If you've spent any time configuring user authentication on... Full Story
By Manny Fernandez
July 23, 2026
The Clock Is Ticking: What CA/B Forum’s Ballot SC-081v3 Means for the Future of Web Security
If your team manages SSL/TLS certificates using spreadsheets, calendar reminders, or manual renewals, consider this your official wake-up call.
In April 2025, the CA/Browser (CA/B) Forum passed Ballot SC-081v3 , a landmark proposal authored by Apple’s Clint Wilson and sponsored by Sectigo. The ballot lays out a multi-year roadmap that slashes the maximum lifetime of publicly trusted TLS certificates down to just 47 days by 2029.
This isn’t just an incremental policy tweak; it’s a fundamental shift in how the web handles digital trust. Here is everything you need to know about why this passed, what the timeline looks like, and how your team should prepare.
Why Is the Industry Moving to 47-Day Certificates?
To understand why browsers (Apple, Google, Mozilla, Microsoft) pushed hard for this change, you have to look at the vulnerabilities of long-lived certificates:
-
Revocation is Fundamentally Broken: Traditional revocation mechanisms like CRLs (Certificate Revocation Lists) and OCSP (Online Certificate Status Protocol) have major privacy and reliability flaws. When a key is compromised, browsers often “soft-fail” revocation checks. Shorter certificate lifespans act as a built-in revocation mechanism, even if a key leaks, the maximum window of exposure shrinks dramatically.
-
Domain Ownership Drift: When domains expire, get sold, or change hands, old certificates frequently remain valid for up to 13 months. Attackers can misuse these orphaned certificates to impersonate brands or execute man-in-the-middle attacks.
-
Crypto-Agility: When cryptographic algorithms need to be deprecated (as happened with SHA-1 and will eventually happen with post-quantum transitions), 1-year certificate lifespans slow down ecosystem-wide updates.Short-lived certificates allow security standards to update rapidly across the web.
-
Enforcing Automation: Human error is responsible for the vast majority of certificate outages. By lowering the lifespan threshold, the CA/B Forum is intentionally making manual management operationally impossible, forcing organizations to adopt automated certificate management environments (ACME).
The Phased Timeline: 2026 to 2029
Rather than dropping a 47-day cap overnight, SC-081v3 establishes a progressive reduction schedule to give IT teams time to adapt:
| Phase | Effective Date | Max Certificate Lifetime | Max Domain Validation (DCV) Reuse | Renewals per Year |
| Phase 1 | March 15, 2026 | 200 days (199 effective) | 200 days | ~2 / year |
| Phase 2 | March 15, 2027 | 100 days (99 effective) | 100 days | ~4 / year (Quarterly) |
| Phase 3 | March 15, 2029 | 47 days (46 effective) | 10 days (8 effective) | ~8 / year (Every 6–7 weeks) |
Why “47 Days”?
Why such a specific number? In automated certificate management, a common practice is to trigger renewals when two-thirds of a certificate’s lifespan has elapsed. On a 47-day lifecycle, renewal happens around day 30, giving systems a generous 17-day buffer to retry and resolve any network or DNS validation glitches before the active certificate expires.
The Real Surprise: 10-Day DCV Reuse
While the 47-day certificate cap grabs the headlines, the real operational challenge in Phase 3 is the reduction of Domain Control Validation (DCV) data reuse to 10 days. Currently, CAs let organizations prove domain control once and reuse that proof for up to a year. By 2028/2029, your systems will need to prove domain control almost continuously (roughly every week and a half).
What Does This Mean for Your Organization?
Note: SC-081v3 applies only to publicly trusted TLS certificates. Private PKIs, internal Active Directory Certificate Services (AD CS), and internal mesh certificates are not bound by CA/B Forum rules.
If your public endpoints (websites, APIs, reverse proxies, edge load balancers, and gateways) rely on public CAs like Let’s Encrypt, DigiCert, Sectigo, or GlobalSign, you must prepare now.
Action Plan for IT & Security Teams
-
Perform a Discovery Audit: You cannot automate what you cannot see. Map out every public TLS certificate across all domains, cloud environments, and edge appliances.
