Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

200-day certificates are starting to expire. Is your organization ready?

Дата публикации: 23-09-2026 04:00:00

The 200-day certificate era stopped being theoretical. On March 15, 2026, the CA/Browser Forum's Ballot SC-081v3 cut public SSL/TLS certificate validity from 398 days to 200 days. That was the warning. Now comes the test: certificates issued on and around that date are reaching the end of their validity window, and the first real wave of 200-day renewals is landing on IT and security teams right now.For organizations that treated March 15 as a distant compliance deadline rather than an operational one, this is the moment the gap becomes visible.

Основное содержимое страницы с новостью.

The 200-day certificate era stopped being theoretical. On March 15, 2026, the CA/Browser Forum's Ballot SC-081v3 cut public SSL/TLS certificate validity from 398 days to 200 days. That was the warning. Now comes the test: certificates issued on and around that date are reaching the end of their validity window, and the first real wave of 200-day renewals is landing on IT and security teams right now.

For organizations that treated March 15 as a distant compliance deadline rather than an operational one, this is the moment the gap becomes visible.

Why this moment matters

A certificate issued the week of March 15, 2026 reaches the end of its 200-day validity period in early October 2026, twice as fast as it would have under the old 398-day standard. That means the renewal workload security and IT teams budgeted for annually is now landing twice a year, and it's landing for the first time this fall.

This isn't a future risk to plan around anymore. It's a present one to manage.

A quick recap: how we got here

In April 2025, the CA/Browser Forum approved Ballot SC-081v3, a motion originally proposed by Apple and backed by major browser vendors and certificate authorities, including Google/Chrome, Mozilla, and Sectigo. The ballot set a phased schedule for shrinking public SSL/TLS certificate validity and Domain Control Validation (DCV) reuse periods:

Date

Max certificate validity

DCV reuse

March 15, 2026

200 days

200 days

March 15, 2027

100 days

100 days

March 15, 2029

47 days

10 days

The rationale was straightforward: longer certificate lifespans mean longer windows of exposure if a certificate or its underlying key is ever compromised, and longer stretches between validation checks mean domain ownership data can drift out of date. Shorter lifespans, paired with post-quantum cryptography's push toward faster key rotation, are part of the same broader shift toward crypto-agility.

That was the policy. What's landing on IT and security teams now is the operational reality of it.

What changes when renewal cycles compress

Halving certificate validity both doubles how often a certificate needs to be renewed and compounds every process built around that renewal:

  • Renewal volume doubles, immediately: Every certificate an organization manages now needs attention twice as often as it did under 398-day validity. Teams that renewed annually are now renewing roughly every six months, with no reduction in per-renewal effort if the process is still manual.
  • Discovery gaps surface faster: Certificates that were "set and forget" under a 13-month cycle now resurface for action in under seven months. Any certificate that wasn't properly inventoried the first time around is due again, sooner than expected.
  • DCV reuse windows tighten too: Domain Control Validation reuse periods are compressing alongside certificate validity. Teams that don't have a repeatable DCV workflow will feel that friction on every renewal, not just some of them.
  • The margin for error shrinks: With renewals landing more frequently, a missed one is a recurring risk. Expired-certificate outages become a matter of when, not if, for organizations still relying on spreadsheets and calendar reminders.

None of this is unique to any one industry or company size. Any organization with a public-facing certificate footprint (which is to say, nearly all of them) is now working through this same compression at the same time, which is part of why the effects are showing up broadly this fall rather than trickling in gradually.

The cost of standing still

Manual certificate management was already expensive before validity periods shortened. However, Forrester Total Economic Impact™ (TEI) study conducted on behalf of Sectigo found that organizations automating certificate lifecycle management with Sectigo Certificate Manager (SCM) saw a 243% return on investment, including $1.3 million in reduced provisioning labor and $965,000 in reduced renewal expenses over three years, plus a further $2.4 million in avoided outage-related costs.

Those figures were calculated against a slower renewal cadence. At 200-day validity, the labor and risk that automation offsets double in frequency. Every dollar manual processes were costing per renewal cycle is now being spent twice as often, and every hour spent chasing down expiring certificates is now an hour spent twice as often too. The ROI case for automation holds at 200-day lifespans, and strengthens with each stepdown.

