Certificate lifetimes
47-day certificates are coming. Renewal is the new expiry.
The CA/Browser Forum is cutting the maximum life of a TLS certificate from 398 days to 200, then 100, then 47 days by March 2029. Renewal stops being an annual chore and becomes a job that runs every few weeks - and fails silently. Here is the timeline and how to keep watch.
Free personal workspace forever · No credit card
The schedule
Maximum certificate lifetime, by date
398 days
Until 15 Mar 2026
200 days
In force since 15 Mar 2026
100 days
From 15 Mar 2027 - in 156 days
47 days
From 15 Mar 2029 - in 887 days
Source: CA/Browser Forum ballot SC-081v3, passed 11 April 2025. The 398-day figure is the limit browsers have enforced since September 2020.
What changes
Why shorter certificates change how you monitor
Renewal replaces expiry as the signal
With 47-day certificates a site renews eight times a year. The question is no longer "when does it expire" but "did the renewal that was due last week actually happen" - and did the server pick it up.
Fixed alert ladders age badly
30/14/7-day thresholds were tuned for one-year certificates. On short-lived ones the 30-day alert fires on every single certificate, right before it renews anyway, and gets ignored or turned off.
Validation reuse shrinks too
The same ballot cuts how long a domain validation can be reused to 10 days by 2029. Validation has to be as automated as issuance, so a broken DNS record or webroot breaks renewal on the very next cycle.
Nobody emails you any more
Let's Encrypt stopped sending expiry notifications on 4 June 2025 and recommends third-party monitoring instead. ACME clients log renewal failures locally, where nobody reads them.
The watch
What CertSentry does about it
Renewal-aware thresholds
Expiry thresholds that would fire before the renewal is even due are skipped automatically, so a 90-day certificate stops paging you at day 60. Long-lived certificates keep the full ladder.
Renewal-overdue alert
Every check records when the served certificate was issued. Once it passes three quarters of its lifetime without being replaced you get one alert - weeks before expiry, while there is time to fix the job.
A heartbeat from the renewal job
Pair a certificate with a heartbeat pinged from your renewal hook. The overdue alert then says whether the job never ran or ran and failed to deploy - two very different fixes.
Readiness at a glance
The certificates view shows what share of your estate renews automatically, which certificates are due or overdue, and how many still exceed the next lifetime cap.
Questions
Common questions
When do 47-day certificates start?
New certificates are limited to 47 days from 15 March 2029, under CA/Browser Forum ballot SC-081v3 (passed 11 April 2025). Before that the cap drops to 200 days from 15 March 2026 and 100 days from 15 March 2027. A certificate keeps the validity it was issued with; only new issuance is affected.
Do I have to change anything now?
Certificates issued today can be no longer than 200 days, so anything still renewed by hand already renews twice as often as it did a year ago. The practical step is to automate renewal (ACME) before the 100-day cap in 2027, and to monitor that the automation keeps working - that is the part that fails silently.
What is ARI?
ACME Renewal Information (RFC 9773) lets a CA tell your ACME client when to renew, including early renewals after a revocation. Newer certbot releases and Caddy support it; many other clients do not yet, and none of them tell you when a renewal fails. Watching the certificate you actually serve closes that gap.
Why does a fixed 30-day expiry alert stop working?
On a 47-day certificate, 30 days before expiry is day 17 of its life - long before any renewal is due. A fixed threshold either fires on every certificate or gets switched off. Alerts have to scale with the lifetime: renewal is due once a third of the lifetime remains, and it is overdue when that window passes with the same certificate still being served.
The next expiry email you get should be from us.
Not from a furious client. Add your first domain in under a minute.
Start the watch, free