SSL certificate validity is now capped at 200 days. Since March 15, 2026, no publicly trusted SSL/TLS certificate can last longer than that, down from 398 days. The limit drops to 100 days in March 2027 and 47 days in March 2029. If you still handle SSL once a year by hand, your certificate will expire before your next renewal date unless it gets reissued and reinstalled in between.
Here’s what changed, what it means for your website, and how to make sure your padlock never lapses.
What Changed With SSL Certificate Validity in 2026?
The CA/Browser Forum writes the rules for SSL. Its members are the certificate authorities that issue certificates and the companies that make web browsers. In April 2025, the group approved Ballot SC-081. Apple proposed it, and Google Chrome, Mozilla, and Sectigo endorsed it.
The ballot cuts certificate lifetimes in three steps. It also shortens how long a certificate authority can reuse an earlier check that proves you control your domain.
| Certificates issued on or after | Maximum certificate lifetime | A domain check can be reused for |
|---|---|---|
| March 15, 2026 | 200 days | 200 days |
| March 15, 2027 | 100 days | 100 days |
| March 15, 2029 | 47 days | 10 days |
Certificates issued before March 15, 2026 keep their original expiration dates. That’s why many sites haven’t noticed the change yet. They’ll feel it at their first renewal after that date.
Business identity checks are tightening too. For OV and EV certificates, a certificate authority can now reuse your verified company details for 398 days, down from 825, under the Baseline Requirements.
Why Are SSL Certificates Getting Shorter?
A shorter lifetime means a stolen or wrongly issued certificate stays useful for less time. It also pushes everyone toward automation, because renewing every 47 days by hand isn’t practical for anyone.
Free certificates are moving even faster. Let’s Encrypt still issues 90-day certificates by default. It plans to cut that to 64 days on February 10, 2027, and to 45 days on February 16, 2028. Sites that opt in can already get 45-day certificates.
What Shorter SSL Validity Means for Your Website
- More installs every year. A 200-day certificate means at least two installs a year. At 100 days, it’s four. At 47 days, it’s about eight.
- A yearly plan still needs reissues. You can still pay for SSL by the year. But within that year, the certificate has to be reissued and installed again before each one expires.
- More domain checks. Your certificate authority has to re-confirm that you control your domain more often. By 2029, a domain check can only be reused for 10 days, so validation has to happen automatically.
- A missed renewal is public. When a certificate expires, Chrome shows a full-page warning that says “Your connection is not private.” Visitors have to get past it before they see any page, including your contact form and checkout.
- No reminder emails for free certificates. Let’s Encrypt stopped sending expiration notices in June 2025. If you use free certificates, you need your own monitoring.
How to Get Ahead of the 200-Day SSL Limit
1. List every certificate you have
Start with your main domain, then add subdomains like shop or portal, your staging site, and any server that sends or receives mail. To see an expiration date, open the site, click the icon next to the web address, and view the certificate details.
2. Automate renewals wherever you can
ACME is the open standard that hosts and certificate tools use to request, validate, and install certificates on their own. If your host supports it, turn it on. On our Managed WordPress hosting, SSL is included, and the certificate is installed, validated, and renewed for you.
3. Use auto-install SSL when you can’t automate
Some setups can’t run ACME, like older servers or sites on a host that doesn’t support it. For those, pick a certificate with automatic re-installation or a managed SSL service, so a person doesn’t have to remember every reissue.
4. Send expiry alerts to more than one person
Point alerts at a shared inbox, not one employee. People go on vacation, change jobs, and miss emails. A monitor that checks your certificate every day is cheap insurance.
5. Keep your company details current for OV and EV
OV and EV certificates verify your company’s legal details, and that check now repeats at least every 398 days. If your legal name, DBA, address, or phone has changed, update it everywhere first. Our guide on filing a DBA in Las Vegas shows how to keep your business name consistent.
6. Put March 2027 and March 2029 on the calendar
Each step makes manual renewals harder. If any certificate still depends on a person, fix that before March 15, 2027, when the limit drops to 100 days.
