The first 200-day renewal cycle: is your certificate management keeping up?
Watch the webinar now
Missed the live session? Sign up now to watch the full recording and gain valuable insights into the latest trends and strategies.
The first wave of 200-day SSL/TLS certificates is expiring right now, and it's exposing gaps most teams didn't know they had. In April 2025, the CA/Browser Forum set a phased schedule cutting certificate validity from 398 days down to 200, then 100 (March 2027), then 47 (2029). The first certificates with shorter lifespans are now reaching expiration. The renewal workload that was once annual, is now landing twice as fast, for the first time.
Join us for a practical session on what's breaking, why it's breaking, and how to get ahead of the next stepdown before it hits. We’re exposing gaps in certificate inventories, ownership and DCV workflows, and we’ll cover the real cost of manual renewal cycles, how automation takes away the burden, and how to turn this renewal surge into a dry run for 100-day certificates.
Agenda
- How we got here: a fast recap of Ballot SC-081v3, the CA/Browser Forum's phased validity schedule (200 to 100 to 47 days).
- Why this moment matters: a quick look at the first 200-day expirations, and why planning matters.
- What is at risk of breaking: the combination of factors increasing renewal risk
- The cost of manual management: a cost comparison of 398-day validity vs 200-day validity.
- A practical self-assessment: how to tackle inventory gaps, ownership, spreadsheet-based tracking and manual issuance paths.
- What to do this quarter: concrete next steps for reconciling your inventory, automating high-volume certificates, stress-testing DCV, and resetting alert thresholds. Also receive our 47-day toolkit.
- Live Q&A: time to answer your questions