TLS Certificates Valid for Only 47 Days: Automated Certificate Management Becomes Essential

Art
Managed Security & SOC Services
Published
15.06.2026

 

Starting in 2029, publicly trusted TLS certificates will be limited to a maximum validity period of just 47 days—a decision by the CA/Browser Forum that will make manual certificate management practically impossible for most organizations. A company managing 500 TLS certificates will need to handle approximately 4,000 renewal events per year instead of just one annual renewal cycle. Organizations that fail to implement an automation strategy today risk certificate outages, operational disruptions, and compliance violations.

 

 

What Are Digital Certificates—and Why Are They Business-Critical?

Digital certificates are the foundation of trust in modern IT infrastructures. They authenticate servers and applications, encrypt communication channels, and ensure the integrity of digital processes

Typical Use Cases:

  • TLS/SSL Connections for Websites and Applications
  • Software and Document Signing
  • S/MIME-Secured Email Communications
  • VPN Connections
  • IoT Devices and Connected Manufacturing Systems

 

When a certificate expires, applications may become inaccessible or systems may refuse to communicate with one another. Particularly concerning is the fact that many organizations lack both comprehensive certificate inventories and automated alerting mechanisms.

 

TLS Certificates: The 47-Day Rule Is Coming

The CA/Browser Forum has decided to gradually reduce the maximum validity period of publicly trusted TLS certificates.

 

What Has the CA/Browser Forum Decided—and When Will It Take Effect?

The CA/Browser Forum has formally approved a four-stage reduction in the maximum validity period of publicly trusted TLS certificates:

  • Until March 14, 2026: maximum validity of 398 days — the current status quo
  • From March 15, 2026: maximum validity of 200 days — the first reduction puts manual processes under pressure
  • From March 15, 2027: maximum validity of 100 days — manual certificate management becomes critical
  • From March 15, 2029: maximum validity of 47 daysfull automation becomes mandatory

At the same time, the reusability period for domain validations will be reduced to just 10 days. This means that not only will certificate renewal frequency increase, but the entire validation infrastructure must also be fundamentally rethought.

For IT decision-makers, the first major milestone is March 15, 2026—just a few months away. Process adjustments should begin now, not in 2028.

 

What Does the 47-Day Rule Mean in Practice for IT Operations?

A company managing 500 TLS certificates currently renews them once per year—resulting in 500 renewal events annually. Starting in 2029, this workload will increase to approximately 4,000 renewal events per year. Each renewal process involves validation, deployment, testing, and documentation.

Manual processes do not just reach their capacity limits—they are also highly prone to error. A single missed certificate renewal can result in:

  • Disrupted HTTPS Connections and Security Warnings Displayed to Users
  • Disrupted API Communication Between Systems
  • Production Environments in OT/IoT Infrastructures Being Brought to a Standstill
  • Compliance Violations Related to NIS2, DORA, or eIDAS 2.0 Requirements

 

What Is Certificate Lifecycle Management (CLM)?

Certificate Lifecycle Management (CLM) refers to the structured, automated management of digital certificates throughout their entire lifecycle—from issuance to revocation.

A professional CLM solution includes:

  • Inventory Management of All Certificates (Including Shadow IT and Forgotten Certificates)
  • Automated Certificate Issuance and Deployment
  • Proactive Certificate Renewal Before Expiration
  • Revocation of Compromised Certificates
  • Continuous Monitoring and Alerting
  • Audit-Proof Documentation for Compliance and Regulatory Requirements

A professional CLM solution reduces operational risk, provides full visibility across the entire certificate landscape, and is the key prerequisite for meeting the 47-day certificate validity requirement without increasing operational overhead.

Which Compliance Requirements Are Affected?

In addition to the technical changes, regulatory requirements for certificate management are also becoming more stringent:

  • NIS2 – Requirements for Cryptography, Encryption, and Incident Response
  • DORA – Digital Operational Resilience in the Financial Sector, Including Documentation and Evidence Requirements for IT Security Measures
  • eIDAS 2.0 – Requirements for Trust Services and Electronic Signatures

An integrated CLM solution provides the documentation and audit trail required to support compliance with all three regulatory frameworks—significantly reducing overall compliance effort in the process.

 

Conclusion – What Should IT Decision-Makers Do Now?

The reduction of certificate validity periods has been decided and is not open for negotiation. The first phase will already take effect in March 2026.

Three Immediate Actions for IT Decision-Makers:

  1. Create a Certificate Inventory – Establish a complete overview of all TLS certificates, including expiration dates, ownership, and the systems they support.
  2. Evaluate Automation Options – Assess CLM tools, ACME protocol integration, and connectivity with certificate authorities (CAs).
  3. Develop a CLM Strategy – Treat certificate lifecycle management as a long-term architectural decision, not merely a short-term tooling project.

Organizations that act early can reduce risk, strengthen the resilience of their IT infrastructure, and establish a solid foundation for meeting future compliance requirements.

 

 

Manage Now unterstützt IT-Entscheider beim Aufbau eines automatisierten Zertifikatsmanagements – von der Analyse der bestehenden Zertifikatslandschaft bis zur Einführung einer nachhaltigen CLM-Strategie.
Sprechen Sie mit unseren Security-Experten →