Learn

What Are 47-Day TLS Certificates and Why Do Enterprises Need Automated Certificate Lifecycle Management?

What Are 47-Day TLS Certificates? Why Enterprises Need Automated Certificate Lifecycle Management

Public TLS certificate lifetimes have started the transition from 398 days to 200 days, as of March 2026. By 2029, certificate lifetimes are expected to shrink to just 47 days , following a unanimous vote from the CA/Browser Forum. This is quickly changing how enterprises manage certificates at scale.

What worked with near annual renewals will not work with a new 47-day timeline. Manual processes, unclear ownership, and limited visibility will lead to missed renewals, outages, and increased audit risk.

Transport Layer Security (TLS) certificates are digital documents that verify a website’s identity and provide a secure, encrypted connection. It ensures that data is kept secure and private while communicating between web applications and servers. While also referred to as “Secure Sockets Layer (SSL) certificates,” TLS is the modern standard used to secure websites, APIs, and digital services.

As the name suggests, 47-day TLS certificates are publicly trusted TLS certificates with a maximum lifespan of 47 days. These short-lived certificates are the result of an industry-wide reduction in certificate lifecycles, rolling out in phases since March 2026.

Effective Date 
Maximum TLS Certificate Validity
Renewal Frequency
Operational Cost & Complexity
Before March 15, 2026
398 days 
1x
Baseline
March 15, 2026
200 days 
2x
+100% more work
March 15, 2027
100 days 
4x
Manual processes break
March 15, 2029
47 days  
8x
Continuous renewal churn 

Effective Date: Before March 15, 2026  
Maximum TLS Certificate Validity: 398 days  
Renewal Frequency: 1x
Operational Cost & Complexity: Baseline

Effective Date: March 15, 2026   
Maximum TLS Certificate Validity: 200 days   
Renewal Frequency: 2x
Operational Cost & Complexity: +100% more work

Effective Date: March 15, 2027 
Maximum TLS Certificate Validity: 100 days    
Renewal Frequency: 4x
Operational Cost & Complexity: Manual processes break

Effective Date: March 15, 2029 
Maximum TLS Certificate Validity: 47 days  
Renewal Frequency: 8x
Operational Cost & Complexity: Continuous renewal churn 

This change is designed to strengthen trust, reduce exposure to compromised certificates, and encourage modern, automated management practices across the ecosystem.

The CA/Browser Forum introduced this shift to address growing security risks tied to long-lived certificates. Shorter lifetimes limit the window of exposure if a certificate or private key is compromised, reduce reliance on revocation mechanisms that are often inconsistently enforced, and ensure organizations regularly rotate keys and validate domain ownership. The move also reflects the need to keep pace with increasingly automated, short-lived infrastructure and machine identities.

This shift is fundamentally changing how organizations approach public key infrastructure (PKI) and certificate lifecycle management (CLM). Rather than defaulting to public trust, organizations must first determine whether public trust is appropriate for each use case, or if private PKI is a better fit. Once evaluated, automation becomes essential for publicly trusted certificates, as manual processes can’t keep up with 47-day renewal cycles.

As we move towards a 47-day certificate era, it’s important for organizations to first consider how trust models align with use cases.

Public trust and private PKI operate under different policies, with operational risk largely determined by who sets and enforces those rules. In public trust, requirements are dictated by browser and platform providers like Google, Apple, Microsoft, and Mozilla, primarily to secure public internet traffic. As these certificate requirements evolve, organizations relying too heavily on public trust face growing operational complexity and risk.

With private trust, organizations maintain more control over PKI strategy. So, the first question should not be “How do we automate everything?” but rather “Am I using the right PKI for this use case?”

After evaluating current PKI strategy and shifting appropriate use cases to a private trust model, you can reduce the scope of what needs to be automated to meet public trust requirements.

Reducing certificate lifetimes creates significant new complexity for enterprises. Certificate renewal shifts from annually to once every six weeks, increasing the need for intervention at every stage.

Certificate volumes have also increased across enterprises as cloud and DevOps environments grow. This creates a challenge when large volumes of certificates are spread across fragmented, hard-to-track systems.

Most enterprises still rely on manual certificate tracking and calendar-based renewals. Across sprawling environments with a large volume of certificates, manual management is neither effective nor scalable for growing businesses.

The impact:

  • Missed renewals leading to outages and downtime
  • Increased incident response burden
  • Greater risk to customer experience and revenue

What Is Certificate Lifecycle Management? 

