https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days ') //check if OneTrust is allowing "Personalized Experience Cookies" (i.e., Adobe Target) to load var adobeTargetOneTrustGroup = "PE"; function isAdobeTargetAllowed(adobeTargetOneTrustGroup) { var OptanonConsentCookie = document.cookie.match(/OptanonConsent=.*;/); return (OptanonConsentCookie && decodeURIComponent (OptanonConsentCookie[0]).includes(adobeTargetOneTrustGroup + ":1")); } if (isAdobeTargetAllowed(adobeTargetOneTrustGroup)) { //Adobe Target prehiding snippet ;(function(win, doc, style, timeout) { var STYLE_ID = 'at-body-style'; function getParent() { return doc.getElementsByTagName('head')[0]; } function addStyle(parent, id, def) { if (!parent) { return; } var style = doc.createElement ('style'); style.id = id; style.innerHTML = def; parent.appendChild (style); } function removeStyle(parent, id) { if (!parent) { return; } var style = doc.getElementById(id); if (!style) { return; } parent.removeChild(style); } addStyle(getParent(), STYLE_ID, style); setTimeout(function() { removeStyle(getParent(), STYLE_ID); }, timeout); }(window, document, "body {opacity: 0 !important}", 3000)); } * Platform Back DigiCert ONE Platform PKI Certificate Lifecycle Management Code & Software Signing IoT & Connected Devices Document & eSignature DNS Solutions Public Trust TLS/SSL Certificates Private/Internal PKI Manage PKI and Certificate Risk in One Place + Prevent outages + Certificate lifecycle management + Private PKI services + Integrations & advantages Manage PKI and Certificate Risk in One Place + Prevent outages + Certificate lifecycle management + Private PKI services + Integrations & advantages The Smarter Way to Manage Certificate Lifecycles + Issue & install + Inspect & remediate + Renew & automate + Assign & delegate Continuous Signing for CI/CD & DevOps + Assure code integrity + Automate software signing workflows + Centralize key & permission management + Simplify & enforce compliance Secure, Flexible and Global Signing + Establish crypto-unique identities + Trusted remote identity verification (RIV) + Intuitive Adobe & DocuSign integrations + Flexible workflow options Trusted From Silicon to In-the-Field + Healthcare IoT + Home & Consumer IoT + Industrial IoT + Smart City IoT + Transportation IoT Device Security Without Compromise + Embedded trust + Automated device management + Centralized control Accelerate Secure App Development + OS- & processor-agnostic development + Flexible footprint + Any language Scan. Sign. Deliver. How do you deal with software supply chain complexities? GET OUR GUIDE Software security in 5 steps * Solutions Back Solutions Solutions for Matter Solutions for Automation Solutions for CI/CD Solutions for Code Solutions for Devices Solutions for Documents Solutions for CI-Plus Solutions for Secure Email Solutions for ServiceNow DigiCert(r) TrustCore SDK PKI+DNS DigiCert Open Source Replacement Certificates The Smarter Way to Manage Certificate Lifecycles + Issue & install + Inspect & remediate + Renew & automate + Assign & delegate Software Supply Chain Security Protect your entire software supply chain with automated tools TALK TO AN EXPERT Software security in 5 steps * Buy Back TLS/SSL Certificates Single Domain BUY Buy Extended validation Buy Organization validation Multi-Domain BUY Buy Extended validation Buy Organization validation Wildcard Domain BUY Document Signing Certificates Document Signing - Individual BUY Document Signing - Organization BUY Code Signing Certificates Code Signing BUY Code Signing + KeyLocker BUY S/MIME Email Certificates Secure Email - Individual BUY Secure Email - Business BUY Mark Certificates Verified Mark Certificates (VMC) BUY Common Mark Certificates BUY DNS Authoritative DNS BUY EU (eIDAS) QWAC BUY Qualified Signing BUY PSD2 BUY PKIoverheid Private Services Server BUY Document Signing BUY Authentication/Encryption BUY Find the right TLS/SSL Certificate to secure your website Compare eIDAS-compliant transaction and website document security solutions Learn More * Company Back About DigiCert Blog Careers Events Case Studies Media Library Newsroom Partners Professional Services Webinars Contact Us Manage PKI and Certificate Risk in One Place + Prevent outages + Certificate lifecycle management + Private PKI services + Integrations & advantages Manage PKI and Certificate Risk in One Place + Prevent outages + Certificate lifecycle management + Private PKI services + Integrations & advantages The Smarter Way to Manage Certificate Lifecycles + Issue & install + Inspect & remediate + Renew & automate + Assign & delegate Continuous Signing for CI/CD & DevOps + Assure code integrity + Automate software signing workflows + Centralize key & permission management + Simplify & enforce compliance