TLS certificate lifetimes: 200, 100, then 47 days
Public TLS certificate renewal windows are shrinking. The practical work is not the date itself; it is knowing which certificates exist, who owns them, and which renewal paths still depend on manual steps.
What changes
The CA/Browser Forum Baseline Requirements now include a staged reduction in maximum public TLS certificate lifetimes. On the current schedule, certificates issued from March 15, 2026 are capped at 200 days. The cap moves to 100 days on March 15, 2027 and to 47 days on March 15, 2029.
Domain and IP validation reuse periods shrink too. The important 2029 change is that validation reuse for domain names and IP addresses drops to 10 days, so renewal processes that still rely on occasional manual validation become much more fragile.
What to inventory before the next reduction
- List public certificates from CT logs and compare them with the inventory your teams already maintain.
- Identify internal TLS endpoints that are not visible from the public internet.
- Assign owners to certificates and domains before the renewal window becomes urgent.
- Check which renewal paths are automated and which still depend on a human approval, DNS change, or manual upload.
- Route alerts to the operational channel that can act, not only to a shared security mailbox.
Where Nocert fits
Nocert does not issue certificates. It monitors public and internal TLS observations and routes expiration alerts through certificate and endpoint rules. Business and Custom Compliance workspaces add policy findings and timestamped evidence. That makes Nocert useful before, during, and after a renewal automation project: the deployed result stays visible even when issuance is handled by another tool.
Primary source
The schedule above is based on the CA/Browser Forum Baseline Requirements and Ballot SC081v3. Review the current Baseline Requirements directly before making policy decisions, because root program and browser requirements can continue to evolve.