Reduced lifetime of SSL/TLS certificates from 15 March 2026

The global market for SSL/TLS certificates is changing, and Commfides is making the necessary adjustments to ensure that our offerings to our customers comply with the new industry standards.

As of March 15, 2026, the technical lifetime of a public SSL/TLS certificate will be reduced to a maximum of 200 days (with some differences between different CAs). The decision applies to all certificate authorities (CAs) and has been adopted by the CA/Browser Forum, the international industry body that establishes common security requirements for public PKI and the internet.

This is the first step in a planned and gradual transition to shorter certificate cycles than we have been used to. The lifetime will be further reduced in the coming years, with the aim of strengthening safety and reducing risk.

Commfides is working in parallel with these changes to ensure that the transition is as predictable and smooth as possible for our customers. In this article, we explain what the change entails, which dates apply, and what this means practically for you – both now and in the future.

Why is the lifetime of SSL/TLS certificates decreasing?

Shorter lifetime is a security measure to reduce risk in the digital infrastructure.

When the service life is shortened:

  • Reduces the risk of potential key compromise
  • Errors in validation processes are corrected faster
  • The amount of time a compromised or misissued certificate can be active is limited
  • Automated certificate management becomes easier and more robust

The background must also be seen in the light of a more complex and sharpened threat picture. As technology and vulnerabilities develop rapidly, security mechanisms must also be adapted accordingly.

The reduction in certificate lifetime is therefore part of a long-term strategy from the CA/Browser Forum to modernize and strengthen public PKI globally.

What happens now and in the future?

The reduction to 200 days in 2026 is the first step in a planned, gradual tightening of SSL/TLS certificate lifetimes. The change is a natural continuation of previous lifetime reductions from 3 years → 2 years → 1 year (398 days), and is an industry-wide requirement established through new Baseline Requirements from the CA/Browser Forum, aimed at reducing security risks and ensuring that enterprise IT environments remain more robust, up-to-date and resilient over time.

Below is a timeline of the predicted development of the lifespan of SSL/TLS certificates in the coming years.

What does this mean in practice for you as a customer?

The most important thing to be aware of is that there will now be a distinction between:

  1. The contract period you pay for
  2. Technical lifetime of the certificate

At Commfides, the agreement period will continue to be 1 year (365 days), as it is today.
The change only applies to how long each individual certificate can be technically valid.

From March 15, 2026, an SSL/TLS certificate can have a maximum technical lifetime of 200 days. This means that a certificate purchased with a 1-year agreement period must be reissued once during the period.

Coverage period

Re-issuance is a technical process where:

  1. New CSR is generated
  2. The certificate is reissued
  3. New validity period starts within the same agreement

This is not a new purchase, but part of an existing agreement.

What does Commfides do to make this easier?

We are fully aware that more frequent certificate cycles can be perceived as more administration. That’s why we’re working in parallel to improve and further develop the SSL portal to:

  • Simplify renewal processes
  • Provide a better overview of certificate status
  • Reduce manual steps
  • Introduce more automated workflows
  • Standardize and simplify domain control (DCV)

Several of these enhancements are being rolled out on an ongoing basis in the run-up to the first reduced-life renewals over the next six months.

The aim is to ensure that shorter certificate lifetimes do not become an increased burden for our customers, but a more structured, secure and future-oriented solution.

The future: Automation - with or without ACME

Certificate management is in the process of moving from being an annual task to becoming an ongoing and automated process. This is also a clear intention from the CA/Browser Forum, as the gradual reduction in certificate lifetime is precisely intended to drive a more automated process for SSL/TLS management.

An effective solution for full automation is ACME (Automated Certificate Management Environment), an open and widely supported standard for automatic issuance and renewal of SSL/TLS certificates. With ACME, key processes can be automated, from ordering and domain control to installation and renewal.

At the same time, we are aware that not all businesses are ready for full automation yet.

Therefore, Commfide’s SSL portal will continue to be a fully-fledged and secure alternative during the transition period up to 2029. Through improved functionality, better overview and more structured handling, both manual, partially automated and fully automated certificate management will be carried out efficiently and in a controlled manner.

At the same time, the SSL portal is being further developed to be a single point of administration for both traditional certificates and ACME-based solutions. This includes management of ACME accesses and URLs, as well as a comprehensive certificate overview, also for customers who use their own ACME clients.

Our strategy is therefore twofold:

  • For customers who want full automation → ACME and API-based solutions
  • For customers who are not yet ready for this → improved and more efficient portal-based management

Both approaches will be compliant with the new industry standards – brought together in one end-to-end solution at Commfides.

Do you have questions about SSL/TSL?

Have a chat with us

Commfides customer service

Phone number

+47 21 55 62 60

E-mail address

servicedesk@commfides.com

Scroll to Top