SSL Certificate Lifecycle Changes

Jordan Graves
Published: 22 September 2026Last updated: 1 October 2026
Share:

Since 24th February, 2026, all TLS Certificates must have a maximum validity of 199 days. This change will apply to all SSL certificates from all vendors and certificate authorities.

This change is to align with the CA/Browser Forum ballot, which voted in favour of updating the TLS baseline requirements, effectively shortening the lifetime of TLS Certificates from 398 days to 200 days in 2026, 100 days in 2027, and 47 days in 2029. 

The benefits outlined by the CA/Browser Forum for these changes are:

  • Encourages automation - Shorter certificate lifetimes push organisations to automate certificate issuing, renewals and deployment instead of relying on manual processes.
  • Keeps certificate information fresher - Shorter lifetimes mean domain ownership and validation information is checked more frequently and is less likely to become outdated.
  • Reduces expiry-related issues - Automation of SSL certificates reduces the risk of certificates expiring because someone forgot to replace them.

 

What does this mean for your SSL Certificates?

All SSL certificates will remain purchasable and renewable for 1 year periods; two certificates will be included within this 1 year cycle. The first certificate will be for the first 199 days of the 1 year period, followed by another certificate that will cover the domain name for the rest of the duration period.

These changes mean that your SSL needs to be re-issued mid-term, and this verification will occur using the same verification method, automatically.

If you are experiencing any issues with the reissuing or the automatic installation of your SSL certificate mid-term, please contact our Support Team, who will be happy to help.