198 days, older validations must be redone.
- Sectigo-provisioned Code Signing certificates can only be purchased as a 1-year product after February 15th.
- Ensure DNSSEC signing is correctly configured (if enabled), as CAs will no longer be permitted to proceed when DNSSEC validation fails.
- eIDAS QWAC customers should prepare for new RSA key size requirements beginning November 30, 2026, while PSD2 QWAC customers should also review the September 30, 2026 trust-chain change.
If your organization uses eIDAS QWAC or PSD2 QWAC certificates, review your certificate request and deployment processes now.
- Before September 30, 2026: Determine whether PSD2 QWAC certificates are being used to secure public websites. Where appropriate, plan to migrate those use cases to a standard eIDAS QWAC certificate (non-PSD2).
- Before November 30, 2026: Ensure systems, tooling, and automation generating RSA-based QWAC certificate requests support RSA keys of at least 3072 bits.
Preparing early can help avoid unexpected impacts to browser trust and certificate issuance delays.
With certificate durations shrinking, automation becomes essential to reduce operational overhead and outage risk.

