Helient Blog

SSL Certificate Lifetime Changes: What Organizations Should Know and How to Prepare

Written by Mike Trantas | Sep 10, 2026, 7:01:39 PM

SSL/TLS certificates are fundamental to modern IT environments, protecting communications, establishing application and website identity, and securing connections between users, applications, systems, and services.

The way organizations manage these certificates is changing significantly and has a direct impact on your environment if you use them. The Certification Authority Browser Forum (CA/Browser Forum) has approved changes that progressively reduce the maximum lifetime of publicly trusted SSL/TLS certificates—from 200 days in 2026, to 100 days in 2027, and ultimately 47 days in 2029.

Traditionally, whether you have multiple or dozens of SSL certificates, it’s been a completely manual process and each time it needs to be renewed a maintenance window needs to be scheduled, the device or application is temporarily taken offline, and the time-consuming process is completed.


What Is Changing?
The maximum lifetime of publicly trusted SSL/TLS certificates is being reduced over the next 2 ½ years. The maximum certificate lifetime changes will occur as follows:

  • March 15, 2026: 200 days (completed)
  • March 15, 2027: 100 days
  • March 15, 2029: 47 days

Additionally, the maximum period for reusing domain and IP address validation information will also decrease, ultimately reaching 10 days in 2029.

To note, these requirements do not mean every certificate in an organization's environment must follow these public certificate lifetimes. Internal systems that do not require public trust may be able to use an internal PKI instead.


There Is No One-Size-Fits-All Solution
Enterprise environments are rarely homogeneous. Organizations may have Windows Servers, IIS servers, domain controllers, network appliances, and any given variety of production applications -all of which may manage certificates differently.

As a result, there is no single technology that will solve every certificate-management requirement.

An organization’s strategy may combine an internal 2-tier Microsoft Internal Microsoft Certification Authority with ACME-based certificate automation for pubic facing certificates and/or use a combination of internal and external PKI systems bundled with Microsoft Azure Key Vault. However, an organization is configured, the objective with ACME is to reduce the manual certificate management overhead with an automated process.

The objective should be to reduce unnecessary manual certificate management while maintaining security, reliability, compatibility, and cost control.


ACME: Automating Public Certificate Management

For public-facing certificates, the Automated Certificate Management Environment (ACME) protocol can provide an effective way to automate certificate issuance and renewal. ACME allows a compatible client or agent to communicate with a Certificate Authority, perform domain validation, request certificates, and renew them via an automated process before expiration.

The advantages of ACME include:

  • Reduced manual renewal activities
  • Fewer certificate-expiration errors
  • Improved security through more frequent renewal
  • Greater scalability
  • Consistent certificate-management processes

Azure Key Vault: An Option for Azure Customers
Organizations with an existing Microsoft Azure presence may be able to leverage Azure Key Vault as part of their certificate-management strategy. For organizations with an existing Azure presence, Azure Key Vault makes sense to use, as Azure portal operations are already a part of the organization’s infrastructure and migration to it is simple. For organizations without an Azure presence or limited Azure presence, using Azure Key Vault may add an additional expense to your monthly spend.


Use Internal PKI Where Appropriate

Organizations can also effectively reduce their reliance on public certificates by determining whether a device or application requires a public certificate. Many internal systems do not. Domain controllers and IIS web servers, for example, can integrate effectively with Microsoft Enterprise Certificate Authorities. The reliance on ACME and public-facing SSL certificates can be significantly reduced when implementing a design to use a combination of both internal and public certificates.

Please note that some legacy applications will still require manual intervention because they do not support ACME clients. The idea is to reduce the manual intervention required when the certificates need to be renewed.

How Helient Can Help
The goal is to develop a secure, reliable, supportable, and cost-effective certificate-management strategy that is tailored to the organization’s environment that reduces the overhead requirement of engineers required to manually replace certificates every 200 days.

Helient can assess your environment and help you build a certificate-management strategy aligned to your infrastructure, applications, security requirements, and operational needs. Whether that means a full ACME-based approach, a mix of internal PKI and ACME, or a broader shift to internal PKI, Helient works with your team to define the right path. For more information, email service@helient.com.