SSL/TLS · Certificate management

SSL/TLS certificate reissuance: prepare for the new validity rules

Public SSL/TLS certificates must now be reissued and renewed more frequently. Understand the new SSL/TLS certificate validity rules, check your HTTPS certificate and prepare confidently for upcoming deadlines.



Why should you plan ahead for SSL certificate reissuance?

An expired SSL/TLS certificate can trigger browser warnings, undermine visitor trust and cause a visible disruption to your website. With the new validity periods, planning ahead is essential.

Avoid HTTPS warnings

An expired or incorrectly installed certificate can trigger a security warning in your visitors’ browsers.

Plan ahead for reissuance

Validity periods are getting shorter: 200 days from 2026, 100 days from 2027, then 47 days from 2029.

Stay compliant

The new rules apply to public SSL/TLS certificates, including DV, OV, EV, Wildcard and multi-domain certificates, particularly those issued by Sectigo.




Need to track multiple certificates over time?

From your customer area, view all your SSL certificates, track expiry dates, receive alerts, initiate reissuance and plan renewals without chasing deadlines.

Timeline for the new SSL/TLS validity periods

The maximum validity period for public SSL/TLS certificates is being progressively reduced.
The reuse period for Domain Control Validation (DCV) is also being shortened.

Effective dateMaximum validity
of a public SSL/TLS certificate
Reuse of domain
validation — DCV
Main impact
Until March 15, 2026398 days398 daysA renewal cycle of approximately one year.
From March 15, 2026200 days200 daysCertificates must be reissued approximately twice a year.
From March 15, 2027100 days100 daysManual tracking becomes more prone to missed deadlines.
From March 15, 202947 days10 daysAutomation becomes strongly recommended.



What is SSL/TLS certificate reissuance?

Reissuing an SSL/TLS certificate means generating a new certificate from an existing order or certificate. It may be necessary when a private key changes, a server is migrated, a domain name needs to be corrected or new validation is required.

This should not be confused with commercial renewal. A certificate can be reissued during its validity period, but its lifetime remains subject to certificate authority and browser rules.

When should an SSL certificate be reissued?
  1.   ✓ Server change or hosting migration.
  2.   ✓ Loss or replacement of the private key.
  3.   ✓ Error in the domain name or declared SANs.
  4.   ✓ Addition, correction or modification of a covered domain.
  5.   ✓ Suspected compromise of the certificate or private key.
  6.   ✓ An approaching expiration date requiring reissuance..
  7.   ✓ Expired DCV or validation that must be repeated.

Why are SSL/TLS certificate lifetimes getting shorter?
Shorter lifetimes are intended to strengthen overall web security. Shorter-lived certificates limit exposure in the event of compromise, encourage automation and allow organizations to adopt new cryptographic practices more quickly.

Which Sectigo certificates are affected?
The new rules apply to public SSL/TLS certificates regardless of validation level: DV, OV, EV, Wildcard, multi-domain or SAN certificates, sometimes called UCC depending on their use. Sectigo SSL certificates in the product catalog should therefore be monitored carefully ahead of upcoming renewal deadlines.

Best practices to prevent HTTPS downtime

As validity periods shorten, careful management becomes increasingly essential.
An SSL certificate often goes unnoticed in day-to-day operations until its expiry directly affects access to your website.

Keep an inventory of your certificates

List all publicly accessible domains, subdomains, applications, APIs and services along with their associated certificates.

Monitor expiry dates

Set up alerts before expiry to allow enough time for reissuance.

Introduce automation gradually

As the number of certificates grows, automation reduces missed deadlines, human error and service disruptions.




SSL Certificate Reissuance – Frequently Asked Questions

Frequently asked questions about renewals, DCV and changes to certificate lifetimes.

  • What is the maximum SSL/TLS certificate lifetime in 2026?

    From March 15, 2026, The maximum validity period for public SSL/TLS certificates is reduced to 200 days. Some providers may issue slightly shorter certificates to remain strictly below the permitted limit.

  • What is DCV?

    DCV, or Domain Control Validation, verifies control of a domain. It allows the certificate authority to confirm that the applicant is authorized to obtain a certificate for the domain in question.

  • Does reissuance extend the certificate lifetime?

    No. Reissuance cannot extend a certificate beyond the maximum permitted lifetime. It generates a new certificate whose validity period depends on the certificate authority’s rules, the purchased order and the requirements in force at the time of issuance.

  • What happens if my SSL certificate expires?

    The browser may display a security warning to visitors. This can undermine trust, block certain interactions and cause a visible disruption to your HTTPS service.

  • Are Sectigo SSL certificates affected?

    Yes. Public Sectigo SSL/TLS certificates are affected, as are public certificates issued by other browser-trusted certificate authorities.

Can’t find the answer you need? Contact our support team

Sources and references




Need to plan ahead for your SSL/TLS renewals?

Our teams help you reissue, renew and monitor your Sectigo SSL certificates.