SSL/TLS certificates don't last as long as they used to. A certificate issued today is valid for about 200 days — and that number is set to keep shrinking. Here's what's changing, why, and how your certificate still protects your site for the full period you paid for.
The new certificate lifetimes
The CA/Browser Forum — the industry body whose rules every certificate authority (Sectigo, DigiCert, Comodo and the rest) must follow — has set a schedule that steadily reduces how long a single certificate can be valid:
- Until 14 March 2026 — up to 398 days (about 13 months).
- From 15 March 2026 — up to 200 days.
- From 15 March 2027 — up to 100 days.
- From 15 March 2029 — up to 47 days.
These limits apply to the certificate itself, not to the term you buy — and they apply everywhere, to every CA and every reseller. No one can issue a longer certificate.
Why are lifetimes shrinking?
Shorter-lived certificates are better for security:
- Less exposure if something goes wrong. If a private key is compromised or a certificate is mis-issued, a shorter lifetime limits how long it can be abused.
- Fresher validation. Domain ownership and company details are re-checked more often, so a certificate reflects who really controls a domain today.
- A push toward automation. Shorter cycles encourage automated issuance and renewal, which is far more reliable than manual, once-a-year work.
"So why does my certificate expire before my term ends?"
This is the part that surprises people. If you buy a 1-year (or multi-year) certificate today, the CA still cannot issue a single certificate that lasts a year — the cap is around 200 days. So your purchase isn't one long certificate; it's a plan. You get a certificate now, and before it expires you get the next one — until the full term you paid for is used up. Your paid period isn't lost; it's simply delivered across a short series of certificates, at the price you locked in.
How we manage this for you
We're built so the shorter cycles don't become your problem:
- One dashboard tracks every certificate, its status and its next renewal date.
- Reminders reach you well before each expiry — so a renewal never sneaks up on you.
- Guided reissue. When it's time, we walk you through a quick CSR and domain validation, and the next certificate issues against your plan.
- Multi-year plans lock in today's price and reissue free before each expiry, so a single payment covers years — especially handy now that lifetimes are getting shorter.
What you should do
- Watch for our reminders and keep an eye on the renewal dates in your dashboard.
- Consider a multi-year plan to lock your price and cut the admin — you reissue free instead of re-buying.
- Automate where you can. For fast-changing environments, automated issuance and renewal keeps up with shorter lifetimes without manual effort.