IT Operations
SSL Certificate Validity 2026: Stop Surprise Outages
Affix Center · · 7 min read

It usually starts with a phone call. A customer says your website shows a red "Your connection is not private" warning. Your payment page, vendor portal or email gateway has stopped working, and nobody knows why until someone checks the date on the SSL certificate. It expired last night, and the person who renewed it last year has moved on.
This kind of outage was always embarrassing. From 2026 it becomes far more likely, because the maximum life of a public SSL/TLS certificate has started shrinking, and it will keep shrinking every year until 2029. If your team still renews certificates by hand from a calendar reminder, the number of chances to miss one is about to multiply.
The good news: this is a solvable operations problem. Below we explain what changed, where Indian businesses and government departments usually get caught, and a step-by-step plan to fix it for good.
What Changed: The New SSL Certificate Validity Timeline
In April 2025 the CA/Browser Forum, the industry body of certificate authorities and browser makers, approved Ballot SC-081v3. It sets a schedule that steadily cuts how long a publicly trusted TLS certificate can be valid:
- From 15 March 2026: maximum validity of 200 days.
- From 15 March 2027: maximum validity of 100 days.
- From 15 March 2029: maximum validity of 47 days.
The same ballot also shortens how long a certificate authority can reuse your earlier domain validation. By 2029 that reuse window falls to just 10 days, which means domain control has to be proved again almost every time you renew.
In simple terms: the old habit of buying a one-year certificate and forgetting about it is already over. In 2026 you renew roughly twice a year. By 2029 you would renew around eight times a year for every single certificate you own.
Why Manual Renewal Is Now a Real Risk
Most organisations do not have one certificate. They have many, and they are spread across places that different people look after.
Certificates hide in more places than you think
A typical mid-size company or department may have certificates on the main website, a customer or citizen portal, APIs used by mobile apps, the mail server, VPN and firewall login pages, load balancers, internal dashboards and third-party SaaS tools mapped to its own domain. Each one can expire on a different date.
Knowledge sits with one person
Often only one developer, vendor or system administrator knows how a certificate was installed. When that person is on leave or leaves the company, the renewal slips.
More renewals means more human error
Each manual renewal involves generating a request, validating the domain, installing the new certificate and the right chain, and restarting services. Doing that a few times a year per certificate is a lot of small steps, and one wrong step can break a site just as badly as an expired certificate.
The cost is bigger than a warning page
When a certificate expires, browsers block visitors, payment gateways and partner APIs may refuse to connect, and mobile apps can fail silently. For a public-facing portal, that means lost enquiries, failed transactions and complaints, all from a task that should have taken minutes.
The Fix: A 6-Step Plan to Automate Certificate Renewal
The answer to shorter validity is not a bigger spreadsheet. It is automation, with monitoring as a safety net. Here is the approach we recommend.
- Build a complete certificate inventory. List every public certificate: domain, where it is installed, who issued it, expiry date, and who owns the service. Scan your domains and subdomains and check Certificate Transparency logs so you also find certificates that nobody remembers buying.
- Name an owner for every certificate. Each certificate needs a responsible team, not just a person. Record the renewal method and the vendor contact for anything hosted outside your own servers.
- Automate issuance and renewal with ACME. ACME is the standard protocol for automatic certificate issuance and renewal. Most modern web servers, load balancers, hosting control panels and cloud platforms support it directly or through a client. Where possible, let the system renew and install certificates on its own, well before expiry.
- Plan for systems that cannot automate. Some older appliances, legacy applications and embedded devices cannot use ACME. Put these on a short list, check whether a firmware update or a reverse proxy in front of them can handle TLS, and plan their upgrade or replacement.
- Monitor expiry independently. Automation can fail quietly, for example when a DNS change breaks domain validation. Add external checks that alert your team at 30, 14 and 7 days before any certificate expires, so a failed renewal gets noticed in time.
- Document and test the process. Write a short runbook for renewal and emergency replacement. Test it once on a non-critical site so the team knows exactly what to do when an alert fires.
Common Mistakes to Avoid
- Buying longer certificates to "save effort". Multi-year certificates are no longer issued as single long-lived certificates. Even if a vendor sells a multi-year plan, you still have to reissue and reinstall within the validity limit.
- Forgetting the certificate chain. Installing the new certificate without the correct intermediate certificate can cause errors on some browsers and devices even though the certificate itself is valid.
- Ignoring internal systems. Internal tools that use certificates from your own private certificate authority are not covered by the public rules, but they still expire. Keep them in the same inventory.
- Relying on email reminders from the vendor. These often go to an old mailbox or an employee who has left. Send alerts to a shared team channel or monitoring tool instead.
What This Means for Government Departments and PSUs
Government portals and PSU applications often run for years with the same vendor setup, and hosting may be split between a data centre, a MeitY-empanelled cloud and third-party service providers. This makes ownership of certificates less clear. When you renew your AMC or hosting contracts, add clear responsibility for certificate renewal, automation and expiry monitoring to the scope of work. Ask vendors to confirm how their platform will handle 100-day and 47-day certificates before those limits arrive.
If you are also working on stronger logging and incident readiness, a certificate outage is a good test of your process. Our guide to 24x7 network monitoring explains how expiry alerts fit into wider monitoring.
A Simple Timeline to Follow
- Now (2026): finish the inventory, assign owners, and turn on ACME for every website and portal that supports it.
- Before March 2027: close the gap on legacy systems and put independent expiry monitoring on everything.
- Before March 2029: make sure no public certificate depends on a manual step, since renewing every few weeks by hand will not be practical.
Frequently Asked Questions
What is the maximum SSL certificate validity in 2026?
For publicly trusted TLS certificates issued from 15 March 2026, the maximum validity is 200 days. It falls to 100 days from 15 March 2027 and 47 days from 15 March 2029.
Do I need to replace my current certificate right away?
No. Certificates issued before the change stay valid until their expiry date. The new limits apply when you renew or buy a new certificate.
Does this apply to free certificates too?
Yes. The rules apply to all publicly trusted certificates. Many free certificate authorities already issue short-lived certificates and expect renewal through ACME, which is why automation is the natural fix.
What if our application cannot support automatic renewal?
You can often place a reverse proxy or load balancer in front of it to handle TLS and renew automatically. If that is not possible, plan an upgrade and keep strict expiry monitoring in the meantime.
How Affix Center Helps
Affix Center helps enterprises, SMEs and government departments move from manual certificate renewal to a managed, automated process. Our IT operations and managed services team can build your certificate inventory, set up ACME automation across web servers and hosting, and add expiry alerts to your monitoring. Where certificates sit on firewalls, VPNs and legacy systems, our cybersecurity and cloud and infrastructure specialists plan the right fix for each one.
Do not wait for the next warning page to find out which certificate was missed. Talk to Affix Center and we will help you put certificate renewal on autopilot.