cert-governance · severity medium

Certificate lifetime readiness

Share of newly issued certificates with a validity window longer than the 47-day maximum the CA/Browser Forum is phasing in — renewals that must be automated before the deadline.

Measured every Sunday · last updated

How it is measured

Stream a Certificate Transparency log, parse each leaf, compute not_after − not_before. Population unit: certificate; segmented by CA.

Why it matters

The same deadline seen from the supply side. It shows which CAs have already moved their customers to automated short-lived issuance and which are still writing certificates that will be non-compliant — a per-CA readiness table nobody else publishes.

Limits of this measurement

Measured over a sample of recent issuance, so it reflects current practice rather than the installed base. The 47-day threshold was chosen after a 100-day cut returned 0% everywhere — issuance had already moved below it, leaving no variance to observe.

The base rate

Measured over the full population of certificates, from public bulk sources.

All certificates 86.71% fail · n=12,000
within_47d: 13.29%longer_than_47d: 86.71%
within_47d · 13.29%longer_than_47d · 86.71%

Every segment

Pick one to see the citable answer, with its trend and methodology.

Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.