47-Day TLS Certificates: What They Are and How to Prepare
Solution Highlights
セクションを確認する
- TLS Certificate Lifetime Reduction Timeline
- What Are 47-Day TLS Certificates?
- Why Are TLS Certificate Lifetimes Being Reduced?
- Rethink Public Trust in a 47-Day Certificate World
- Why 47-Day Certificates Create an Enterprise Challenge
- How to Prepare for 47-Day TLS Certificates: Key Readiness Questions Enterprises Must Ask
- よくある質問
What Are 47-Day TLS Certificates and Why Do Enterprises Need Automated CLM?
Public TLS certificate lifetimes have started the transition from 398 days to 200 days, as of March 2026. By 2029, certificate lifetimes are expected to shrink to 47 days, following a unanimous vote from the CA/Browser Forum. This is quickly changing how enterprises manage certificates at scale.
What worked with near-annual renewals will not work with a new 47-day timeline. Manual processes, unclear ownership, and limited visibility will lead to missed renewals, outages, and increased audit risk.
TLS Certificate Lifetime Reduction Timeline
Effective Date: Before March 15, 2026
Maximum TLS Certificate Validity: 398 days
Renewal Frequency: 1x
Operational Cost & Complexity: Baseline
Effective Date: March 15, 2026
Maximum TLS Certificate Validity: 200 days
Renewal Frequency: 2x
Operational Cost & Complexity: +100% more work
Effective Date: March 15, 2027
Maximum TLS Certificate Validity: 100 days
Renewal Frequency: 4x
Operational Cost & Complexity: Manual processes break
Effective Date: March 15, 2029
Maximum TLS Certificate Validity: 47 days
Renewal Frequency: 8x
Operational Cost & Complexity: Continuous renewal churn
47日間TLS証明書とは
Transport Layer Security (TLS) certificates are digital documents that verify a website’s identity and provide a secure, encrypted connection. They ensure that data stays secure and private while communicating between web applications and servers. While also referred to as “Secure Sockets Layer (SSL) certificates,” TLS is the modern standard used to secure websites, APIs, and digital services.
As the name suggests, 47-day TLS certificates are publicly trusted TLS certificates with a maximum lifespan of 47 days. These short-lived certificates are the result of an industry-wide reduction in certificate lifecycles, rolling out in phases since March 2026.
Why Are TLS Certificate Lifetimes Being Reduced?
This change is designed to strengthen trust, reduce exposure to compromised certificates, and encourage modern, automated management practices across the ecosystem.
The CA/Browser Forum introduced this shift to address growing security risks tied to long-lived certificates. Shorter lifetimes limit the window of exposure if a certificate or private key is compromised, reduce reliance on revocation mechanisms that are often inconsistently enforced, and ensure organizations regularly rotate keys and validate domain ownership. The move also reflects the need to keep pace with increasingly automated, short-lived infrastructure and machine identities.
This shift is fundamentally changing how organizations approach public key infrastructure (PKI) and certificate lifecycle management (CLM). Rather than defaulting to public trust, organizations must first determine whether public trust is appropriate for each use case, or if private PKI is a better fit. Once evaluated, automation becomes essential for publicly trusted certificates, as manual processes can’t keep up with 47-day renewal cycles.
Rethink Public Trust in a 47-Day Certificate World
Shorter certificate lifespans raise a strategic question before an operational one: which trust model fits each use case.
Public trust and private PKI operate under different policies, with operational risk largely determined by who sets and enforces those rules. In public trust, requirements are dictated by browser and platform providers like Google, Apple, Microsoft, and Mozilla, primarily to secure public internet traffic. As these certificate requirements evolve, organizations relying too heavily on public trust face growing operational complexity and risk.
With private trust, organizations maintain more control over PKI strategy. So, the first question should not be “How do we automate everything?” but rather “Am I using the right PKI for this use case?”
After evaluating current PKI strategy and shifting appropriate use cases to a private trust model, you can reduce the scope of what needs to be automated to meet public trust requirements.
Why 47-Day Certificates Create an Enterprise Challenge
Reducing certificate lifetimes creates significant new complexity for enterprises. Certificate renewal shifts from annually to once every six weeks, increasing the need for intervention at every stage.
Certificate volumes have also increased across enterprises as cloud and DevOps environments grow. This creates a challenge when large volumes of certificates are spread across fragmented, hard-to-track systems.
