Transport SecurityMedium impact

TLS certificate lifetimes: 200 days now, 100 in 2027, 47 by 2029

Takes effect: In force since 15 Mar 2026 - next step 15 Mar 2027

In April 2025 the CA/Browser Forum passed ballot SC-081v3 - proposed by Apple, endorsed by Chrome, Mozilla and Sectigo - putting every publicly trusted TLS certificate on a fixed shrinking schedule. This is not a proposal to watch: the first phase has been in force since 15 March 2026.

FromMax validityDomain-validation reuse
Before 15 Mar 2026398 days398 days
15 Mar 2026 - in force200 days200 days
15 Mar 2027100 days100 days
15 Mar 202947 days10 days

Why email is on the clock

These are the same certificates behind your mail stack: STARTTLS on the MX, the HTTPS host serving your mta-sts policy (yours even on Google Workspace or Microsoft 365), BIMI logo hosting, and any custom tracking or unsubscribe domains. Mailbox-provider MX certificates (Google, Microsoft, Zoho, hosted gateways) are the provider's task - self-hosted mail servers carry the full schedule themselves.

Already happening

Every public CA now issues at most 200-day certificates, and the first post-cutover cohort hits its first renewal around 1 October 2026 - the industry's first mass short-cycle renewal wave. Let's Encrypt is running ahead: its opt-in profile has issued 45-day certificates since May 2026, stepping its default down to 45 days by February 2028. Manual renewal is on borrowed time; automation (ACME) plus TLS-RPT monitoring is the working posture.

Need help moving your sending to a properly authenticated domain?

← All industry updates

Chat with us!