In April 2025 the CA/Browser Forum passed ballot SC-081v3 - proposed by Apple, endorsed by Chrome, Mozilla and Sectigo - putting every publicly trusted TLS certificate on a fixed shrinking schedule. This is not a proposal to watch: the first phase has been in force since 15 March 2026.
| From | Max validity | Domain-validation reuse |
|---|---|---|
| Before 15 Mar 2026 | 398 days | 398 days |
| 15 Mar 2026 - in force | 200 days | 200 days |
| 15 Mar 2027 | 100 days | 100 days |
| 15 Mar 2029 | 47 days | 10 days |
Why email is on the clock
These are the same certificates behind your mail stack: STARTTLS on the MX, the HTTPS host serving your mta-sts policy (yours even on Google Workspace or Microsoft 365), BIMI logo hosting, and any custom tracking or unsubscribe domains. Mailbox-provider MX certificates (Google, Microsoft, Zoho, hosted gateways) are the provider's task - self-hosted mail servers carry the full schedule themselves.
Already happening
Every public CA now issues at most 200-day certificates, and the first post-cutover cohort hits its first renewal around 1 October 2026 - the industry's first mass short-cycle renewal wave. Let's Encrypt is running ahead: its opt-in profile has issued 45-day certificates since May 2026, stepping its default down to 45 days by February 2028. Manual renewal is on borrowed time; automation (ACME) plus TLS-RPT monitoring is the working posture.