14
TLS certificate lifetimes: 200 days now, 100 in 2027, 47 by 2029
CA/B Forum ballot SC-081v3 is phasing public TLS certificate validity down from 398 days to 47 by March 2029 - the 200-day cap took effect 15 March 2026. Email surfaces are on the clock: MX/STARTTLS, the MTA-STS policy host, BIMI logo hosting. The first mass renewal wave of 200-day certificates lands around 1 October 2026.
EffectiveIn force since 15 Mar 2026 - next step 15 Mar 2027