Why Short-Lived Certificates (90-Day, Soon 47-Day) Are Becoming the Norm
Certificate validity periods have been shrinking steadily and deliberately for over a decade, from a time when an eight or ten-year certificate was genuinely available, down to today's 398-day maximum for publicly trusted certificates, with an industry-agreed roadmap heading toward a maximum as short as 47 days by the end of the decade. This isn't arbitrary tightening — it reflects a specific, well-reasoned security tradeoff that the industry has been navigating deliberately.
Why Longer Certificates Were Ever the Norm
In the earlier, more manual era of certificate management, a longer validity period was primarily a customer convenience — fewer manual renewal events meant less administrative overhead and lower risk of an accidental lapse from a forgotten renewal, a real, practical concern before automated issuance and renewal tooling existed. Certificate authorities were happy to sell longer terms partly because it matched customer preference and partly because longer terms meant more revenue collected upfront per transaction.
The Security Case for Shorter Lifespans
A certificate's validity period defines the maximum window during which a compromised private key, a mis-issued certificate, or an outdated piece of identity information embedded in the certificate remains a live, exploitable problem if it isn't separately, actively revoked. Certificate revocation, in practice, has real limitations — not every client checks revocation status reliably, and revocation checking mechanisms (discussed in the piece on OCSP stapling elsewhere on this blog) have their own gaps and inconsistencies across different browsers and clients. A shorter validity period functions as a reliable backstop independent of revocation infrastructure working perfectly: even in the worst case where a compromise is never actively detected or revoked, the certificate naturally expires and stops being trusted within a bounded, predictable window.
The Timeline of Industry-Wide Reductions
The CA/Browser Forum, the industry body that sets baseline requirements for publicly trusted certificate authorities, has progressively tightened maximum validity: from a previous era with no meaningful cap, down to 60 months, then 39 months around 2015, then 825 days (roughly 27 months) in 2018, and 398 days (approximately 13 months) since 2020 — with major browser vendors, particularly Apple through Safari, historically pushing these reductions forward even ahead of full CA/Browser Forum consensus, using the leverage of simply refusing to trust certificates exceeding their preferred maximum regardless of formal industry agreement.
The Planned Move to 47 Days
A more recent industry ballot has established a phased roadmap reducing maximum certificate validity considerably further, moving in staged steps down toward a 47-day maximum by around 2029. This dramatically shorter window is explicitly designed around the assumption that certificate issuance and renewal will be, by that point, essentially universally automated — a 47-day certificate is simply impractical to manage through any kind of manual renewal process, which is precisely the point: the industry is deliberately using validity period reduction as a forcing function to push the entire ecosystem toward full automation.
Why Automation Makes This Transition Viable
The entire trajectory toward shorter lifespans is only tenable because of the parallel maturation of automated certificate management, primarily through the ACME protocol popularized by Let's Encrypt, discussed in depth elsewhere on this blog. A manually managed certificate renewal process that was already a minor annual chore becomes an untenable operational burden at a 47-day renewal cadence, but a properly automated ACME-based setup handles renewal identically regardless of whether it happens every 13 months or every 47 days — the automation doesn't know or care about the specific interval, which is exactly why the industry felt confident pushing toward such aggressive reduction only once automated tooling had become genuinely mainstream and reliable.
What This Means for Anyone Still Managing Certificates Manually
For any organization still relying on manual certificate purchase, installation, and renewal — increasingly rare, but not extinct, particularly in some enterprise and legacy environments — the shrinking validity window represents a genuine, forcing operational pressure to adopt automated issuance and renewal tooling sooner rather than later, since manual processes that were merely inconvenient at a 13-month cadence become genuinely impractical and risky at a considerably shorter one. This is, by design, precisely the outcome the industry roadmap is engineered to produce.
How Shorter Lifespans Interact With the Renewal-Failure Risk Discussed Elsewhere
It's worth connecting this trend to a related risk discussed in the piece on silent certificate renewal failures elsewhere on this blog: as the renewal cadence accelerates from roughly quarterly toward closer to monthly, any gap in automated monitoring for renewal failures becomes proportionally more dangerous, since there's simply less buffer time between a failed renewal attempt and the certificate's actual expiration. Organizations planning for this trajectory should treat robust, independent renewal-failure alerting not as an optional nicety but as a genuinely necessary companion investment alongside adopting shorter-lived certificates in the first place.
The Takeaway
Shrinking certificate validity periods reflect a deliberate, long-planned industry strategy to reduce the exposure window of a compromised or mis-issued certificate, made viable specifically by the parallel rise of automated certificate management tooling. Organizations that have already adopted ACME-based automation will experience the continued shrinkage as essentially invisible; those still managing certificates manually face a clear, unambiguous signal that automation is no longer optional for long-term sustainability.
Tags: certificate automation, certificate lifespan, short-lived certificates