Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

47-Day Certificate Validity: The Complete Explainer and Readiness Checklist

Certificate Lifecycle Management

47-day certificate validity is the final stage of a CA/Browser Forum-mandated schedule, Ballot SC-081v3, that phases down the maximum lifespan of publicly trusted TLS certificates from today’s 398 days to 47 days by March 15, 2029, through intermediate steps of 200 days and 100 days.

47-day certificate validity is the endpoint of Ballot SC-081v3, the CA/Browser Forum’s phased reduction of maximum public TLS certificate lifespan. Validity drops to 200 days starting March 15, 2026, then 100 days starting March 15, 2027, then 47 days starting March 15, 2029. Every publicly trusted certificate issued after each date must comply, making automated renewal mandatory rather than optional.

Key Takeaways

  • 47 days is the final step in a three-stage schedule under Ballot SC-081v3: 200 days from March 15, 2026, 100 days from March 15, 2027, and 47 days from March 15, 2029.
  • This replaces earlier, less precise “90-day certificate” framing; the CA/Browser Forum adopted this phased schedule instead of a flat 90-day rule.
  • At a 47-day maximum, a certificate must be renewed roughly 7 to 8 times a year per domain, which makes manual renewal operationally unworkable at any meaningful scale.
  • Domain Control Validation (DCV) reuse is also being shortened alongside certificate validity, meaning organizations will need to revalidate domain ownership more frequently too.
  • Automated Certificate Management Environment (ACME) protocol adoption, paired with a centralized certificate management platform, is the practical path to compliance at every stage of the schedule.

What is the Full SC-081v3 Validity Schedule?

Ballot SC-081v3 is the CA/Browser Forum decision that sets the maximum validity period for publicly trusted TLS/SSL certificates on a fixed, three-stage timeline. Each stage takes effect on its own date and applies to certificates issued on or after that date; certificates issued earlier keep their original validity until they expire or are replaced.

Effective dateMaximum certificate validityApproximate renewals per year
Today (pre-March 2026)398 days~1
March 15, 2026200 days~2
March 15, 2027100 days~4
March 15, 202947 days~7-8

Why is Certificate Validity Shrinking?

The core rationale is exposure time. A compromised private key or a mis-issued certificate stays trusted, and therefore exploitable, for as long as that certificate remains valid. Shortening validity shrinks that window and forces the industry toward automated issuance and renewal, which also makes it faster to roll out algorithm updates, including the eventual shift toward post-quantum cryptography, across a certificate estate.

Wasn’t this Google’s 90-day Certificate Poposal?

Google originally proposed a flat 90-day maximum validity in 2023. The CA/Browser Forum did not adopt that specific number. Instead, it passed Ballot SC-081v3, the phased 200/100/47-day schedule above, which reaches a shorter endpoint than Google’s original proposal but gives the industry a longer, staged runway to get there. Any content, internal documentation, or bookmarked article still describing a coming “90-day certificate” rule is describing a proposal that was superseded by this schedule.

What Else is Changing Alongside Certificate Validity?

  • Domain Control Validation (DCV) reuse period: the maximum time a CA can reuse a prior domain validation without rechecking it is also shortening, meaning domain ownership must be reconfirmed more often, not just the certificate itself reissued.
  • Multi-Perspective Issuance Corroboration: CAs increasingly validate domain control from multiple network vantage points before issuing, reducing the risk of routing-based validation attacks.
  • Short-lived certificate profiles: some CAs now offer certificate profiles built specifically for sub-10-day lifespans as an even more aggressive option ahead of the 2029 deadline, aimed at highly automated environments.

47-Day Certificate Readiness Checklist

Use this checklist to assess readiness for each stage of the SC-081v3 schedule, starting with the March 2026 deadline.

  1. Inventory every certificate you run, including ones outside central IT’s visibility, such as certificates embedded in load balancers, IoT devices, and internal tooling.
  2. Identify which certificates are issued, renewed, and deployed manually today, since these are the ones a 47-day cycle will break first.
  3. Deploy ACME clients across web servers, load balancers, and reverse proxies, and confirm each can complete a DNS-01 or HTTP-01 challenge without manual intervention.
  4. Centralize certificate visibility and renewal in a single platform rather than leaving it spread across teams, spreadsheets, and ad hoc scripts.
  5. Automate deployment, not just issuance: confirm renewed certificates are pushed to the systems that use them without a manual reload or restart step.
  6. Set up expiration and renewal-failure alerts with enough lead time to fix a failed automated renewal before the old certificate expires.
  7. Test the full automated cycle end to end well before each SC-081v3 deadline, rather than waiting for the deadline to discover a gap.
  8. Revisit domain validation processes, since shortened DCV reuse windows mean domain control will need to be reconfirmed more frequently, independent of certificate reissuance.
  9. Build a documented incident response plan for a compromised or mis-issued certificate, including who can revoke and reissue outside the normal renewal cycle.
  10. Assign clear ownership for certificate lifecycle management, since a 47-day cycle run without automation and without an owner is the most common way outages happen.

What Happens if an Organization is Not Ready?

Manual certificate management does not scale to a 47-day cycle. At that validity period, a domain needs roughly 7 to 8 renewals a year, and any manual step, requesting the certificate, validating domain control, or deploying it to production, becomes a recurring point of failure. Organizations without automation in place before each SC-081v3 deadline face a materially higher risk of outages, since a single missed renewal now recurs far more often than it did under a 398-day certificate.

How Encryption Consulting Helps

How Encryption Consulting HelpsCertSecure Manager automates certificate discovery, ACME-based issuance and renewal, and deployment across your entire certificate estate, so your organization is ready for the 200-day, 100-day, and 47-day stages of the SC-081v3 schedule without manual intervention. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

When does 47-day certificate validity take effect?

The 47-day maximum takes effect March 15, 2029, as the final stage of Ballot SC-081v3. It follows two earlier reductions: 200 days starting March 15, 2026, and 100 days starting March 15, 2027.

Is 47-day validity the same as Google’s 90-day certificate proposal?

No. Google proposed a flat 90-day maximum in 2023, but the CA/Browser Forum adopted a different, phased schedule instead under Ballot SC-081v3, reaching 47 days by March 2029 through intermediate 200-day and 100-day stages.

How many times will a certificate need to be renewed each year under the new schedule?

At a 47-day maximum validity, a certificate needs roughly 7 to 8 renewals per year per domain, compared to about 1 renewal a year under today’s 398-day maximum.

What is the single most important step to prepare for shorter certificate validity?

Automate the full lifecycle, not just issuance: discovery, DCV, issuance, deployment, and renewal all need to run without manual steps, since manual handling anywhere in that chain becomes a recurring failure point at a 47-day cycle.

Does DCV reuse change along with certificate validity?

Yes. The maximum period a CA can reuse a previous domain validation without rechecking it is shortening alongside certificate validity, so organizations need to plan for more frequent domain control reconfirmation, separate from certificate reissuance itself.

Get Ready for 47-Day Certificates

Take the next step CertSecure Manager automates certificate discovery, ACME-based renewal, and deployment so you are ready for every stage of the SC-081v3 schedule, from 200 days down to 47. Get ready for 47-day certificates.