Managing Short SSL Certificate Validity

Shorter SSL Certificate validity periods are no longer something to prepare for. The first reduction took effect on March 15, 2026, and every SSL Certificate issued since that date carries a maximum validity of 200 days.

That means more frequent reissues across the life of your license. This page covers what changes in practice, what you can put in place today, and what Trustico® is building to make each cycle easier. It is updated as each tool becomes available.

Where the Validity Reductions Stand Today

The CA/Browser Forum approved a phased reduction in the maximum lifetime of an SSL Certificate. The reduction to 200 days took effect on March 15, 2026. Validity reduces again to 100 days on March 15, 2027, and to 47 days on March 15, 2029.

The purpose is to confirm domain ownership more often, which shortens the window in which a compromised or incorrectly issued SSL Certificate could be exploited. Learn About the 200 Day Change 🔗

Understanding Your License and Your SSL Certificate

When you order an SSL Certificate from Trustico® you obtain a license that runs for a set period, commonly one, two, three, four or five years. The license is what you pay for and it is unaffected by the industry reductions.

The issued SSL Certificate is a separate thing. It carries its own validity period, capped at the current industry maximum, and it stops working on its own expiration date rather than on the date your license ends.

Note : A license validity period and an SSL Certificate expiration date are two separate things. Your license defines the total period you have paid for. Your SSL Certificate expiration is the date when your currently issued SSL Certificate stops working and needs to be reissued against that license.

Keeping your website protected for the whole license period therefore means reissuing your SSL Certificate each time the issued one approaches its expiration date. Learn About Maintaining Your Protection 🔗

Reissue Frequency Under a 200 Day Maximum

At a 200 day maximum, a one year license needs roughly two issuances, a three year license roughly six, and a five year license roughly ten. The exact count depends on when each SSL Certificate is issued within the license period.

Reissuing carries no additional charge. Within your license you can reissue your SSL Certificate as many times as you need, and the procedure itself has not changed. The only practical difference is how often you carry it out.

Reissuing Your SSL Certificate

Reissues are performed through the Trustico® tracking system on an order-by-order basis. You submit your existing Certificate Signing Request (CSR) to keep your current Private Key, or a new Certificate Signing Request (CSR) if you prefer a fresh key pair.

You then complete Domain Control Validation (DCV) again so that the Certificate Authority (CA) can confirm you still control the domain. Learn About Reissuing an SSL Certificate 🔗

Shorter Domain Control Validation (DCV) Reuse Periods

Reissuing more often is only part of the change. The same industry schedule shortens how long a completed Domain Control Validation (DCV) may be reused, which means you will revalidate more often as well, not simply reissue more often.

That matters most if you rely on approver e-mail, or if the person receiving validation e-mail is not the person managing the server. Learn About Reuse Periods 🔗

Tracking Every Expiry Date

The Trustico® tracking system displays your license validity dates alongside the validity details of the last SSL Certificate issued against that order. It also provides downloadable calendar files for both, so each date can be placed directly into your own calendar.

Setting those reminders now is the most effective single step available to you, because a shorter validity period leaves far less margin if a date is missed. Learn About The Tracking System 🔗

Important : Customers and partners are responsible for monitoring the expiry dates of installed SSL Certificates. The ordering system displays all orders on an account with the purchased license validity dates, however each SSL Certificate has its own validity dates dependent on when it was issued within the license period.

When managing several SSL Certificates, dedicated SSL Certificate monitoring software is advisable so that installed SSL Certificates are detected and you are alerted when a reissue is due.

Responsibility for keeping an SSL Certificate current sits with the certificate owner, or with the server administrator acting on their behalf. Learn About Your Obligations 🔗

Automating with Certificate as a Service (CaaS)

Certificate as a Service (CaaS) removes the manual cycle altogether. Rather than reissuing each SSL Certificate yourself, your own software obtains and reissues SSL Certificates automatically for the life of the subscription.