Which SSL Option Fits Your Business?
| Your situation | Good fit | What happens at each reissue |
|---|---|---|
| WordPress site on our Managed WordPress hosting | Included SSL | Installed, validated, and renewed for you |
| One site, and you’re comfortable installing certificates | DV SSL | You reinstall it before each expiry |
| Several sites, or no time to manage SSL | DV SSL with Auto-Install, or Managed DV SSL for sites on our hosting | Re-installation is automated |
| Online store, finance, or any site that should show verified company details | OV or EV SSL with Auto-Install | Re-installation is automated, and company details are re-verified at least every 398 days |
Prices come live from our store. DV SSL starts at $38.99/yr, and Managed WordPress hosting with SSL included starts at $8.99/mo. Want it done for you? Our SSL Setup Service installs the certificate, redirects your site to HTTPS, and fixes mixed content errors. Compare every option on our SSL certificates page.
Common SSL Mistakes to Avoid
- Treating a 1-year plan as one install a year. The plan can last a year. The certificate inside it can’t.
- Forgetting subdomains. Your main site renews, but the shop, portal, or booking subdomain expires and breaks.
- Tying reminders to one inbox. If that person leaves, nobody sees the warning.
- Skipping the check after an install. Load your key pages and confirm the padlock shows and nothing looks broken.
- Changing hosts or DNS without updating automation. A move can quietly break domain validation. Test a renewal after any change.
An expired certificate isn’t the only thing that puts a warning in front of your visitors. Malware can too. If that ever happens, here’s what to do when your WordPress site is hacked.
When to Get Professional Help
Automation takes some setup if you run more than one website, sell online, or use servers your host doesn’t manage. MCNM Marketing is a Las Vegas agency that sets up SSL, hosting, and website security for local businesses. If you’re also weighing a new host, start with our guide to the best WordPress hosting for Las Vegas small businesses.
Want a second set of eyes? We’ll check your certificates, your renewal setup, and the rest of your site in a free marketing audit.
Prefer to talk? Call (702) 608-4226.
Frequently Asked Questions
How long is an SSL certificate valid in 2026?
Publicly trusted SSL/TLS certificates issued on or after March 15, 2026 can be valid for up to 200 days. The limit drops to 100 days for certificates issued on or after March 15, 2027, and to 47 days on March 15, 2029. Certificates issued before March 15, 2026 keep their original dates.
Do I need to buy a new SSL certificate every 200 days?
Not usually. You can still pay for SSL by the year, and the certificate gets reissued during that term. Each new certificate still has to be validated and installed. Your host, an auto-install certificate, or a managed SSL service can do that for you.
What happens if my SSL certificate expires?
Browsers stop trusting your site. Chrome shows a full-page warning that your connection is not private, and visitors have to get past it to reach any page, including forms and checkout. Reissue and install a new certificate right away, then automate renewals so it doesn’t happen again.
Does the 200-day limit apply to free SSL certificates?
Yes. It covers every publicly trusted TLS certificate, free or paid. Let’s Encrypt certificates already last 90 days by default, and Let’s Encrypt plans to cut its default to 64 days in February 2027 and to 45 days in February 2028.
How do I check when my SSL certificate expires?
Open your site in a browser, click the icon next to the web address, and view the certificate details. The expiration date is listed there. Your hosting or SSL dashboard shows it too. Check every subdomain, not just your main site.
Sources
- CA/Browser Forum: Ballot SC-081v3, schedule of reducing validity and data reuse periods and the TLS Baseline Requirements
- Google Chrome Help: Fix connection errors
- IETF: RFC 8555, Automatic Certificate Management Environment (ACME)
- Let’s Encrypt: Decreasing certificate lifetimes to 45 days, certificate lifetimes, and upcoming features
Dates and limits are current as of October 3, 2026. Certificate rules can change, so check the CA/Browser Forum’s Baseline Requirements for the latest.


Leave a Reply