The KeyGuardRail Brief
Confirmed scheduleTLS certificates

Shorter certificate lifetimes. A little preparation goes a long way.

A shorter certificate lifetime means a more frequent renewal cycle. For a team with working automation and clear ownership, the next change may be a routine adjustment. For others, it is a useful reason to review how renewal actually happens.

The confirmed schedule

This schedule covers newly issued, publicly trusted TLS server certificates, such as those used for HTTPS. It does not retroactively shorten existing certificates or set the rules for a private, internal certificate authority.

Maximum validity for certificates issued on or after each date
Issuance dateMaximum validity
200 days
100 days
47 days

These are maximum validity periods, not recommended renewal intervals. Your issuer may use shorter lifetimes. Check its guidance and the actual certificate expiry date.

Source: CA/Browser Forum · TLS Baseline Requirements, §6.3.2 (2.3.0 · September 7, 2026).

Start with the renewal process you have

An automated renewal process still benefits from an accountable owner. A useful review asks whether the certificate was issued, deployed to the right endpoint, and checked afterward. If a provider handles all of this, document that arrangement and its escalation route; there is no need to duplicate a working system.

If certificates are currently renewed by hand, consider whether your issuer and hosting setup support automated renewal. Keep enough time to test issuance, deployment, and failure handling before relying on a new process.

A useful exercise

Make one renewal path easy to follow.

  1. Start with one important service

    Choose a website or endpoint your team depends on. Record the certificate issuer and current expiry date. Keep the certificate body and private key in their existing systems.

  2. Follow the renewal path

    Find out whether renewal is handled by your hosting provider, an ACME client, another automation tool, or a person. Identify who checks that the renewed certificate reaches the service.

  3. Name the owner and the fallback

    Record who receives a failure notification and who can help if that person is unavailable. Confirm the notification reaches a channel someone actually monitors.

  4. Leave a useful handoff

    Link the runbook, note the last verified renewal, and set a review date. If something is unknown, record a follow-up rather than marking the process complete.

You do not need to replace everything today. Start by making one renewal path clear enough for another person to follow. Then apply what you learn to the rest of your inventory.

Use the free inventory template