Skip to content

Certificate Automation

100-day TLS certificates arrive March 15, 2027: a readiness checklist

The next public maximum is 100 days from 15 March 2027. Validation reuse also shrinks. This is a checklist, not a panic headline.

sslcertificates.io Editorial · Published 2026-09-21 · Fact-checked 2026-09-21 · Topic window 2026-08-20

On 15 March 2027 the public maximum for a newly issued subscriber certificate becomes 100 days. Validation reuse becomes 100 days the same day. You still have time. You do not have a spare year of informal process.

Readiness checklist:

  • Inventory every hostname that terminates TLS, including customer-owned SaaS names and leftover staging CNAMEs.
  • Mark which certificates the platform issued and which you only imported.
  • Confirm each automated certificate has a deploy target or an honest “download only” owner.
  • Confirm webhook certificate.renewed is not treated as “HTTPS is fine.”
  • Measure how long DNS-01 actually takes in your zones. Propagation is not a constant.
  • Rehearse a failed renewal: Action Required must page a person.
  • Recalculate rate limits. More issuances per year is not free at a CA.
  • Tell finance that commercial CA SKUs billed per year may not match 100-day reissue cadence.

What not to do: buy a new dashboard and leave SSH copy-paste as the install step. Issued ≠ installed ≠ served.

Related: /automated-renewals, /certificate-deployment, /certificate-inventory-monitoring.

Sources

Related

Automate the lifecycle this article describes

Inventory, renewals and verified deployment are product surfaces — not adjectives.

Start free Read the Product hub