Since March 2026, newly issued public TLS certificates have a reduced lifetime of 200 days. That reduction was only the start of a much greater change. From 15 March 2027, certificate lifetimes fall again to 100 days, meaning every public-facing certificate will need renewing around 3.7 times a year. Eventually, in 2029, certificates will be valid for a maximum of 47 days.
For organisations still relying on manual processes, spreadsheets or partial visibility, that doesn't just increase the workload. It increases the opportunities for something to be missed.
For teams that are already stretched, the next decrease will be here in no time. Before the deadline arrives, it's worth asking some honest, practical questions about how ready your organisation really is, and starting the work now rather than waiting as we’ve seen how long it can take.
Most organisations think they know where all their certificates are until they run a proper discovery scan. In fact, DigiCert's 2026 Global PKI Research found that only 34% of organisations have a complete and current view of their certificate estate. Manual tracking methods, including spreadsheets, remain one of the biggest challenges teams face.
Having a certificate inventory is a good start, but the real test is whether you have continuous, automated discovery across every public-facing certificate, including those protecting legacy websites, acquired domains or applications that no longer have a clearly defined owner.
What this looks like in practice:
A manual renewal typically involves validating ownership, generating a new private key, creating a CSR, requesting the certificate, deploying it and testing everything is working as expected. For many organisations, that's around four hours of work for a single certificate.
With 100-day certificate lifespans, that work no longer happens once a year. It happens around 3.7 times. Across an estate of a thousands of public certificates, that's thousands of additional hours of repetitive manual work every year, all of it landing on teams that typically aren't getting any bigger to handle the increased load. I recently looked at what this means in real terms, including the impact on renewal volumes and operational effort, you can read it here: The Cost of TLS Certificate Renewals.
The question is no longer whether automation is worthwhile. It's whether you can reduce renewal time from hours to minutes before the increase in volume arrives.
What this looks like in practice:
CyberArk's 2026 PKI Modernisation Report found that 56% of organisations have experienced unplanned outages caused by expired or misconfigured certificates. While today's certificate lifetimes are still relatively generous, the transition to 100-day and eventually 47-day certificates will significantly increase the number of renewals organisations need to complete each year. Every additional renewal is another opportunity for something to be missed.
The question is whether you'll know about a failed renewal before your users do. That depends on more than expiry notifications. It means integrating certificate management with your monitoring, ticketing and operational workflows so failures are detected, escalated and resolved before they become production incidents and impact reputation and revenue.
What this looks like in practice:
Research from Enterprise Management Associates (EMA) found that nearly 80% of SSL/TLS certificates in use were still potentially vulnerable to man-in-the-middle attacks, largely because the associated servers were not using TLS 1.3. The same research found that up to 25% of certificates were expired or self-signed, creating further security and trust risks.
As certificate lifetimes shorten, organisations will be issuing and deploying certificates more frequently. Without automated policy checks, that creates more opportunities for weak algorithms, unapproved certificate authorities or incomplete chains of trust to make it into production. It also creates more opportunities to identify and correct those issues, provided validation is built into the renewal process.
That raises an important question: are you automatically validating certificate attributes such as key length, signing algorithms and chains of trust while restricting issuance to approved certificate authorities?
What this looks like in practice:
The move to 100 day certificate lifetimes is a milestone, not the end point. By 15 March 2029, every public TLS certificate will need renewing almost eight times a year. That’s every 47 days.
The real test of readiness isn't whether you can meet the 100-day deadline next year. It's whether the approach you put in place today will still work as certificate lifetimes continue to shrink and cryptographic standards evolve. That means building automation that can scale with future certificate lifetime reductions, while ensuring your infrastructure is crypto-agile enough to adapt to future cryptographic changes, including post-quantum cryptography.
Only 22% of organisations say they've fully assessed their systems for future cryptographic risk (DigiCert 2026 Global PKI Research). For most organisations, the challenge extends beyond shorter certificate lifetimes. It's about building a certificate management strategy that's resilient enough to support whatever comes next.
What this looks like in practice:
Most organisations don't need to solve every challenge overnight. But they do need to understand what they own, where manual effort is creating unnecessary risk, and where automation will have the greatest impact. The earlier that work begins, the easier each future lifespan reduction becomes.
A practical place to start is thoroughly identifying and mapping your estate. ProofID, together with CyberArk, offers a complimentary scan of your public TLS certificates, that will give you a clear view of your external certificates and help you prioritise the work ahead.
Once you've received your results, you'll have the opportunity to book a complimentary strategy session with our certificate lifecycle management experts. They'll walk you through the findings, discuss your current approach and help you build a practical roadmap for managing shorter certificate lifecycles with confidence.
From there, the path is straightforward: