Manual certificate renewal every 47 days is impractical. Organizations without ACME automation will face outages.
Certificate validity period, ACME CA detection, automation indicators, CAA records, and expiry status.
Set up certbot, acme.sh, or Caddy for automated ACME certificate issuance before the deadlines hit.
Under CA/Browser Forum ballot SC-081, the maximum lifetime of public TLS certificates drops from 398 to 200 days in March 2026, to 100 days in March 2027 and to 47 days in March 2029. Shorter lifetimes limit the damage of a compromised key and force healthier automation.
Automate issuance and renewal with an ACME client such as certbot, acme.sh, lego or Caddy, renew well before expiry, and monitor independently so a failed renewal is caught before the certificate lapses. Manual renewal is not viable at 47 days.
ACME (RFC 8555) is the protocol that Let's Encrypt and other CAs use to issue certificates automatically. ARI (ACME Renewal Information, RFC 9773) lets the CA tell your client the ideal renewal window, which matters more as lifetimes shrink.
200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. Certificates issued before each date keep their original lifetime.
It inspects a domain's current certificate validity window, whether it appears to use an ACME-capable CA, signs of automation, CAA records and how close it is to expiry, then rates how ready you are for shorter lifetimes.
We're new and growing — your feedback helps us improve.