47-day SSL certificates: the timeline and a checklist for MSPs
Public TLS certificates are getting much shorter. If you look after sites, mail servers or appliances for clients, renewals that used to happen once a year will soon happen every few weeks. Here is what changes, when, and how to get ready.
The timeline
| From | Maximum lifetime | Who it affects |
|---|---|---|
| Until 15 Mar 2026 | 398 days | Previous rule for all public CAs |
| 15 Mar 2026 | 200 days | All public CAs (in force now) |
| 10 Feb 2027 | 64 days | Let's Encrypt default certificates |
| 15 Mar 2027 | 100 days | All public CAs |
| 15 Mar 2029 | 47 days | All public CAs, final step |
The CA/Browser Forum voted for the schedule in 2025. Domain validation reuse periods shrink alongside it, so CAs will re-check that you control a domain more often as well.
What actually breaks
- Fixed 60-day renewal jobs. Many ACME clients and cron jobs renew every 60 days. With 64-day Let's Encrypt certificates that leaves four days of margin, so one failed run means an expired site.
- Manual renewals. Appliances, mail servers, VPNs and load balancers where someone uploads a certificate by hand. At 47 days that's about eight manual renewals a year per host.
- Forgotten hosts. Old subdomains and staging servers nobody remembers. They show up in public Certificate Transparency logs even when they're missing from your documentation.
- Expiry emails. Let's Encrypt stopped sending expiry reminder emails in 2025, so the safety net many teams relied on is gone.
Checklist
- Inventory every certificate. Pull hostnames for each client domain from Certificate Transparency logs, not just from your notes.
- Find the manual ones. Anything without ACME automation needs an owner and a plan before lifetimes drop to 100 days in March 2027.
- Renew by remaining lifetime, not a fixed interval. Configure ACME clients to renew based on how much lifetime is left, or on ACME Renewal Information (ARI) where your client supports it, instead of a fixed number of days.
- Watch what is actually served. A renewed certificate that never got deployed still expires. Check the certificate each host presents, every day.
- Alert the team, not one inbox. Send expiry alerts to a shared channel with escalation in the final week.
- Track the non-certificate renewals too. Domains, Microsoft 365 seats, firewall licenses and warranties fail the same way: nobody noticed the date.
Radardue does steps 1, 4, 5 and 6 for you
Type a client's domain and Radardue finds every hostname, checks what each one serves daily, flags hosts on a fixed ~60-day renewal cycle, and alerts your team by email, Slack, Discord, Telegram or any webhook. Start free or check a site.