Tools Learn Login Sign up
Home Tools 47-Day Readiness

47-Day Certificate Readiness

Certificate lifetimes are shrinking to 47 days by 2029. Is your domain ready for automated renewal?

What's Changing
March 15, 2026 — 200-day maximum
CA/Browser Forum ballot SC-081 reduces maximum certificate lifetime to 200 days.
March 15, 2027 — 100-day maximum
Further reduction to 100 days. Domain validation (DCV) reuse also drops to 100 days.
March 15, 2029 — 47-day maximum
Final reduction. DCV reuse limited to 10 days. Manual management is impossible.

Why This Matters

Manual certificate renewal every 47 days is impractical. Organizations without ACME automation will face outages.

What We Check

Certificate validity period, ACME CA detection, automation indicators, CAA records, and expiry status.

Get Ready Now

Set up certbot, acme.sh, or Caddy for automated ACME certificate issuance before the deadlines hit.

Frequently asked questions

Why are SSL certificate lifetimes shrinking to 47 days?

Under CA/Browser Forum ballot SC-081, the maximum lifetime of public TLS certificates drops from 398 to 200 days in March 2026, to 100 days in March 2027 and to 47 days in March 2029. Shorter lifetimes limit the damage of a compromised key and force healthier automation.

How do I prepare for 47-day certificates?

Automate issuance and renewal with an ACME client such as certbot, acme.sh, lego or Caddy, renew well before expiry, and monitor independently so a failed renewal is caught before the certificate lapses. Manual renewal is not viable at 47 days.

What are ACME and ARI?

ACME (RFC 8555) is the protocol that Let's Encrypt and other CAs use to issue certificates automatically. ARI (ACME Renewal Information, RFC 9773) lets the CA tell your client the ideal renewal window, which matters more as lifetimes shrink.

When do the new certificate limits take effect?

200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. Certificates issued before each date keep their original lifetime.

What does this checker look at?

It inspects a domain's current certificate validity window, whether it appears to use an ACME-capable CA, signs of automation, CAA records and how close it is to expiry, then rates how ready you are for shorter lifetimes.

Report a bug

We're new and growing — your feedback helps us improve.

Click to upload, or paste (Ctrl+V) an image