Important milestones are approaching for the standards changes that will make automation of certificate lifecycle management effectively mandatory
Since March 15, 2026, the maximum public TLS certificate lifetime has been 200 days, down from 398. If you bought or renewed one on that date, it will expire on October 1, 2026.
But it's coming sooner than that. DigiCert and other public CAs changed their maximum TLS certificate lifetime earlier than March 15, to leave time for solving any problems that might arise. We switched over on February 24, 2026 and the new maximum lifetime is 199 days. If you bought or renewed from us on the day before, it will expire on September 11, 2026.
These dates are not out on the horizon anymore. They are imminent, and many customers who renew manually may still be waiting for an annual renewal calendar alert that won’t appear until next spring—putting them at risk of an outage.
The more you look at dates, the more unexpected events you'll find. If you renewed the 199-day DigiCert certificate mentioned above on September 10—the day before it expires—the new one will expire on March 29, 2027, when the maximum lifetime will be 99 days.
If you automated certificate lifecycle management (CLM), you could be renewing every 30 days already without having to remember, and without having to worry about unexpected outages from expirations—at least for the certificates you know about.
The problem goes into overdrive on or shortly before March 15, 2029, when the maximum lifetime drops to 47 days. DigiCert will limit our public certificates to 46 days.
The goal of these standards changes that were announced in May 2025 is effectively to push organizations toward automated certificate renewal. The responsible renewal cadence after the 2029 change will be every 30-40 days. Are you sure you will do that manually without fail? Every time you forget or you can’t get around to it, you risk experiencing an outage.
The smart approach is to automate those renewals using the ACME (Automated Certificate Management Environment) standard. There are many good reasons to do this other than being forced to do it.
Automation can be completely free, but free comes at a cost. Implementing automation with free tools and protocols requires changes to and management of every server that uses certificates. Once you have more than a few of these, it makes sense to investigate a full Certificate Lifecycle Management (CLM) tool, like DigiCert Trust Lifecycle Manager.
The move to shorter lifetimes in March 2027 could already create problems for users who haven't automated. If you haven't started, DigiCert CertCentral is the easiest public CA to automate. If you wish, you can install our ACME client. It runs on Windows and Linux and is preconfigured for our own servers. Alternatively, you can use any of the many available free ACME clients like certbot or Posh ACME.