The certificate authorities small sites rely on aren't ready for the 47-day clock
TLS certificate lifetimes are shrinking toward 47 days, but many CAs still issue long-dated certs. What our weekly data shows and how to check your own cert.
The industry has agreed where this is heading. The maximum lifetime of a TLS certificate — the file that puts the padlock in the address bar and proves your site is really yours — is being cut, step by step, toward a ceiling of just 47 days. Under the CA/Browser Forum schedule agreed in April 2025 (ballot SC-081v3), the maximum lifetime — until recently 398 days — dropped to 200 days on 15 March 2026, falls to 100 days on 15 March 2027, and reaches 47 days on 15 March 2029. The logic is sound: a certificate that lives for weeks rather than years is far less use to anyone who steals it, and it forces renewal to be automated rather than remembered. A shorter clock is a safer clock.
But there’s a quiet gap between the rule and the readiness for it, and it doesn’t sit only with website owners. It sits with the certificate authorities — the organisations that issue certificates in the first place. Each week we measure the certificates being issued across the public web, and the validity windows they’re handing out tell you how ready the ecosystem actually is for a 47-day world. When we last measured, on 9 August 2026, about 87% of newly issued certificates still carried a validity window longer than the eventual 47-day limit — so on the supply side, most issuance hasn’t moved yet.
Why it stays invisible
A certificate’s expiry is the definition of a deadline nobody sees coming until it arrives. Nothing degrades as the date approaches. The site works perfectly the day before, and then the certificate expires and every visitor is met with a full-page red warning telling them the connection isn’t private. There’s no gradual slope, just a cliff — and historically the cliff was a year away, far enough that “we’ll deal with it nearer the time” felt safe.
Shrinking the lifetime removes that comfort. When a certificate lasts 47 days, a once-a-year manual renewal isn’t merely risky, it’s arithmetically impossible — you’d hit the cliff seven or eight times between reminders. The only arrangement that survives is automated renewal. Yet the certificate a site is issued today reflects whatever its provider defaults to, and if that provider is still issuing long-dated certificates against manual renewal, the site inherits a habit with a built-in expiry date of its own.
This is the sort of shift that’s easy to miss precisely because it’s being phased in politely, over years, in stages. Each step down feels survivable, so nobody changes how they work — until the interval drops below what a human can keep up with by hand, and the whole arrangement has to change at once.
The per-CA picture, from that same 9 August measurement, varies enormously. Amazon — whose certificates are issued and renewed automatically inside its cloud — had already moved about 93% of its issuance to 47 days or shorter. At the other end, GoDaddy was still issuing effectively all of its certificates with longer windows, and Sectigo, Google Trust Services and Let’s Encrypt were each above 96%. DigiCert sat in between, with roughly a quarter of its certificates already inside the 47-day window. One honest caveat: a long window isn’t automatically a problem if renewal is automated — Let’s Encrypt and Google issue roughly 90-day certificates through automated protocols, so those renew themselves regardless of the window. The readiness that actually matters is whether renewal happens without a human remembering; the validity window is only a visible proxy for it, and the supply side is a useful early-warning sign, not a verdict on any one site.
Find it yourself
You don’t need our dataset to check the one certificate you care about — your own. Two minutes.
- Open your site in a browser and click the padlock in the address bar.
- Open the certificate details. In Chrome or Edge, click Connection is secure → Certificate is valid to open the certificate viewer. In Firefox, click the padlock, then Connection secure → More information → View Certificate.
- Read two dates: “Issued on” and “Expires on”. The gap between them is your certificate’s lifetime. If it’s around a year, you’re on the old, long-window model — the one the shrinking clock is about to make untenable.
- Find out who issued it. In the same view, read the Issued by field — that’s your certificate authority. Note it; it matters for the fix.
- Ask the question that actually counts: when this expires, what renews it? If the honest answer is “someone gets an email and does it by hand”, you have a manual renewal on a shrinking clock, which is the failure this issue is about — regardless of today’s expiry date.
The uncomfortable moment is usually step 5: the certificate is fine, the date is months away, and nobody can name what renews it.
The fix
The destination is the same for every site: renewal that happens on its own, well before expiry, without anyone remembering.
Move to automated issuance. The open standard for this is called ACME — the protocol that lets your server request and install a fresh certificate automatically. Most modern hosting platforms, CDNs and certificate providers support it, and many issue short-lived certificates that renew every few weeks without you touching anything. If your provider is still handing you a long-dated certificate to install by hand, that’s your signal to switch to one that automates it — the check in step 4 told you who you’re dealing with.
Automate first, then let the lifetime shrink on its own. Once renewal is automatic, a shorter validity window is a non-event — the machine simply renews more often. The whole point of getting off manual renewal now, before the clock tightens further, is that you make the change once, calmly, rather than in a scramble the first time a 47-day certificate catches you out.
Keep a warning in reserve. Automation occasionally breaks quietly — a changed permission, an expired account. A simple expiry monitor that emails you if a certificate ever drops below, say, two weeks of life is the backstop that catches the day the automation stops without telling you.
The shrinking clock isn’t a threat so much as a forcing function: it retires the one arrangement that was always fragile — a renewal that depended on a person remembering — and replaces it with one that can’t be forgotten. Get there before the deadline shrinks again, and it’s a problem you never have to think about.
Knowing every certificate you’re responsible for, and being warned before any of them lapse, is exactly the kind of quiet monitoring that’s easy to intend and easy to drop. DomainOps keeps an eye on your certificates and their expiry windows so a lapsed renewal never becomes a red warning page — but the two-minute check above costs nothing, so start there.
The base rate behind this issue
Read next
One real, fixable exposure every week. Free.