Why SSL Certificates Are Changing: What Website Owners Need to Know
By Robert Wright
If you've owned or managed a website for a while, you may have noticed that SSL/TLS certificates (often simply called "security certificates") seem to need renewal more frequently than they used to. If it feels like the rules keep changing, you're not imagining it.
Over the next few years, the maximum lifespan of security certificates will continue to get shorter. While this may sound like an inconvenience, the changes are designed to make the internet safer for everyone.
Here's what is changing, why it's happening, and what it means for your website.
First, What Is a Security Certificate?
Every secure website uses an SSL/TLS certificate. It's what allows your browser to display the little padlock icon next to a website address and enables the use of https:// instead of http://.
Think of a security certificate as a digital ID card for your website. It serves two important purposes:
- It proves that visitors are actually connected to your website—not someone pretending to be you.
- It encrypts information exchanged between your website and your visitors, helping protect passwords, payment information, contact forms, and other sensitive data.
Without a valid certificate, modern web browsers display prominent security warnings that can discourage visitors from continuing to your site.
Why Are Certificate Lifespans Getting Shorter?
Years ago, website certificates could be valid for five years or more. Eventually that dropped to three years, then two years.
In 2020, the industry reduced the maximum certificate validity period to 398 days (just over one year).
Now the industry is taking the next step.
The primary reason is simple: shorter certificate lifetimes improve security.
Technology changes quickly. Companies change ownership. Websites move to new hosting providers. Encryption standards evolve. Employees come and go. The shorter a certificate remains valid, the sooner outdated or compromised credentials are replaced.
Reducing certificate lifetimes also encourages organizations to automate renewals instead of relying on someone remembering to renew a certificate once every year or two. Automated renewals greatly reduce the risk of a certificate unexpectedly expiring and taking down a website.
Who Is Making These Decisions?
Many people assume companies like Google or Apple control SSL certificates, but the process is actually governed by several organizations working together.
The CA/Browser Forum is an industry group made up of web browser developers (including Google, Apple, Mozilla, and Microsoft) and Certificate Authorities (companies that issue SSL certificates such as DigiCert, Sectigo, GlobalSign, and Let's Encrypt).
The CA/Browser Forum develops the technical standards that govern publicly trusted SSL certificates.
Browser vendors ultimately decide which Certificate Authorities they trust. Because of this, when browser makers support new security requirements, Certificate Authorities must follow those requirements in order for their certificates to remain trusted by modern web browsers.
In recent years, Apple has been one of the strongest advocates for reducing certificate lifetimes, with support from other major browser vendors and members of the CA/Browser Forum.
The New Timeline
The industry has adopted a phased approach rather than making one large change all at once.
Prior to March 15, 2026, the maximum certificate lifetime was 398 days.
Then on March 15, 2026 the maximum certificate lifetime was decreased to 200 days (current).
The upcoming schedule is:
-
March 15, 2027: Maximum certificate lifetime decreases to 100 days
-
March 15, 2029: Maximum certificate lifetime decreases to 47 days
These limits apply to newly issued publicly trusted SSL/TLS certificates after each effective date.
Why 47 Days?
Forty-seven days may sound unusually short, but by the time this change arrives, the expectation is that nearly every website will renew its certificates automatically.
In fact, many websites already do.
Services such as Let's Encrypt issue certificates that are valid for only 90 days, and millions of websites renew them automatically every day without website owners ever noticing.
The move to 47-day certificates continues that trend by making automated certificate management the standard across the internet.
Will This Increase My Workload?
Not necessarily.
If your hosting provider or IT team already uses automated certificate renewal, you may never notice these changes. Certificates will simply renew behind the scenes before they expire.
However, organizations that still manage certificates manually will need to adjust their processes. Waiting until "next year" to renew a certificate will no longer be an option.
For businesses with multiple websites, automation is becoming less of a convenience and more of a necessity.
What Happens If a Certificate Expires?
An expired certificate doesn't usually take your website offline, but it does create a significant trust problem.
Visitors may see messages such as:
-
"Your connection is not private."
-
"This site may not be secure."
-
"Potential security risk ahead."
Many visitors will leave immediately rather than continue to the site.
In addition, some APIs, integrations, payment systems, and mobile applications may refuse to connect to a website with an expired certificate.
The result can be lost traffic, reduced customer confidence, and interruptions to online services.
What Should Website Owners Do?
The good news is that there is no need to panic.
Instead, consider these best practices:
-
Verify that every website you own uses HTTPS.
-
Confirm who is responsible for renewing your SSL certificates.
-
Ask whether certificate renewals are fully automated.
-
Keep contact information up to date so you'll receive renewal notifications if action is ever required.
-
If you manage your own servers, begin planning for automated certificate deployment well before the shorter lifetimes take effect.
Taking these steps now can help prevent future headaches as certificate lifetimes continue to decrease.
Looking Ahead
These changes are part of a broader effort to make the web more secure and more reliable. While renewing certificates more often might initially seem inconvenient, the long-term goal is actually fewer emergencies, fewer expired certificates, and stronger protection for everyone who uses the internet.
The reality is that website security continues to evolve. Encryption standards improve, cyber threats become more sophisticated, and industry best practices adapt over time. Shorter certificate lifetimes are simply one piece of that ongoing evolution.
For most website owners, the transition should be almost invisible—provided certificate renewals are properly automated. If your website is professionally hosted or managed, now is a good time to confirm that automation is already in place and that you're prepared for the upcoming changes.
In the end, the best security is often the security you never have to think about.
TAG-Hosted Websites
The A Group's IT team is already working on the implementation of an automated certificate renewal system for its web clients. We will reach out to each of our web clients in the next couple months with more information on how the new system will work, and what, if anything, needs to be done to begin utilizing the new system. Stay tuned for more information.
