Guides

Shorter-lived SSL certificates: how many renewals you'll need by 2029

The CA/Browser Forum and Let's Encrypt timelines: the dates from 2026 to 2029 and how many renewals you'll need with 10 or 50 certificates.

UptimeMag editorial team · 6 October 2026 · 3 min read

Certificati SSL a vita più corta: quanti rinnovi dovrai fare da qui al 2029

Anyone managing more than a handful of domains already knows it: public TLS certificates are going to last less and less. The timeline is fixed and public, not a rumour doing the rounds. Between now and 2029, the number of renewals a sysadmin needs to plan for will change, and that number multiplies depending on how many certificates they manage.

The CA/Browser Forum timeline

In April 2025 the CA/Browser Forum approved Ballot SC-081v3, which reduces the maximum validity of SSL/TLS certificates from 398 days to 47 days by 15 March 2029. The schedule, as reported in the analysis of the ballot's text, is as follows:

Certificates issued Maximum validity Renewals/year per certificate
Before 15 March 2026 398 days ~1
From 15 March 2026 to 14 March 2027 200 days ~1.8
From 15 March 2027 to 14 March 2029 100 days ~3.7
From 15 March 2029 47 days ~7.8

These thresholds are binding: certificates issued before 15 March 2026 must not exceed 398 days; those issued from 15 March 2026 to 15 March 2027 must not exceed 200 days; from 15 March 2027 to 15 March 2029 the cap is 100 days; from 15 March 2029 the cap drops to 47 days. Alongside validity, domain control validation (DCV) reuse is also being reduced — this defines how long a CA can reissue a certificate without requiring a fresh domain verification — dropping to as little as 10 days by 2029: it's not enough to automate issuance, validation needs to be automated too.

How many renewals with 10 certificates

The calculation is 365 days divided by the maximum duration, multiplied by the number of certificates:

Period Validity Renewals/year with 10 certificates
Today 398 days ~9
From 15/3/2026 200 days ~18
From 15/3/2027 100 days ~37
From 15/3/2029 47 days ~78

Anyone who currently renews a batch of 10 certificates once a year will, by 2029, be doing so every 4-5 working days on average across the year.

How many renewals with 50 certificates

For those managing a larger certificate estate, such as a hosting reseller or agency, the scale changes considerably:

Period Validity Renewals/year with 50 certificates
Today 398 days ~46
From 15/3/2026 200 days ~91
From 15/3/2027 100 days ~183
From 15/3/2029 47 days ~389

From roughly one renewal a week to more than one a day, including weekends and holidays.

Let's Encrypt's parallel path

Let's Encrypt isn't stopping at the minimum required by the CA/Browser Forum: it's aiming for 45 days, slightly below the 47 days mandated by the ballot, and it's getting there ahead of the 2029 deadline. According to the official documentation, industry rules will cap certificate validity at a maximum of 47 days from 15 March 2029, and Let's Encrypt will reduce the maximum validity of its own certificates to 45 days by February 2028. The roadmap published by the certificate authority sets out three milestones:

Date What changes
13 May 2026 The optional tlsserver ACME profile starts issuing 45-day certificates for those who voluntarily opt into testing
10 February 2027 The classic profile, the default one, moves to 64-day certificates with 10-day authorisation reuse, affecting anyone who hasn't opted into the tlsserver or short-lived profiles
16 February 2028 The classic profile moves to 45-day certificates with 7-hour authorisation reuse

Applying the same calculation (365 / duration × number of certificates), for those using Let's Encrypt's classic profile, annual renewals go from around 41 (10 certificates, currently at 90 days) to around 57 after February 2027 (64 days) and around 81 after February 2028 (45 days). With 50 certificates, that's a rise from around 203 to 285, up to around 406 renewals a year.

What this means in practice

At these frequencies, manual renewal is no longer a manageable option beyond a handful of domains. Let's Encrypt itself says as much in its own documentation, recommending ACME clients with automatic renewal and support for ARI (ACME Renewal Information) so you know in advance when to renew, rather than relying on a fixed interval via cron.

Sources: official Let's Encrypt documentation at letsencrypt.org/docs/cert-lifetimes/, announcement at letsencrypt.org/2025/12/02/from-90-to-45, and the text of the CA/Browser Forum's Ballot SC-081v3.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).