-
Transition Away from Manual Workflows: If team members are generating CSRs, completing email/DNS validation manually, and SSHing into servers to install
.crtfiles, those processes will collapse under Phase 2 and Phase 3 workloads. -
Standardize on ACME Protocols: Implement ACME (Automatic Certificate Management Environment) or automated Certificate Lifecycle Management (CLM) platforms.
-
Automate DNS-Based DCV: Because DCV reuse drops to 10 days, programmatic DNS validation (via API-driven DNS providers) will be critical to prevent domain re-validation bottlenecks.
Final Thoughts
Ballot SC-081v3 marks the official end of the “set it and forget it” era for public SSL certificates. While changing operational habits is always challenging, moving toward automated, short-lived certificates reduces outage risks, hardens web endpoints against key misuse, and builds a far more resilient security architecture.
Recent posts
-
-
DNS is one of those technologies that quietly underpins... Full Story
-
BGP issues on FortiGate firewalls usually trace back to... Full Story
-
Every time your laptop talks to your router, a... Full Story
-
If you've spent any time configuring NAT on a... Full Story
-
If you have spent any time configuring firewall policies... Full Story
-
High availability on FortiGate is one of those features... Full Story
-
If you've configured SD-WAN on a FortiGate, you've almost... Full Story
-
FortiLink is the management protocol that turns a FortiSwitch... Full Story
-
FortiSwitches are pretty rock solid from Mean Time Between... Full Story
-
This is a quicky tip. Have you ever gone... Full Story
-
DNS is one of those quiet pieces of internet... Full Story
-
This article is an updated version of the previous... Full Story
-
You will add ns2 as a secondary (slave) BIND9... Full Story
-
In the process of deploying my lab, I needed... Full Story
-
RFC 8805, used to be known as Self-Correcting IP... Full Story
-
Years back, I wrote an article about certificate pinning. ... Full Story
-
FortiGates have the ability to send alerts to Microsoft... Full Story
-
In this post, I am going to walk through... Full Story
-
Troubleshooting VoIP on a FortiGate can feel like trying... Full Story
-
Prior to FortiOS 7.0, there were three commands to... Full Story
-
In this post, I am going to go over... Full Story
-
What we are going to do: We are going... Full Story
-
Choosing between FGCP (FortiGate Clustering Protocol) and FGSP (FortiGate... Full Story
-
Creating a VLAN on macOS (The "Pro" Move) A... Full Story
-
This blog post explores the logic behind how macOS... Full Story
-
Pretty Fly for a Wi-Fi Tell My Wi-Fi Love... Full Story
-
Part of my daily gig is creating BoMs (Bill-of-Materials)... Full Story
-
ICMP introduces several security risks, but careful filtering, rate... Full Story
-
The command diag debug application dhcps -1 enables full... Full Story
-
In the world of FortiOS, execute tac report is... Full Story
-
LLDP; What is it The Link Layer Discovery Protocol... Full Story
-
What it actually does When you run diagnose fdsm... Full Story
-
Monkey Bites are bite-sized, high-impact security insights designed for... Full Story
-
I have run macOS in macOS with Parallels but... Full Story
-
Don't be confused with my other FortiNAC posts where... Full Story
-
This is the third session in a multi-part article... Full Story
-
Today I was configuring key-based authentication on a FortiGate... Full Story
-
Netcat, often called the "Swiss Army knife" of networking,... Full Story
-
At its core, IEEE 802.1X is a network layer... Full Story
-
In case you did not see the previous FortiNAC... Full Story
-
This is our 5th session where we are going... Full Story
-
Now that we have Wireshark installed and somewhat configured,... Full Story
-
The Philosophy of Packet Analysis Troubleshooting isn't about looking... Full Story
-
Everyone learns EVPN as "type 2 carries MACs and... Full Story
-
The short answer. XDR and SOAR overlap on automated... Full Story
-
If your team manages SSL/TLS certificates using spreadsheets, calendar... Full Story