SSL Certificates Are Expiring Faster: Every Change Through 2029

If you set up HTTPS once and forgot about it, that era is over. Certificate lifetimes are being cut in stages, domain checks are getting stricter, and Let’s Encrypt is moving even faster than the industry deadline. Here’s what’s changing, when, and what to do about it.

Certificate lifetimes are shrinking

In April 2025 the CA/Browser Forum, the group that sets the rules for publicly trusted certificates, passed Ballot SC-081v3. It cuts the maximum lifetime of a TLS certificate in three steps:

Issued on or afterMaximum lifetime
Before March 15, 2026398 days
March 15, 2026 (already in effect)200 days
March 15, 2027100 days
March 15, 202947 days

The same ballot also limits how long a certificate authority can reuse your proof of domain ownership. By 2029 that drops to just 10 days, so your domain will be re-validated at almost every renewal. Renewing by hand, or validating by email, stops being practical. Automation becomes the only realistic option.

Let’s Encrypt is ahead of schedule

Let’s Encrypt announced its own timeline to move from 90-day to 45-day certificates:

  • May 13, 2026: the opt-in tlsserver profile started issuing 45-day certificates.
  • February 10, 2027: the default profile switches to 64-day certificates, with domain validation reused for only 10 days.
  • February 16, 2028: the default profile moves to 45-day certificates, with validation reused for only 7 hours.

If you want to go further, six-day certificates (160 hours) are already generally available through the shortlived profile.

Other changes you may have missed

  • OCSP is gone at Let’s Encrypt. OCSP URLs were removed from certificates on May 7, 2025 and the OCSP servers were shut down on August 6, 2025. Revocation is now published only through CRLs, so remove any OCSP Must-Staple settings.
  • New root certificates. On May 13, 2026, Let’s Encrypt began issuing from its new “Generation Y” roots. They’re cross-signed by the older roots, so most sites won’t notice, unless you’ve pinned a specific intermediate certificate.
  • No more client authentication certificates. Let’s Encrypt certificates no longer support client authentication. If you used them for mutual TLS (mTLS), you need another solution.

What to do now

  1. Automate renewals. Use an ACME client such as Certbot or acme.sh, or your host’s built-in tool, and stop renewing by hand.
  2. Use a client that supports ARI (ACME Renewal Information), so it knows exactly when to renew.
  3. Remove pinned intermediates and any OCSP Must-Staple configuration.
  4. Test a renewal on a staging server before the next deadline.
  5. Monitor the result, because automation fails too.

Automation isn’t enough on its own

Auto-renewal fails quietly more often than people think. A DNS change, a server move, or a web server that got the new certificate but was never reloaded, and nothing tells you. With certificates lasting weeks instead of a year, a silent failure turns into a browser warning fast.

That’s why I built CertAvert (full disclosure: it’s my project). It checks your certificate from the outside, the same way a visitor’s browser does. There’s nothing to install and no server access needed: you sign up, type your domain, and it emails you before the certificate expires. The dashboard also flags certificates browsers won’t trust, such as a hostname mismatch or a missing intermediate.

The free plan monitors up to 3 domains with no time limit and no card needed. Not ready to sign up? Run a one-off check with the free SSL checker and see when your certificate expires right now.

By 2029, certificates will need renewing roughly eight times a year instead of once. Automate the renewals, then monitor them, so you find out before your visitors do.