Home / Solutions / Industry change
Industry change

Prepare Certificate Operations for 200-Day, 100-Day and 47-Day TLS

Shorter public TLS lifetimes turn occasional renewal work into a continuous operating process. SSLNexus helps teams automate the lifecycle before renewal volume becomes the outage risk.

The operational problem

Make the certificate workflow match the estate you actually run.

The CA/Browser Forum schedule reduced maximum publicly trusted TLS certificate validity to 200 days on 15 March 2026, moves to 100 days on 15 March 2027, and to 47 days on 15 March 2029. Manual renewal processes have less recovery time at every stage.

2026

200-day maximum validity is already in effect.

2027

100-day maximum validity is scheduled from 15 March 2027.

2029

47-day maximum validity is scheduled from 15 March 2029.

Workflow

From visibility to a repeatable operating process.

01Inventory the certificates that still depend on manual renewal
02Classify ownership, CA and deployment destination
03Automate issuance before shortening lifetimes create urgency
04Automate deployment and post-deployment verification
05Track exceptions that still require manual change control
06Use reports to measure automation coverage and renewal failures
Why SSLNexus

Customer-controlled certificate operations.

SSLNexus is installed into customer infrastructure and is designed to keep certificate operations, target access and private-key custody under customer control. The platform coordinates lifecycle work without requiring the estate to be rebuilt around a vendor-hosted key store.

  • Provider-neutral certificate lifecycle management.
  • Private keys remain inside customer-controlled infrastructure.
  • Delegated operational roles instead of one all-powerful administrator model.
  • Audit history, reports and verification stay attached to the certificate lifecycle.
Questions

Common questions

Are 47-day certificates already required?

Not yet. The current maximum is 200 days for certificates issued on or after 15 March 2026. The approved schedule moves to 100 days in 2027 and 47 days in 2029.

Why prepare now?

Automation takes time to validate across real applications, network boundaries and change processes. Preparing while certificate lifetimes are still longer gives teams room to remove manual exceptions safely.

Does SSLNexus depend on one CA for this transition?

No. The lifecycle is designed to remain usable across supported CA connections, including ACME-based workflows.

Related

Go deeper