SSL/TLS certificate reissuance: prepare for the new validity rules
Public SSL/TLS certificates must now be reissued and renewed more frequently. Understand the new SSL/TLS certificate validity rules, check your HTTPS certificate and prepare confidently for upcoming deadlines.
Why should you plan ahead for SSL certificate reissuance?
An expired SSL/TLS certificate can trigger browser warnings, undermine visitor trust and cause a visible disruption to your website. With the new validity periods, planning ahead is essential.
An expired or incorrectly installed certificate can trigger a security warning in your visitors’ browsers.
Validity periods are getting shorter: 200 days from 2026, 100 days from 2027, then 47 days from 2029.
The new rules apply to public SSL/TLS certificates, including DV, OV, EV, Wildcard and multi-domain certificates, particularly those issued by Sectigo.
Need to track multiple certificates over time?
From your customer area, view all your SSL certificates, track expiry dates, receive alerts, initiate reissuance and plan renewals without chasing deadlines.Timeline for the new SSL/TLS validity periods
The maximum validity period for public SSL/TLS certificates is being progressively reduced.
The reuse period for Domain Control Validation (DCV) is also being shortened.
| Effective date | Maximum validity of a public SSL/TLS certificate | Reuse of domain validation — DCV | Main impact |
|---|---|---|---|
| Until March 15, 2026 | 398 days | 398 days | A renewal cycle of approximately one year. |
| From March 15, 2026 | 200 days | 200 days | Certificates must be reissued approximately twice a year. |
| From March 15, 2027 | 100 days | 100 days | Manual tracking becomes more prone to missed deadlines. |
| From March 15, 2029 | 47 days | 10 days | Automation becomes strongly recommended. |
What is SSL/TLS certificate reissuance?
Reissuing an SSL/TLS certificate means generating a new certificate from an existing order or certificate. It may be necessary when a private key changes, a server is migrated, a domain name needs to be corrected or new validation is required.This should not be confused with commercial renewal. A certificate can be reissued during its validity period, but its lifetime remains subject to certificate authority and browser rules.
When should an SSL certificate be reissued?
- ✓ Server change or hosting migration.
- ✓ Loss or replacement of the private key.
- ✓ Error in the domain name or declared SANs.
- ✓ Addition, correction or modification of a covered domain.
- ✓ Suspected compromise of the certificate or private key.
- ✓ An approaching expiration date requiring reissuance..
- ✓ Expired DCV or validation that must be repeated.
Why are SSL/TLS certificate lifetimes getting shorter?
Shorter lifetimes are intended to strengthen overall web security. Shorter-lived certificates limit exposure in the event of compromise, encourage automation and allow organizations to adopt new cryptographic practices more quickly.Which Sectigo certificates are affected?
The new rules apply to public SSL/TLS certificates regardless of validation level: DV, OV, EV, Wildcard, multi-domain or SAN certificates, sometimes called UCC depending on their use. Sectigo SSL certificates in the product catalog should therefore be monitored carefully ahead of upcoming renewal deadlines.Best practices to prevent HTTPS downtime
As validity periods shorten, careful management becomes increasingly essential.
An SSL certificate often goes unnoticed in day-to-day operations until its expiry directly affects access to your website.
List all publicly accessible domains, subdomains, applications, APIs and services along with their associated certificates.
Set up alerts before expiry to allow enough time for reissuance.
As the number of certificates grows, automation reduces missed deadlines, human error and service disruptions.
SSL Certificate Reissuance – Frequently Asked Questions
Frequently asked questions about renewals, DCV and changes to certificate lifetimes.
- What is the maximum SSL/TLS certificate lifetime in 2026?
From March 15, 2026, The maximum validity period for public SSL/TLS certificates is reduced to 200 days. Some providers may issue slightly shorter certificates to remain strictly below the permitted limit.
- What is DCV?
DCV, or Domain Control Validation, verifies control of a domain. It allows the certificate authority to confirm that the applicant is authorized to obtain a certificate for the domain in question.
- Does reissuance extend the certificate lifetime?
No. Reissuance cannot extend a certificate beyond the maximum permitted lifetime. It generates a new certificate whose validity period depends on the certificate authority’s rules, the purchased order and the requirements in force at the time of issuance.
- What happens if my SSL certificate expires?
The browser may display a security warning to visitors. This can undermine trust, block certain interactions and cause a visible disruption to your HTTPS service.
- Are Sectigo SSL certificates affected?
Yes. Public Sectigo SSL/TLS certificates are affected, as are public certificates issued by other browser-trusted certificate authorities.
Can’t find the answer you need? Contact our support team
Sources and references
- CA/Browser Forum — Ballot SC-081v3 : progressive reduction of public TLS certificate validity and data reuse periods.
- Sectigo — 47-Day SSL : information on shorter SSL/TLS certificate lifetimes and automation.
- DigiCert — Domain validation reuse changes in 2026 : changes to domain validation reuse rules.
- DigiCert — TLS certificate lifetimes reduced to 47 days : timeline for 2026, 2027 and 2029.