Try free Sign in Contact sales
← Blog

47-day SSL certificates: the CA/B Forum lifetime schedule explained

CA/B Forum Ballot SC-081v3 timeline: 200 days (2026), 100 days (2027), 47-day SSL/TLS max by March 2029 — why it happened, DCV reuse risks, and how automation keeps HTTPS online.

Public TLS certificate lifetimes are getting shorter — and the CA/Browser Forum has already approved a schedule that ends at a 47-day maximum for publicly trusted SSL/TLS certificates. That is not a rumor. Ballot SC-081v3 (April 2025) set a multi-year ramp: 200 days, then 100 days, then 47 days by March 15, 2029, with domain-validation reuse shrinking even faster.

This is the single docstoc guide to that change: why it exists, the official timeline, what breaks for freelancers and SMBs, and how ACME automation (including docstoc’s Let's Encrypt renewals) keeps HTTPS from becoming a calendar chore. We are not publishing a second overlapping “47-day” post — one URL, one canonical answer.

Why SSL/TLS lifetimes are shrinking

Long-lived certificates (years, then ~398 days) were convenient and risky: a compromised private key could impersonate your site until expiry or revocation (revocation is imperfect on the public web). Shorter lifetimes force fresher keys and make automation the default.

Let's Encrypt’s widely deployed ~90-day DV certificates already trained much of the internet on that model. The CA/B Forum ballot extends shorter maximums across all publicly trusted TLS certificates — commercial CAs included — on a published schedule.

The 47-day SSL certificate schedule (SC-081v3)

In April 2025 the CA/Browser Forum approved Ballot SC-081v3 to reduce maximum validity and validation-data reuse for public TLS certificates. Approximate caps (confirm against current Baseline Requirements if you are writing compliance policy):

In force from Max certificate lifetime Max domain validation (DCV) reuse
Before Mar 15, 2026 398 days 398 days
Mar 15, 2026 200 days 200 days
Mar 15, 2027 100 days 100 days
Mar 15, 2029 47 days 10 days

So “47-day certificates” is the destination, not an overnight flip. The first step (200 days) lands in March 2026; 100 days in 2027; 47 days in 2029. Manual annual repurchase was already fragile — under 47 days plus 10-day DCV reuse it is operationally untenable.

Domain validation reuse is the real trap

Headlines focus on 47 days of certificate life. The steeper change is how often you must prove domain control again. By March 2029, DCV reuse drops to about 10 days — so you re-validate domain control multiple times per certificate lifetime. Hand-placing a DNS TXT record once a year will not survive that cadence. Automation (ACME, host panels, or an in-product renewer) becomes the only sane path.

Impact on freelancers and SMBs

If you buy a “1-year SSL” from a reseller and wait for a renewal email, HTTPS will fail more often as caps fall to 200 → 100 → 47 days. If you already use ACME automation (host checkbox, Cloudflare, certbot, or docstoc), the policy change is mostly invisible — the system reissues before expiry.

Use the SSL expiry calculator to see how fast a short clock burns down, then ask whether your current process can survive without human reminders.

Why automation is mandatory

Shorter lifetimes only strengthen security when renewals actually happen. Organizations that still click through CA portals will hit outages, expired padlocks, and broken payment pages. The industry answer is ACME (and related renewal signaling), not more calendar invites.

What to do now

  1. Inventory hostnames and who renews them (host, Cloudflare, CA portal, DIY certbot, docstoc).
  2. Eliminate manual annual repurchase for DV sites — move to ACME before the 100-day and 47-day caps arrive.
  3. Treat March 2026 (200-day cap) as a rehearsal for 2027/2029, not a distant footnote.
  4. Keep commercial OV/EV only where policy requires them — and still automate wherever the CA supports it.
  5. For HTTPS next to invoices and templates, start with docstoc SSL/TLS automation (Free: 5 × 90-day; Pro: multi-SAN; Business: wildcards).

FAQ

When do 47-day SSL certificates become mandatory?

Under Ballot SC-081v3, the maximum validity for publicly trusted TLS certificates drops to 47 days starting March 15, 2029, after intermediate caps of 200 days (March 15, 2026) and 100 days (March 15, 2027). Always re-check the current CA/Browser Forum Baseline Requirements for compliance work.

Are shorter certificates less secure?

No — they reduce how long a leaked key remains useful. Security improves when issuance and renewal are automated correctly.

Is this the same as Let's Encrypt’s 90-day certs?

Related idea, different scope. Let's Encrypt already uses short-lived DV certificates. The CA/B Forum schedule caps maximum validity industry-wide for publicly trusted TLS, stepping down to 47 days by 2029.

Will docstoc keep up as lifetimes shrink to 47 days?

docstoc’s model is ACME automation against Let's Encrypt. Shorter public DV lifetimes reinforce automated renewal rather than undermine it. docstoc does not replace enterprise OV/EV PKI or commercial CLM suites.

Do I need a separate article or product just for “47-day SSL”?

No. Treat 47-day as the end state of the same lifetime-shortening story — automate renewals once, and the schedule stops being a crisis.