📅 September 28, 2026 🔐 SSL Certificate ⏱ 8 min read

SSL Certificate Validity Reduced to 47 Days
— What It Means & How to Prepare

SSL Certificate validity reduced to 47 days — padlock security illustration

Background: Why CA/Browser Forum Shortened SSL Lifetimes

In 2025, the CA/Browser Forum — the governing body that sets global SSL/TLS standards, comprising browser vendors (Google, Apple, Mozilla, Microsoft) and major Certificate Authorities — voted to significantly reduce the Maximum Validity of SSL certificates.

The current maximum SSL certificate lifetime is 398 days (approximately 13 months). However, security experts argue this is too long: certificate data such as domain ownership and public keys can become stale or compromised without detection.

💡 Why specifically 47 days? 47 days is calculated to allow Auto-Renewal systems multiple retry attempts before expiry. If a certificate renews every 30 days, there's a 17-day buffer for handling temporary system failures.

SSL Validity Reduction Timeline: 2026–2029

The CA/Browser Forum has planned a phased reduction of Max Validity to give all parties time to adapt:

Effective Date Max Validity Max DCV Reuse Action Required
March 15, 2026 200 days 200 days New SSL issued after this date: 200-day max
March 15, 2027 100 days 100 days Renewals needed 3–4 times per year
March 15, 2029 47 days 10 days Auto-Renewal effectively required (~8×/year)
⚠️ Important Note This timeline is based on the CA/Browser Forum's 2025 ballot. Specific dates may be adjusted slightly. Monitor announcements from your certificate authority directly.

Impact on Website Owners

The shortened SSL validity period has several significant implications for website operators:

1. Far More Frequent Renewals

Instead of renewing once per year, by 2029 you'll need to renew approximately 7–8 times per year. Manual renewals become impractical at this frequency.

2. Manual Renewal Workflows Must Change

Websites that still renew SSL manually — downloading a CSR file and emailing it to a CA — will face an unsustainable burden. Automated systems are no longer optional.

3. DCV Reuse Drops to Just 10 Days

From 2029 onward, CAs must re-validate domain control every 10 days, fundamentally changing how SSL issuance works at scale.

4. Security Benefits

Auto-Renewal Is the Primary Solution

When SSL certificates need renewal 8 times per year, manual processes simply won't scale. Auto-Renewal is the essential capability every website owner needs.

What Is the ACME Protocol?

ACME (Automatic Certificate Management Environment) is a standard protocol developed by Let's Encrypt that enables systems to:

As the CA/Browser Forum mandates 47-day validity, all CAs will be required to support ACME — for both free (Let's Encrypt) and paid (RapidSSL, GeoTrust) certificates.

✅ ACME Advantages ACME systems operate around the clock including weekends and holidays. They renew certificates 30 days before expiry and automatically retry if a renewal attempt fails — all without human intervention.

DirectAdmin AutoSSL with Let's Encrypt

For websites hosted on DirectAdmin — the control panel used exclusively at AsiaGB — the built-in AutoSSL feature provides Let's Encrypt integration at no cost:

How to Enable AutoSSL on DirectAdmin

  1. Log in to your DirectAdmin Control Panel
  2. Navigate to SSL Certificates
  3. Select Let's Encrypt
  4. Click Save to activate AutoSSL

DirectAdmin will then automatically renew your SSL every 60 days (30 days before expiry), covering all domains and subdomains in your hosting account.

💡 Let's Encrypt on DirectAdmin is completely free Let's Encrypt provides DV SSL at no charge. It's ideal for general websites, blogs, and small-to-medium e-commerce stores that need HTTPS without requiring OV/EV organization validation.
SSL Type Certificate Lifetime Auto-Renewal Best For
Let's Encrypt (AutoSSL) 90 days → 47 days (2029) ✅ Automatic General websites, blogs
RapidSSL DV (฿1,000/yr) 398 days → 47 days (2029) ⚙️ ACME setup required SME business websites
GeoTrust OV (฿4,000/yr) 398 days → 47 days (2029) ⚙️ ACME setup required Organizations needing OV
RapidSSL Wildcard (฿5,000/yr) 398 days → 47 days (2029) ⚙️ ACME setup required Multiple subdomains

Paid SSL certificates such as RapidSSL, GeoTrust, and Sectigo retain key advantages even with shorter validity periods:

When the 47-day rule takes effect in 2029, all CAs in the CA/Browser Forum will be required to support ACME API, making automated renewal for paid SSL a universal standard — eliminating the need for manual CSR downloads and email submissions.

Checklist: Preparing for 47-Day SSL

Follow this checklist to prepare systematically for the transition:

Do Now

Do Before March 2026

Do Before March 2029

Frequently Asked Questions

❓ When will SSL certificates be limited to 47 days?
According to the CA/Browser Forum timeline: March 2026 reduces to 200 days, March 2027 reduces to 100 days, and March 2029 reaches the final maximum of 47 days.
❓ Do I need to act immediately if I already have an SSL certificate?
SSL certificates issued before each deadline remain valid for their original term. However, you should establish Auto-Renewal systems (DirectAdmin AutoSSL or ACME Protocol) before the rules take effect.
❓ What are the security benefits of shorter SSL lifetimes?
Key benefits include: if a private key is compromised, attackers can exploit it for only 47 days; certificate data is verified more frequently; and Certificate Transparency log coverage improves across the web ecosystem.
❓ Does DirectAdmin offer free Auto-Renewal SSL?
Yes — DirectAdmin supports AutoSSL via Let's Encrypt at no charge. Certificates auto-renew approximately every 60 days before expiry, covering all domains and subdomains in the hosting account.
❓ How will paid SSL certificates handle 47-day renewals?
When the 47-day rule takes effect, all CAs must support ACME Protocol, enabling automatic renewal for paid SSL. Providers like AsiaGB will support this standard process.
❓ Are Wildcard and Multi-Domain SSL certificates affected the same way?
Yes — the Max Validity rule applies uniformly to all SSL types: DV, OV, EV, Wildcard, and Multi-Domain certificates must all comply with the 47-day maximum.

🔐 SSL Certificates Ready for New Standards

AsiaGB offers a full range of SSL types — from RapidSSL DV at ฿1,000/year to Wildcard at ฿5,000/year
with DirectAdmin AutoSSL for free Let's Encrypt included

View All SSL Certificates →

🔖 Summary: SSL at 47 Days — No Fear, Just Preparation

  • The CA/Browser Forum is reducing SSL Max Validity to 47 days by 2029, in phases: 200 → 100 → 47
  • The goal is stronger security: limiting the damage window from key compromise and certificate staleness
  • Solution: Auto-Renewal — DirectAdmin AutoSSL (Let's Encrypt) for hosting, ACME Protocol for paid SSL
  • Existing SSL certificates remain valid for their original term, but Auto-Renewal should be set up before 2026
  • AsiaGB Hosting includes AutoSSL on DirectAdmin — ready to use with no additional configuration required