Secure, Flexible and Global Signing + Establish crypto-unique identities + Trusted remote identity verification (RIV) + Intuitive Adobe & DocuSign integrations + Flexible workflow options Trusted From Silicon to In-the-Field + Healthcare IoT + Home & Consumer IoT + Industrial IoT + Smart City IoT + Transportation IoT Device Security Without Compromise + Embedded trust + Automated device management + Centralized control Accelerate Secure App Development + OS- & processor-agnostic development + Flexible footprint + Any language Scan. Sign. Deliver. How do you deal with software supply chain complexities? GET OUR GUIDE Software security in 5 steps * Resources Back Resource Center Blog Case Studies Events FAQs Media Library Webinars Insights Artificial Intelligence Post-Quantum Cryptography Sphincs Dilithium The 4 Elements of Digital Trust Digital Open Source The Case for Compliance Zero Trust: Critical to Digital Trust Are You Ready? Join industry luminaries for World Quantum Readiness Day. WATCH REPLAY > World Quantum Readiness Day Promo Are you ready? Join industry luminaries for World Quantum Readiness Day. WATCH REPLAY * Support Back Support Support PKI Support Contact Us Tools Tools: S/MIME Certificate Linter Tools: SSL Install Diagnostics Tools: Certificate Utility for Windows Tools: CSR Creator Tools: Check CSR Tools: SSL Certificate Installation Instructor Resources Documentation API Documentation Knowledgebase Solutions FAQs What is PKI? What is an SSL Certificate? What is SSL, TLS & HTTPS? How TLS/SSL Works What's the Difference Between DV, OV & EV SSL Certificates? Contact Our Support Team + Americas o 1.866.893.6565 (Toll-Free U.S. and Canada) o 1.801.770.1701 (Sales) o 1.801.701.9601 (Spanish) o 1.800.579.2848 (Enterprise only) o 1.801.769.0749 (Enterprise only) + Europe, Middle East Africa o +44.203.788.7741 o Asia Pacific, Japan o 61.3.9674.5500 Email Sales Email Support * Contact us * Language Back CHOOSE YOUR LANGUAGE + English + Espanol + Dutch + Deutsch + Francais + Italiano + Chinese (Simplified) + Chinese (Traditional) + Japanese + Korean + Portugues * Contact us * language Choose your language + English + Espanol + Dutch + Deutsch + Francais + Italiano + Chinese (Simplified) + Chinese (Traditional) + Japanese + Korean + Portugues x * search [ ] x RECOMMENDED LINKS + Compare Certificates + DigiCert(r) Trust Lifecycle Manager + DigiCert(r) Device Trust Manager + DigiCert(r) Document Trust Manager + DigiCert(r) Software Trust Manager + DNS Solutions * * user_circle * x TECHNICAL SUPPORT CHAT > VALIDATION CHAT > SALES CHAT > Blog > Certificate Management > TLS Certificate Lifetimes Will Officially Reduce to 47 Days Certificate Management 04-14-2025 TLS Certificate Lifetimes Will Officially Reduce to 47 Days Stephen Davidson [47-day-blo] The CA/Browser Forum has officially voted to amend the TLS Baseline Requirements to set a schedule for shortening both the lifetime of TLS certificates and the reusability of CA-validated information in certificates. The first user impacts of the ballot take place in March 2026. The ballot was long debated in the CA/Browser Forum and went through several versions, incorporating feedback from certificate authorities and their customers. The voting period ended on April 11, 2025, closing one hotly contested chapter and allowing the certificate world to plan for what comes next. The new TLS certificate lifetime schedule The new ballot targets certificate validity of 47 days, making automation essential. Prior to this proposal by Apple, Google promoted a 90-day maximum lifetime, but they voted in favor of Apple's proposal almost immediately after the voting period began. Here's the schedule: * The maximum certificate lifetime is going down: + From today until March 15, 2026, the maximum lifetime for a TLS certificate is 398 days. + As of March 15, 2026, the maximum lifetime for a TLS certificate will be 200 days. + As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days. + As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days. * The maximum period during which domain and IP address validation information may be reused is going down: + From today until March 15, 2026, the maximum period during which domain validation information may be reused is 398 days. + As of March 15, 2026, the maximum period during which domain validation information may be reused is 200 days. + As of March 15, 2027, the maximum period during which domain validation information may be reused is 100 days. + As of March 15, 2029, the maximum period during which domain validation information may be reused is 10 days. * As of March 15, 2026, validations of Subject Identity Information (SII) can only be reused for 398 days, down from 825. SII is the company name and other information found in an