Certificate Automation
100-day TLS certificates arrive March 15, 2027: a readiness checklist
The next public maximum is 100 days from 15 March 2027. Validation reuse also shrinks. This is a checklist, not a panic headline.
sslcertificates.io Editorial · Published 2026-09-21 · Fact-checked 2026-09-21 · Topic window 2026-08-20
On 15 March 2027 the public maximum for a newly issued subscriber certificate becomes 100 days. Validation reuse becomes 100 days the same day. You still have time. You do not have a spare year of informal process.
Readiness checklist:
- Inventory every hostname that terminates TLS, including customer-owned SaaS names and leftover staging CNAMEs.
- Mark which certificates the platform issued and which you only imported.
- Confirm each automated certificate has a deploy target or an honest “download only” owner.
- Confirm webhook certificate.renewed is not treated as “HTTPS is fine.”
- Measure how long DNS-01 actually takes in your zones. Propagation is not a constant.
- Rehearse a failed renewal: Action Required must page a person.
- Recalculate rate limits. More issuances per year is not free at a CA.
- Tell finance that commercial CA SKUs billed per year may not match 100-day reissue cadence.
What not to do: buy a new dashboard and leave SSH copy-paste as the install step. Issued ≠ installed ≠ served.
Related: /automated-renewals, /certificate-deployment, /certificate-inventory-monitoring.
Sources
Related
Automate the lifecycle this article describes
Inventory, renewals and verified deployment are product surfaces — not adjectives.