Trustico® provides a set of Automatic Certificate Management Environment (ACME) credentials, including your External Account Binding (EAB) keys. Your Automatic Certificate Management Environment (ACME) client then handles issuance and installation continuously. Learn About Certificate as a Service (CaaS) 🔗

Every server environment differs, so while Trustico® supplies the credentials, the implementation on your infrastructure remains your responsibility. Learn About Automatic Certificate Management Environment (ACME) Clients 🔗

Certificate as a Service (CaaS) is a premium service and currently covers selected products rather than the full range. Discover Traditional and CaaS Compared 🔗

Tools in Development

Trustico® is extending the tracking system to reduce the manual effort further. A dedicated Application Programming Interface (API) will allow a reissue to be requested programmatically, with your preferred Domain Control Validation (DCV) method and retrieval of both SSL Certificate and license expiry dates.

Notification services for approaching expiry, and automated installation support for widely used server control panels, are also in development. Supported platforms will be announced as each integration becomes available.

Tip : If automated installation matters to your workflow, let Trustico® know which server control panel you use. That feedback helps prioritize which platforms are supported first.

Feedback from customers and partners directly shapes the order in which these integrations are delivered. Learn About Contacting Trustico® 🔗

Choosing the Right Approach for Your Workflow

If you manage a small number of SSL Certificates, the tracking system combined with calendar reminders remains straightforward and requires no additional setup on your part.

If you manage a larger estate, or you would rather not track dates at all, Certificate as a Service (CaaS) moves the entire cycle onto your own infrastructure and removes the reissue cadence completely.

Either way, the shorter validity periods are already in effect, so the sooner reminders or automation are in place, the less exposure there is to a missed date. Learn About Trustico® Support Options 🔗

Most Popular Questions

Frequently asked questions covering shorter SSL Certificate validity periods, reissue frequency within a license, Domain Control Validation reuse, expiry tracking, and automation options.

Current Maximum SSL Certificate Validity Period

The maximum validity of a newly issued SSL Certificate is 200 days, in effect since March 15, 2026. This reduces again to 100 days on March 15, 2027, and to 47 days on March 15, 2029. The schedule was approved by the CA/Browser Forum and applies across the industry.

License Validity Compared With SSL Certificate Expiration

Your license validity period is the total time you have paid for, commonly one to five years. Your SSL Certificate expiration date is when the currently issued SSL Certificate stops working and needs to be reissued against that license. The two dates are separate and both need to be monitored.

Reissue Frequency Within a Multi Year License

At a 200 day maximum, a one year license needs roughly two issuances, a three year license roughly six, and a five year license roughly ten. The exact number depends on when each SSL Certificate is issued within the license period.

Cost of Reissuing an SSL Certificate

Reissuing carries no additional charge. Within your license you may reissue your SSL Certificate as many times as you need, so the shorter validity periods do not reduce the value of what you have paid for.

Reissue Procedure Through the Tracking System

Reissues are performed in the Trustico® tracking system on an order-by-order basis. You submit your existing Certificate Signing Request (CSR) to retain your current Private Key, or a new one for a fresh key pair, then complete Domain Control Validation (DCV) again.

Domain Control Validation (DCV) Reuse Period Changes

The same industry schedule that shortens SSL Certificate validity also shortens how long a completed Domain Control Validation (DCV) may be reused. This means domain control is confirmed more often, so revalidation becomes part of the routine rather than an occasional step.

Calendar Reminders for Expiry Dates

The tracking system provides downloadable calendar files for both your SSL Certificate expiry and your license expiry. Adding both to your own calendar is the simplest way to stay ahead of a shorter validity period.

Responsibility for Monitoring Installed SSL Certificates

Customers and partners are responsible for monitoring the expiry dates of installed SSL Certificates. Where several SSL Certificates are in use, dedicated SSL Certificate monitoring software is advisable so that installed SSL Certificates are detected and alerts are raised before a reissue is due.

Certificate as a Service (CaaS) as an Automated Alternative

Certificate as a Service (CaaS) replaces the manual reissue cycle with continuous automated issuance against a subscription. Trustico® supplies Automatic Certificate Management Environment (ACME) credentials and your own client handles issuance and installation. It is a premium service covering selected products.

Tools Currently in Development at Trustico®

A tracking Application Programming Interface (API), expiry notification services, and automated installation support for widely used server control panels are all in development. This page is updated as each one becomes available.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6