OV (Organization Validated) or EV (Extended Validation) certificate, i.e., everything but the domain name or IP address protected by the certificate. This does not affect DV (Domain Validated) certificates, which have no SII. Why 47 Days? 47 days might seem like an arbitrary number, but it's a simple cascade: * 200 days = 6 maximal month (184 days) + 1/2 30-day month (15 days) + 1 day wiggle room * 100 days = 3 maximal month (92 days) + ~1/4 30-day month (7 days) + 1 day wiggle room * 47 days = 1 maximal month (31 days) + 1/2 30-day month (15 days) + 1 day wiggle room Apple's justification for the change In the ballot, Apple makes many arguments in favor of the moves, one of which is most worth calling out. They state that the CA/B Forum has been telling the world for years, by steadily shortening maximum lifetimes, that automation is essentially mandatory for effective certificate lifecycle management. The ballot argues that shorter lifetimes are necessary for many reasons, the most prominent being this: The information in certificates is becoming steadily less trustworthy over time, a problem that can only be mitigated by frequently revalidating the information. The ballot also argues that the revocation system using CRLs and OCSP is unreliable. Indeed, browsers often ignore these features. The ballot has a long section on the failings of the certificate revocation system. Shorter lifetimes mitigate the effects of using potentially revoked certificates. In 2023, CA/B Forum took this philosophy to another level by approving short-lived certificates, which expire within 7 days, and which do not require CRL or OCSP support. Clearing up confusion about the new rules Two points about the new rules are likely to cause confusion: 1. The three years for the rule changes are 2026, 2027, and 2029, but the gap between the second set of years is two years long. 2. As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days, but the maximum period during which domain validation information may be reused is only 10 days. Manual revalidation will still technically be possible, but doing so would be a recipe for failure and outages. As a certificate authority, one of the most common questions we hear from customers is whether they'll be charged more to replace certificates more frequently. The answer is no. Cost is based on an annual subscription, and what we've learned is that, once users adopt automation, they often voluntarily move to more rapid certificate replacement cycles. For this reason, and because even the 2027 changes to 100-day certificates will make manual procedures untenable, we expect rapid adoption of automation long before the 2029 changes. Apple's statement about automated certificate lifecycle management is indisputable, but it's something we've been long preparing for. DigiCert offers multiple automation solutions through Trust Lifecycle Manager and CertCentral, including support for ACME. DigiCert's ACME allows automation of DV, OV, and EV certificates and includes support for ACME Renewal Information (ARI). Get in touch for more information on how you can make the best use of automation. The latest developments in digital trust Want to learn more about topics like certificate management, automation, and TLS/SSL? Subscribe to the DigiCert blog to ensure you never miss a story. Related Stories 47 Days: The New Certificate Lifetime Proposed by Apple Why Certificate Automation is an Absolute Must How--and Why--to Automate Certificate Management Featured Stories * Digital Trust 12-04-2024 How Artificial Intelligence is Reshaping Digital Trust Lakshmi Hanspal * Certificate Management 04-14-2025 TLS Certificate Lifetimes Will Officially Reduce to 47 Days Stephen Davidson * Data Security 04-04-2025 Why Mobile Banking Security Still Falls Short Abby Norwood Subscribe to the blog [ ] Subscribe HONEYPOTFIELDHTMLNAME [ ] * DigiCert Logo The most-trusted global provider of high-assurance TLS/SSL, PKI, IoT and signing solutions. * * Linkedin Twitter Youtube * Company + About + Blog + Careers + Events + Newsroom + Leadership + Contact Us + Case Studies * My Account + KnowledgeBase + Documentation + Support + Developers + CertCentral Account + Quick Links + Partner Directory + All Products + Tools + Site Seals * Resources + FAQs + Media Library + Professional Services + What is PKI? + How TLS/SSL Works + What are SSL TLS & HTTPS? + What is an SSL Certificate? + What's the Difference Between DV, OV & EV SSL Certificates? * Sites + Support + Vercara DNS + DigiCert PQC Playground + DigiCert Partner Portal + QuoVadis + Thawte + Rapid SSL + GeoTrust * Linkedin Twitter Youtube * (c) 2025 DigiCert, Inc. All rights reserved. Legal Repository Audits & Certifications Terms of Use Privacy Center Accessibility Cookie Settings TO TOP