- Key Takeaways
- What did Google originally propose?
- What did the CA/Browser Forum actually adopt?
- Why did the industry move toward automation regardless of the exact number?
- How should organizations prepare for the SC-081v3 schedule?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Ready for the SC-081v3 Certificate Schedule
Google’s 90-day TLS certificate proposal was a 2023 push to shorten public TLS certificate validity to 90 days; the CA/Browser Forum ultimately adopted a different, phased schedule under Ballot SC-081v3, reducing validity to 200 days by March 2026, 100 days by March 2027, and 47 days by March 2029.
Google originally proposed cutting maximum TLS certificate validity from 398 days to 90 days to force automation and limit compromised-key exposure. The CA/Browser Forum adopted Ballot SC-081v3 instead, phasing validity down to 200 days in March 2026, 100 days in March 2027, and 47 days in March 2029, a longer runway than Google’s original proposal.
Key Takeaways
- Google’s original 2023 proposal targeted a flat 90-day maximum TLS certificate validity, down from the 398-day limit set in 2020.
- The CA/Browser Forum adopted a different, phased outcome under Ballot SC-081v3: 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029.
- The core motivation carried through to the adopted schedule: shorter validity limits the exposure window from a compromised private key and forces automation.
- Automated Certificate Management Environment (ACME) tooling, popularized by Let’s Encrypt, is now the standard mechanism for meeting shortened renewal cycles.
- Organizations without automated certificate lifecycle management face a materially higher risk of outages as the SC-081v3 schedule phases in.
What did Google originally propose?
In 2023, Google proposed reducing the maximum validity of public TLS certificates from 398 days to 90 days, arguing that shorter lifespans would force automation, limit the damage window from a compromised key, and speed adoption of newer security practices, including preparation for post-quantum cryptography.
What did the CA/Browser Forum actually adopt?
The CA/Browser Forum did not adopt Google’s flat 90-day figure. Instead, it passed Ballot SC-081v3, a phased schedule that gives organizations a longer transition runway than Google’s original proposal while still reaching a shorter endpoint than 90 days.
| Effective date | Maximum validity |
|---|---|
| March 15, 2026 | 200 days |
| March 15, 2027 | 100 days |
| March 15, 2029 | 47 days |
This continues a longer trend: the CA/Browser Forum previously cut maximum validity from 825 days to 398 days, effective September 2020. The SC-081v3 schedule extends that trajectory to a 47-day endpoint rather than stopping at 90 days.
Why did the industry move toward automation regardless of the exact number?
- Reduced exposure window: a shorter validity period limits how long a compromised key or mis-issued certificate stays trusted.
- Faster adoption of new cryptography: frequent renewal cycles make it easier to roll out updated algorithms, including post-quantum candidates, across a certificate estate.
- Fewer expired-certificate outages: automated renewal through ACME removes the single most common cause of certificate-related downtime, a missed manual renewal.
The Automated Certificate Management Environment (ACME) protocol, used widely through Let’s Encrypt, automates certificate issuance, renewal, and revocation, and is the practical mechanism most organizations now rely on to meet either a 100-day or a 47-day validity requirement without manual intervention.
How should organizations prepare for the SC-081v3 schedule?
- Conduct a full certificate audit to discover every certificate currently in use, including ones outside central IT’s visibility.
- Deploy ACME agents across web servers, load balancers, and reverse proxies to automate issuance and renewal.
- Centralize monitoring and alerting so unusual certificate behavior or an upcoming expiration surfaces before it causes an incident.
- Scale the automation to cover every environment, from cloud workloads to IoT devices, as the 100-day and then the 47-day deadlines arrive.
How Encryption Consulting Helps
CertSecure Manager centralizes certificate discovery, ACME-based automated renewal, and real-time monitoring, so your organization is ready for each phase of the SC-081v3 schedule without manual renewal work. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
Did Google’s 90-day certificate proposal actually take effect?
No. Google proposed a flat 90-day maximum validity in 2023, but the CA/Browser Forum adopted a different, phased schedule under Ballot SC-081v3 instead: 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029.
What is the current maximum validity for a public TLS certificate?
As of the SC-081v3 schedule, maximum validity is 200 days starting March 15, 2026, dropping to 100 days starting March 15, 2027, and reaching 47 days starting March 15, 2029.
Why did the industry move away from a flat 90-day rule?
The phased SC-081v3 schedule gives Certificate Authorities and large enterprises more time to build out automation before reaching a 47-day endpoint, rather than requiring an abrupt jump straight to 90 days, which many organizations argued was operationally disruptive without adequate lead time.
What tool helps organizations meet shorter certificate validity requirements?
The Automated Certificate Management Environment (ACME) protocol, widely used through Let’s Encrypt and supported by platforms like CertSecure Manager, automates certificate issuance, renewal, and revocation, removing the manual renewal step that shorter validity periods make impractical.
Get Ready for the SC-081v3 Certificate Schedule
Take the next step
CertSecure Manager automates certificate discovery, ACME-based renewal, and monitoring so you are ready for every phase of the SC-081v3 schedule, from 200 days down to 47. Get ready for 47-day certificates.
- Key Takeaways
- What did Google originally propose?
- What did the CA/Browser Forum actually adopt?
- Why did the industry move toward automation regardless of the exact number?
- How should organizations prepare for the SC-081v3 schedule?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Ready for the SC-081v3 Certificate Schedule