Most enterprises still rely on manual certificate tracking and calendar-based renewals. Across sprawling environments with a large volume of certificates, manual management is neither effective nor scalable for growing businesses.
The impact:
- Missed renewals leading to outages and downtime
- Increased incident response burden
- Greater risk to customer experience and revenue
What is CLM?
Certificate Lifecycle Management (CLM) is the process of managing certificates across their entire lifecycle, including:
- Discovery and inventory
- Issuance and validation
- Deployment and configuration
- Renewal and rotation
- Monitoring and alerting
- Revocation and replacement
- Reporting and compliance
Effective CLM provides automation, visibility, and control across every certificate in your environment
Why Automated Certificate Lifecycle Management Is Essential
Relying on manual certificate lifecycle management opens an enterprise to greater risk as certificate lifespans shorten. In a 47-day certificate environment, automated certificate management is necessary to keep up with continuous renewals:
- Automated Discovery: Identify all certificates across on-premises, cloud, and third-party environments.
- Automated Renewal: Eliminate manual tracking and ensure certificates are renewed before expiration.
- Automated Deployment: Seamlessly deploy certificates to applications, services, and infrastructure.
- Continuous Monitoring: Detect certificate expirations, failures, and policy violations in real time.
- Governance and Reporting: Enforce policies and maintain audit-ready documentation.
Automation is necessary to prevent outages, maintain operational stability, and create a future-ready security foundation.
How to Choose Certificate Management Tools for 47-Day TLS Changes
Not all certificate management tools are designed for enterprise-scale automation.
Key evaluation criteria:
- Discovery and inventory capabilities
- Support for public and private certificates
- Automated renewal and deployment
- Integration with public CAs and ACME protocols
- API and DevOps integrations
- ロールベースのアクセス制御(RBAC)
- Reporting and audit readiness
- Multi-cloud and hybrid environment support
The most effective tools shift teams from reactive renewal management to proactive lifecycle control. Modern data security solutions like the Entrust Cryptographic Security Platform unify PKI, hardware security modules (HSMs), and key, certificate, and secrets lifecycle management – giving businesses centralized visibility and control to support proactive certificate lifecycle management at scale.
How to Prepare for 47-Day TLS Certificates: Key Readiness Questions Enterprises Must Ask
Readiness Area: Inventory
Key Question: Do we know where all certificates are deployed?
Readiness Area: Evaluate
Key Question: Are we using the right PKI for each use case?
Readiness Area: Ownership
Key Question : Does every certificate have an assigned owner?
Readiness Area: Automation
Key Question: Can certificates be renewed without manual intervention?
Readiness Area: Monitoring
Key Question: Can we detect certificate expirations and failures before they cause outages?
windows
Readiness Area: Governance
Key Question: Are policies enforced consistently across teams?
Readiness Area: Scale
Key Question: Can we handle 47-day lifecycles at enterprise volume?
よくある質問
47日間有効のTLS証明書とは何ですか?
47-day TLS certificates are publicly trusted certificates with a maximum valid lifespan of 47 days, introduced to improve web security through a phased reduction in certificate lifetimes.
When will TLS certificates be reduced to 47 days?
The timeline reduces from 398 days to 200 days (March 2026), 100 days (March 2027), and 47 days by March 15, 2029.
Do enterprises need automation for 47-day certificates?
はい。Enterprise environments with high certificate volumes and distributed ownership require automation to manage discovery, renewal, and monitoring effectively.
What is certificate lifecycle management (CLM)?
CLM is the process of managing certificates across their full lifecycle, including discovery, issuance, renewal, monitoring, and revocation.
hat happens if a certificate isn’t renewed in time?
An expired certificate breaks TLS/SSL trust, causing browser warnings, failed connections, and potential service outages until it’s replaced.
Can automated CLM handle both public and private certificates?
はい。Enterprise-grade CLM platforms manage both public trust and private PKI certificates from a single system, letting teams apply the right trust model per use case.
CA/Browser Forumとは何ですか?
The CA/Browser Forum is the industry body of certificate authorities and browser vendors that sets the technical and policy standards governing publicly trusted TLS certificates.
Prepare for the 47-Day Certificate Era
Move from manual to automated CLM to prevent outages, reduce risk, and scale securely across cloud and machine identities.