Radardue
Guide · updated October 2026

47-day SSL certificates: the timeline and a checklist for MSPs

Public TLS certificates are getting much shorter. If you look after sites, mail servers or appliances for clients, renewals that used to happen once a year will soon happen every few weeks. Here is what changes, when, and how to get ready.

The timeline

FromMaximum lifetimeWho it affects
Until 15 Mar 2026398 daysPrevious rule for all public CAs
15 Mar 2026200 daysAll public CAs (in force now)
10 Feb 202764 daysLet's Encrypt default certificates
15 Mar 2027100 daysAll public CAs
15 Mar 202947 daysAll public CAs, final step

The CA/Browser Forum voted for the schedule in 2025. Domain validation reuse periods shrink alongside it, so CAs will re-check that you control a domain more often as well.

What actually breaks

Checklist

  1. Inventory every certificate. Pull hostnames for each client domain from Certificate Transparency logs, not just from your notes.
  2. Find the manual ones. Anything without ACME automation needs an owner and a plan before lifetimes drop to 100 days in March 2027.
  3. Renew by remaining lifetime, not a fixed interval. Configure ACME clients to renew based on how much lifetime is left, or on ACME Renewal Information (ARI) where your client supports it, instead of a fixed number of days.
  4. Watch what is actually served. A renewed certificate that never got deployed still expires. Check the certificate each host presents, every day.
  5. Alert the team, not one inbox. Send expiry alerts to a shared channel with escalation in the final week.
  6. Track the non-certificate renewals too. Domains, Microsoft 365 seats, firewall licenses and warranties fail the same way: nobody noticed the date.

Radardue does steps 1, 4, 5 and 6 for you

Type a client's domain and Radardue finds every hostname, checks what each one serves daily, flags hosts on a fixed ~60-day renewal cycle, and alerts your team by email, Slack, Discord, Telegram or any webhook. Start free or check a site.