Certificate Lifecycle Management (CLM) is the process of managing certificates across their entire lifecycle, including:

  • Discovery and inventory
  • Issuance and validation
  • Deployment and configuration
  • Renewal and rotation
  • Monitoring and alerting
  • Revocation and replacement
  • Reporting and compliance

Effective CLM provides automation, visibility, and control across every certificate in your environment

Person holding smartphone outdoors near modern buildings
Abstract glowing blue circular data swirl

Why Automated Certificate Lifecycle Management Is Essential

Relying on manual certificate lifecycle management opens an enterprise to greater risk as certificate lifespans shorten. In a 47-day certificate environment, automated certificate management is necessary to keep up with continuous renewals.

  • Automated Discovery: Identify all certificates across on-premises, cloud, and third-party environments.
  • Automated Renewal: Eliminate manual tracking and ensure certificates are renewed before expiry.
  • Automated Deployment: Seamlessly deploy certificates to applications, services, and infrastructure.
  • Continuous Monitoring: Detect certificate expirations, failures, and policy violations in real time.
  • Governance and Reporting: Enforce policies and maintain audit-ready documentation.

Key capabilities enterprises need:

Automation is necessary to prevent outages, maintain operational stability, and create a future-ready security foundation.

How to Choose Certificate Management Tools for 47-Day TLS Changes

Not all certificate management tools are designed for enterprise-scale automation. Enterprises must thoroughly evaluate CLM solutions. 

Key evaluation criteria:

  • Discovery and inventory capabilities
  • Support for public and private certificates
  • Automated renewal and deployment
  • Integration with public CAs and ACME protocols
  • API and DevOps integrations
  • Role-based access control (RBAC)
  • Reporting and audit readiness
  • Multi-cloud and hybrid environment support

The most effective tools shift teams from reactive renewal management to proactive lifecycle control. Modern data security solutions like the Entrust Cryptographic Security Platform unify PKI, hardware security modules (HSMs), and key, certificate, and secrets lifecycle management – giving businesses centralized visibility and control to support proactive certificate lifecycle management at scale.

Person using tablet while sitting on office desk
Readiness Area
Key Question
Inventory
Do we know where all certificates are deployed?
Evaluate
Are we using the right PKI for each use case?
Ownership
Does every certificate have an assigned owner?
Automation
Can certificates be renewed without manual intervention?
Monitoring
Can we detect certificate expirations and failures before they cause outages?
Governance
Are policies enforced consistently across teams?
Scale
Can we handle 47-day lifecycles at enterprise volume?

Readiness Area: Inventory 
Key Question: Do we know where all certificates are deployed?
 

Readiness Area: Evaluate 
Key Question: Are we using the right PKI for each use case?
 

Readiness Area: Ownership 
Key Question  : Does every certificate have an assigned owner?
 

Readiness Area: Automation 
Key Question: Can certificates be renewed without manual intervention?
 

Readiness Area: Monitoring 
Key Question: Can we detect certificate expirations and failures before they cause outages?
windows

Readiness Area: Governance 
Key Question: Are policies enforced consistently across teams?
 

Readiness Area: Scale 
Key Question: Can we handle 47-day lifecycles at enterprise volume?
 

The shift to 47-day TLS certificates gives organizations an opportunity not only to reassess public vs. private trust models, but also to move from manual processes to automated certificate lifecycle management to scale with evolving security needs in the post-quantum era.

Organizations that modernize early will:

  • Prevent certificate-related outages
  • Reduce operational risk and cost
  • Improve compliance and audit readiness
  • Scale securely across cloud and machine identities

Those that delay risk falling behind as manual processes become unsustainable.

What are 47-day TLS certificates? 

47-day TLS certificates are publicly trusted certificates with a maximum valid lifespan of 47 days, introduced to improve web security through a phased reduction in certificate lifetimes.  

When will TLS certificates be reduced to 47 days?

The timeline reduces from 398 days to 200 days (March 2026), 100 days (March 2027), and 47 days by March 15, 2029.

Do enterprises need automation for 47-day certificates?

Yes. Enterprise environments with high certificate volumes and distributed ownership require automation to manage discovery, renewal, and monitoring effectively.  

What is certificate lifecycle management (CLM)?

CLM is the process of managing certificates across their full lifecycle, including discovery, issuance, renewal, monitoring, and revocation.  

Take Control of Your PKI Strategy

Discover how Entrust PKI solutions help you gain visibility, align trust models to business use cases, and reduce the impact of changing certificate requirements.