TLS Certificate Lifespan Reduction Impacts Cybersecurity Operations

TLS Certificate Lifespan Reduction Impacts Cybersecurity Operations

First seen 17 Mar 2026, 16:53 UTC Feeds2.FeedburnerMsspalert 39.9

Article Content

Browse articles
ThreatCluster

The CA/Browser Forum has implemented a phased reduction in the lifespan of TLS certificates, starting from March 15, 2026, when the maximum validity dropped from 398 days to 200 days. This change aims to enhance security against potential threats, especially in light of future quantum computing capabilities. By March 15, 2027, the lifespan will further decrease to 100 days, and by March 15, 2029, it will be reduced to just 47 days. Organizations are facing operational challenges as the number of TLS certificates is expected to rise significantly, with enterprises averaging 3,730 certificates in use, projected to increase to over 5,000. The shift necessitates enhanced automation in certificate management to handle the increased administrative burden. MSSPs will play a critical role in managing these changes, ensuring automated discovery, monitoring, and renewal processes are in place. The transition is seen as essential for minimizing risks associated with outdated certificates and improving regulatory compliance.

Key Points: • TLS certificate lifespans reduced from 398 days to 200 days as of March 15, 2026. • Future reductions will see lifespans drop to 100 days in 2027 and 47 days by 2029. • Organizations must enhance automation in certificate management to cope with increased operational demands.

Timeline

2025-03-15
CA/Browser Forum voted to reduce TLS certificate lifespans.
2026-03-15
TLS certificate maximum lifespan reduced to 200 days.
2027-03-15
TLS certificate maximum lifespan to be reduced to 100 days.
2029-03-15
TLS certificate maximum lifespan to be reduced to 47 days.