Signs your organization isn't ready

The first 200-day renewal cycle tends to expose the same gaps:

  • Certificate inventories that are incomplete, outdated, or split across teams and tools.
  • No clear ownership for renewals, DCV, or certificate-related incident response.
  • Renewal tracking that lives in spreadsheets, tickets, or someone's calendar rather than a centralized system.
  • No automated issuance or renewal path (e.g., via ACME) for at least the highest-volume certificate types.

If any of these sound familiar, this renewal cycle is the signal to act before the next one (100-day validity) arrives in March 2027.

What to do this quarter
  1. Reconcile your certificate inventory now: Confirm which certificates were issued around March 15 and are approaching expiration, and identify the owner for each. While you’re at it, inventory every certificate across your organization.
  2. Automate what you can before the next renewal hits: Even partial automation for your highest-volume or highest-risk certificates reduces the operational load of the next compression.
  3. Establish clear ownership across security, IT, and DevOps: Renewal cadence is now fast enough that ambiguity about who's responsible causes real delays.
  4. Build (or stress-test) your DCV workflow: With reuse periods shrinking, a repeatable validation process matters as much as the renewal itself. Consider persistent DCV from CLM providers like Sectigo, so you can set it and forget it with domain validation.
  5. Set monitoring and alerting thresholds now, not after a near-miss: With renewals landing every six months instead of annually, alerting windows calibrated for a 398-day cycle are already out of date.
  6. Use this cycle as a dry run for 100 days: Whatever breaks or takes too long this time is exactly what needs fixing before March 2027, when the same workload compresses again.
What CLM automation removes from this picture

The gaps that show up in a first 200-day renewal cycle are rarely about certificates themselves. They're about the manual processes wrapped around them. Automated certificate lifecycle management (CLM) addresses each one directly:

  • Discovery: A continuously updated inventory replaces one-time audits, so certificates don't fall out of view between renewal cycles.
  • Issuance and renewal: Protocols like the Automated Certificate Management Environment (ACME) let certificates renew automatically as they approach expiration, without a person tracking dates manually.
  • DCV: Centralized, repeatable domain validation workflows keep pace with shrinking reuse windows instead of becoming a bottleneck at each renewal. Persistent DCV simplifies domain validation at scale.
  • Monitoring and alerting: Centralized visibility flags certificates approaching expiration before they become urgent, rather than after a service is already degraded.
  • Governance: Clear audit trails and ownership records replace the ambiguity that slows down response when something does need attention.

None of this eliminates the underlying policy shift. Validity periods are still shrinking on schedule and will likely continue to shrink after the 47-day stepdown. What it removes is the labor and risk of managing that shift by hand.

100 days is next

200-day validity was framed as an adjustment window, and for organizations acting now, it still can be. But the next stepdown is already scheduled: 100-day maximum validity takes effect March 15, 2027, cutting today's renewal cycle in half again. Whatever gaps this first 200-day cycle exposes will only get harder to manage at 100 days, and unsustainable at the eventual 47-day maximum in 2029.

Organizations that use this cycle to build real automation will absorb the next one. Organizations that patch through it manually will hit a harder wall in less than a year.

Get ahead of the renewal curve with SCM

Renewal frequency will keep climbing between now and 2029. Manual, calendar-driven certificate management wasn't built for this pace, and the current renewal cycle is proving it in real time.

Sectigo Certificate Manager (SCM) automates certificate discovery, issuance, renewal, and monitoring end-to-end, so a compressed validity period becomes a configuration change, not a fire drill. Schedule a demo to see how SCM handles the renewal surge already underway.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Why shorter certificate lifespans matter for cybersecurity?09.824-09-2026
2End of manual certificate management: Why automation is becoming a cybersecurity requirement09.0124-09-2026
3Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations011.7426-02-2026
4What Merkle Tree Certificates (MTCs) mean for your certificate operations011.625-09-2026
5CISA 2015: Congress Faces Fast-Approaching Deadline to Reauthorize a Critical Cybersecurity Law012.9714-08-2025
6The Defense Department’s Cybersecurity Requirements Go Live08.811-09-2025
7WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026
8Security Slam 2026 – Fall edition012.9925-09-2026
9"Соглашение о внесении изменений в Отраслевое соглашение по Федеральной службе безопасности Российской Федерации на 2023 - 2025 годы" (утв. ФСБ России, Профессиональным союзом работников органов безопасности РФ 31.08.2026)013.5129-09-2026

Классификация: Информация. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.38. Источник: sectigo.com.