How Long Are SSL Certificates Valid? The 90-Day and 47-Day Rules

VigilDog Team · August 28, 2026 · 6 min read

The answer to "how long are SSL certificates valid" used to be simple: a year or two, set a reminder, move on. That era is ending. Certificate lifetimes are being deliberately cut, and by 2029 the maximum will be 47 days. If your renewal process still assumes an annual cadence, it's about to break. Here's exactly where the rules stand and where they're headed.

The current maximum: 398 days

Since September 2020, publicly trusted TLS certificates (what most people call SSL certificates) have had a hard maximum validity of 398 days, roughly 13 months. No public Certificate Authority will issue one for longer, and browsers reject certificates that exceed it. So if you bought a cert today, the longest it can be valid is about 13 months, not the two or three years some vendors used to sell.

That 398-day ceiling is set by the CA/Browser Forum, the body where browser makers and CAs agree on the rules trusted certificates must follow. It's not your CA being stingy; it's the baseline everyone enforces.

Root CAin the trust storeIntermediatemust be installedYour certificateleaf, for your domain
The TLS certificate chain of trust

The 90-day norm most sites already live with

In practice, a huge share of the web already renews far more often than every 13 months. Let's Encrypt, which secures a large fraction of all HTTPS sites, issues 90-day certificates by design and expects you to automate renewal. The 90-day cycle became the de facto standard for a good reason: shorter lifetimes limit the damage of a stolen key and force automation, which is more reliable than a human remembering.

If you're on Let's Encrypt or a similar ACME-based issuer, you're already living in the short-lifetime world. The renewal is meant to run unattended, typically every 60 days, giving a 30-day safety buffer before the 90-day expiry.

The 47-day rule: the industry timeline through 2029

In 2025 the CA/Browser Forum approved a phased reduction that takes certificate lifetimes all the way down to 47 days. It doesn't happen overnight, it steps down over several years so organizations can automate in time. The approximate schedule:

  • Now through early 2026-398 days maximum, unchanged.
  • From March 2026, maximum drops to roughly 200 days.
  • From March 2027, maximum drops to roughly 100 days.
  • From March 2029, maximum reaches 47 days, the final target.

Why they keep shrinking

Two reasons, both about safety. First, a shorter lifetime shrinks the window in which a compromised or mis-issued certificate stays valid, revocation has always been unreliable, so expiry does the job instead. Second, and more importantly, short lifetimes force automation. A certificate you have to renew every 47 days is not something anyone will do by hand; it pushes the whole ecosystem toward hands-off ACME renewal, which is simply more dependable than a calendar reminder.

The catch is the failure mode. When certs lasted a year, forgetting one was an annual risk. At 47 days you get roughly eight renewals a year per certificate, eight chances for an automation job to silently fail, a DNS validation to break, or a load balancer to keep serving the old cert. More renewals means more opportunities for something to slip through, and an expired SSL certificate throws a full-page browser warning that stops visitors cold.

How to actually keep up

Automate issuance wherever you can, ACME clients, managed certs from your host or CDN, cloud load balancers that rotate certs for you. Automation removes the human-memory failure, but it does not remove the risk, it changes it. Automated renewals fail quietly all the time: a hook doesn't fire, a validation record is stale, the new cert is issued but never deployed to the edge. The only way to know is to check the live certificate the world actually sees, not the job that was supposed to update it.

That's the case for independent expiry monitoring: watch the certificate served on the wire and alert well before it expires, so you catch the automation that silently didn't run. You can spot-check any host right now with our free SSL checker, and for continuous coverage across every domain you manage, VigilDog monitoring tracks certificate expiry and warns you with days to spare. As lifetimes fall toward 47 days, that early-warning net stops being optional.

Questions

Frequently asked

How long are SSL certificates valid right now?

The maximum for a publicly trusted TLS certificate is 398 days (about 13 months). Many sites already use 90-day certificates via Let's Encrypt and similar issuers, which is the de facto norm.

Is the 47-day certificate rule in effect yet?

Not yet. It's the final step of a phased reduction approved in 2025: maximums drop to about 200 days in 2026, about 100 days in 2027, and 47 days from 2029. Today's ceiling is still 398 days.

If renewals are automated, do I still need monitoring?

Yes. Automation removes the human-memory failure but not the risk, renewal jobs fail silently, and a new cert can be issued but never deployed. Monitoring the live certificate is how you catch the automation that didn't run.

Never get caught by a silent renewal failure

As certificate lifetimes fall toward 47 days, VigilDog watches the live cert on every domain and warns you with days to spare, before visitors see a warning.

Your first domain is free forever · no card