Certificate lifetimes are getting much shorter.

In 2025 the CA/Browser Forum voted to cut the maximum lifetime of a public TLS certificate in stages. It is the biggest operational change coming to anyone who runs HTTPS, and the dates are already set.

The schedule

A certificate can last 398 days today. By 2029 it will last 47. One you renew once a year now, you will renew roughly every six weeks.

Why it matters

More renewals mean more chances to miss one. Every renewal is a step that can fail: an expired payment, a DNS change, a CAA record that now blocks your CA, an automation job that silently stopped. A missed renewal takes your site, API or mail server offline behind a browser security warning — the kind customers screenshot and share. And the more often it happens, the more likely one slips past a busy team entirely.

How to stay ahead

Automate renewals wherever you can, and monitor every endpoint independently so one stale node in a load balancer cannot hide. CertMoni watches every public certificate you run around the clock and warns you well before one expires, is revoked or stops being trusted. It recognises certificates that renew themselves — Let's Encrypt, Google, ZeroSSL, Azure, AWS and Cloudflare — and only raises the alarm when a renewal is actually overdue.

The shift is gradual, but the direction is fixed, and teams that put monitoring in place now will barely notice each step down. Those that wait will find the margin for error shrinking every year. Learn more about the checks CertMoni runs, or see pricing.

Start a free trial