Public TLS validity schedule
CA/Browser Forum Baseline Requirements cap public TLS subscriber certificates at 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. Existing certificates keep their original expiry.
What changed
Ballot SC081v3 introduced a published schedule into the TLS Baseline Requirements. As of 15 March 2026 the maximum validity of a newly issued publicly trusted subscriber certificate is 200 days. From 15 March 2027 it is 100 days. From 15 March 2029 it is 47 days. Certificates issued before a date keep their original notAfter; the cap applies to new issuance.
Validation data reuse
Section 4.2.1 shrinks how long a CA may reuse domain and IP address validation data: 200 days from 15 March 2026, 100 days from 15 March 2027, and 10 days from 15 March 2029. Short-lived subscriber certificates are a separate definition (at most 7 days from 15 March 2026).
What to do
Treat calendar reminders as insufficient. Automate issuance, deployment verification and failure alerts. Do not tell auditors you are already on 47-day certificates unless you chose that lifetime. The 47-day maximum is a 15 March 2029 date.