Home / Blogs

Time to Act as Apple Sets Wheels in Motion for Shorter Certificate Life Cycles

You may have read our previous blog about the pending reduction of digital certificate life cycles to just 90 days. This past weekend, the issue gained momentum at the Certification Authority Browser Forum when more detail was discussed following the proposed ballot to set a timeline for shorter lifetime certificates by Apple®.

This creates real urgency for organizations of all sizes to seriously consider and implement automation into their certificate life cycle management. “But it’s just a proposal,” I hear! Yes, currently, it’s just a proposal subject to further discussion and then a ballot. But even if the ballot fails to pass it, it’s highly likely that Apple or Google® will make it policy anyway.

Let’s look at the timeline:

TimeframeLife cycle for certificatesDomain control validation re-use period
After September 2025200-day certificatesDCV re-use 200 days
After September 2026100-day certificatesDCV re-use 100 days
After April 202745-day certificatesDCV re-use 45 days
After September 202745-day certificatesDCV re-use 10 days

This may seem complex at first, but the life cycles follow a simple logic of ideal certificate term, plus an early renewal window:

  • 200 days = 180 days (six months) + 20 days early renewal
  • 100 days = 90 days (three months) + 10 days early renewal
  • 45 days = 42 days (six weeks) + three days early renewal

The good news is that previous predictions that we’d see 90-day certificates come into effect in 2025 is not realized in this proposal—it suggests 180-day certificates next year, with 90-day certificates not coming into effect until 2026. It’s good news insomuch as there’s slightly more time to get your digital ducks in a row. But only slightly more time.

The gradual decrease in certificate life cycles undoubtedly causes a headache for busy IT security teams—and a headache that will only get worse without certificate automation. Organizations with manual tracking and monitoring methods simply will not be able to cope with hundreds (or even thousands) of certificates expiring at different times. Missed certificate renewals = unencrypted sites = security risk.

Automate, automate, automate!

By September 2027, your current renewal workload will have increased eight-fold—organizations can’t really afford to adopt a wait-and-see approach. To automate certificate renewals, you first need to see if your current web servers are Automated Certificate Management Environment (ACME) compatible. Our secure sockets layer (SSL) automation checklist can help you assess whether your current SSL set up is compatible for automation. If it isn’t, I would expect a large-scale project like making all your infrastructure ACME-compatible to take about 12 months, with at least two tests in that period to ensure the new renewal process works smoothly—so it really is time to act!

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Mark Flegg, Global Director at CSC

Filed Under

Comments

Your timeline is wrong Larry Seltzer  –  Apr 15, 2025 5:17 PM

The correct timeline:
Timeframe Life cycle for certificates Domain control validation re-use period
Current 398-day certificates DCV re-use 398 days
As of March 15 2026 200-day certificates DCV re-use 200 days
As of March 15 2027 100-day certificates DCV re-use 100 days
As of March 15 2029 47-day certificates DCV re-use 10 days
Plus, as of March 15, 2026 reuse of non-SAN identity data verificaten in an OV or EV certificate goes from 825 to 398 days.

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Domain Names

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Cybersecurity

Sponsored byVerisign

Brand Protection

Sponsored byCSC

Threat Intelligence

Sponsored byWhoisXML API