HomeBlogThe Era of Annual SSL Certificates is Over: Why They Are Now Issued for 200 Days

The Era of Annual SSL Certificates is Over: Why They Are Now Issued for 200 Days

The Era of Annual SSL Certificates is Over: Why They Are Now Issued for 200 Days
Starting in 2026, SSL certificate validity has been cut to 200 days. Learn how to automate renewal and avoid your website getting blocked.

If you are used to remembering about your website's SSL certificate renewal just once a year, we have important news for you. The rules of the web security game have officially changed. The industry regulator, the CA/Browser Forum (which includes Google, Apple, Microsoft, Mozilla, and the largest certificate authorities), has launched a large-scale reform.

Starting March 15, 2026, the maximum validity period for new public SSL certificates has been reduced to 200 days (in practice, some certificate authorities issue them for 199 days).

Why is this necessary, what should you prepare for, and why is 200 days just a warning before even more radical changes? Let's break it down in this article.

Why Shorten the SSL Validity Period?

The official reason is security and data protection. The shorter the "lifespan" of a digital certificate, the less time cybercriminals have to exploit stolen or compromised encryption keys.

In addition, the industry is preparing for the "quantum era" — the emergence of computers capable of quickly cracking old cryptographic algorithms. A short SSL lifecycle will allow the internet industry to instantly deploy new, more resilient security standards across millions of websites simultaneously.

The Changes Timeline: 200 Days Is Just the Beginning

The current 200-day limit was introduced to give website owners and administrators time to adapt to the new order. This is a transition period, as the deadlines will shorten even more aggressively moving forward:

  • From March 15, 2026 — a maximum of 200 days.
  • From March 15, 2027 — a maximum of 100 days.
  • From March 15, 2029 — the certificate lifespan will be just 47 days.

In effect, the industry is systematically leading us toward a situation where updating SSL manually will become physically impossible.

How Does It Work in Practice if You Buy an SSL for a Year?

Certificate authorities and hosting providers have already adapted to the new realities. If you still purchase a 1-year subscription, you are provided with a so-called "bundle" plan:

  1. You pay for a year of service.
  2. Your first certificate is issued for 199–200 days.
  3. Approximately one month before it expires, you must complete a free reissue (renewal) procedure to receive a second certificate for another 200 days.

Note: Certificates issued before March 15, 2026 will remain valid for their full term (up to 398 days), and do not need to be replaced early. However, all new reissues will follow the 200-day rule.

What Are the Risks of Overlooking This?

If you miss the renewal date, your website will instantly become inaccessible to users. Browsers (Chrome, Safari, Edge) will display a frightening warning page: "Your connection is not private. Attackers might be trying to steal your information."

This leads to an immediate loss of traffic, lower search engine rankings, and a drop in customer trust.

What Should Website Owners Do Right Now?

The main takeaway of the new reform is the transition to automation. Manual control is a thing of the past. To ensure your business does not suffer, follow three simple steps:

  1. Check current certificates. Find out the exact expiration dates of your active SSL documents.
  2. Enable auto-renewal on your hosting. If you use standard or free certificates (such as Let's Encrypt), make sure the automatic renewal feature is enabled in your hosting control panel.
  3. Stay informed. ABCDomain is taking all necessary measures to ensure the uninterrupted operation of our users' services — keep an eye on our updates and email notifications.