What Are 47-Day TLS Certificates and Why Do Enterprises Need Automated Certificate Lifecycle Management?
What Are 47-Day TLS Certificates? Why Enterprises Need Automated Certificate Lifecycle Management
Public TLS certificate lifetimes have started the transition from 398 days to 200 days, as of March 2026. By 2029, certificate lifetimes are expected to shrink to just 47 days , following a unanimous vote from the CA/Browser Forum. This is quickly changing how enterprises manage certificates at scale.
What worked with near annual renewals will not work with a new 47-day timeline. Manual processes, unclear ownership, and limited visibility will lead to missed renewals, outages, and increased audit risk.
What Are 47-Day TLS Certificates?
Transport Layer Security (TLS) certificates are digital documents that verify a website’s identity and provide a secure, encrypted connection. It ensures that data is kept secure and private while communicating between web applications and servers. While also referred to as “Secure Sockets Layer (SSL) certificates,” TLS is the modern standard used to secure websites, APIs, and digital services.
As the name suggests, 47-day TLS certificates are publicly trusted TLS certificates with a maximum lifespan of 47 days. These short-lived certificates are the result of an industry-wide reduction in certificate lifecycles, rolling out in phases since March 2026.
TLS Certificate Lifetime Reduction Timeline
Effective Date: Before March 15, 2026
Maximum TLS Certificate Validity: 398 days
Renewal Frequency: 1x
Operational Cost & Complexity: Baseline
Effective Date: March 15, 2026
Maximum TLS Certificate Validity: 200 days
Renewal Frequency: 2x
Operational Cost & Complexity: +100% more work
Effective Date: March 15, 2027
Maximum TLS Certificate Validity: 100 days
Renewal Frequency: 4x
Operational Cost & Complexity: Manual processes break
Effective Date: March 15, 2029
Maximum TLS Certificate Validity: 47 days
Renewal Frequency: 8x
Operational Cost & Complexity: Continuous renewal churn
Why Are TLS Certificate Lifetimes Being Reduced?
This change is designed to strengthen trust, reduce exposure to compromised certificates, and encourage modern, automated management practices across the ecosystem.
The CA/Browser Forum introduced this shift to address growing security risks tied to long-lived certificates. Shorter lifetimes limit the window of exposure if a certificate or private key is compromised, reduce reliance on revocation mechanisms that are often inconsistently enforced, and ensure organizations regularly rotate keys and validate domain ownership. The move also reflects the need to keep pace with increasingly automated, short-lived infrastructure and machine identities.
This shift is fundamentally changing how organizations approach public key infrastructure (PKI) and certificate lifecycle management (CLM). Rather than defaulting to public trust, organizations must first determine whether public trust is appropriate for each use case, or if private PKI is a better fit. Once evaluated, automation becomes essential for publicly trusted certificates, as manual processes can’t keep up with 47-day renewal cycles.
Rethink Public Trust in a 47-Day Certificate World
As we move towards a 47-day certificate era, it’s important for organizations to first consider how trust models align with use cases.
Public trust and private PKI operate under different policies, with operational risk largely determined by who sets and enforces those rules. In public trust, requirements are dictated by browser and platform providers like Google, Apple, Microsoft, and Mozilla, primarily to secure public internet traffic. As these certificate requirements evolve, organizations relying too heavily on public trust face growing operational complexity and risk.
With private trust, organizations maintain more control over PKI strategy. So, the first question should not be “How do we automate everything?” but rather “Am I using the right PKI for this use case?”
After evaluating current PKI strategy and shifting appropriate use cases to a private trust model, you can reduce the scope of what needs to be automated to meet public trust requirements.
Why 47-Day Certificates Create an Enterprise Challenge
Reducing certificate lifetimes creates significant new complexity for enterprises. Certificate renewal shifts from annually to once every six weeks, increasing the need for intervention at every stage.
Certificate volumes have also increased across enterprises as cloud and DevOps environments grow. This creates a challenge when large volumes of certificates are spread across fragmented, hard-to-track systems.
Most enterprises still rely on manual certificate tracking and calendar-based renewals. Across sprawling environments with a large volume of certificates, manual management is neither effective nor scalable for growing businesses.
The impact:
- Missed renewals leading to outages and downtime
- Increased incident response burden
- Greater risk to customer experience and revenue
What Is Certificate Lifecycle Management?
Certificate Lifecycle Management (CLM) is the process of managing certificates across their entire lifecycle, including:
- Discovery and inventory
- Issuance and validation
- Deployment and configuration
- Renewal and rotation
- Monitoring and alerting
- Revocation and replacement
- Reporting and compliance
Effective CLM provides automation, visibility, and control across every certificate in your environment
Why Automated Certificate Lifecycle Management Is Essential
Relying on manual certificate lifecycle management opens an enterprise to greater risk as certificate lifespans shorten. In a 47-day certificate environment, automated certificate management is necessary to keep up with continuous renewals.
- Automated Discovery: Identify all certificates across on-premises, cloud, and third-party environments.
- Automated Renewal: Eliminate manual tracking and ensure certificates are renewed before expiry.
- Automated Deployment: Seamlessly deploy certificates to applications, services, and infrastructure.
- Continuous Monitoring: Detect certificate expirations, failures, and policy violations in real time.
- Governance and Reporting: Enforce policies and maintain audit-ready documentation.
Key capabilities enterprises need:
Automation is necessary to prevent outages, maintain operational stability, and create a future-ready security foundation.
How to Choose Certificate Management Tools for 47-Day TLS Changes
Not all certificate management tools are designed for enterprise-scale automation. Enterprises must thoroughly evaluate CLM solutions.
Key evaluation criteria:
- Discovery and inventory capabilities
- Support for public and private certificates
- Automated renewal and deployment
- Integration with public CAs and ACME protocols
- API and DevOps integrations
- Role-based access control (RBAC)
- Reporting and audit readiness
- Multi-cloud and hybrid environment support
The most effective tools shift teams from reactive renewal management to proactive lifecycle control. Modern data security solutions like the Entrust Cryptographic Security Platform unify PKI, hardware security modules (HSMs), and key, certificate, and secrets lifecycle management – giving businesses centralized visibility and control to support proactive certificate lifecycle management at scale.
How to Prepare for 47-Day TLS Certificates: Key Readiness Questions Enterprises Must Ask
Readiness Area: Inventory
Key Question: Do we know where all certificates are deployed?
Readiness Area: Evaluate
Key Question: Are we using the right PKI for each use case?
Readiness Area: Ownership
Key Question : Does every certificate have an assigned owner?
Readiness Area: Automation
Key Question: Can certificates be renewed without manual intervention?
Readiness Area: Monitoring
Key Question: Can we detect certificate expirations and failures before they cause outages?
windows
Readiness Area: Governance
Key Question: Are policies enforced consistently across teams?
Readiness Area: Scale
Key Question: Can we handle 47-day lifecycles at enterprise volume?
Prepare for the 47-Day Certificate Era
The shift to 47-day TLS certificates gives organizations an opportunity not only to reassess public vs. private trust models, but also to move from manual processes to automated certificate lifecycle management to scale with evolving security needs in the post-quantum era.
Organizations that modernize early will:
- Prevent certificate-related outages
- Reduce operational risk and cost
- Improve compliance and audit readiness
- Scale securely across cloud and machine identities
Those that delay risk falling behind as manual processes become unsustainable.
Frequently Asked Questions
What are 47-day TLS certificates?
47-day TLS certificates are publicly trusted certificates with a maximum valid lifespan of 47 days, introduced to improve web security through a phased reduction in certificate lifetimes.
When will TLS certificates be reduced to 47 days?
The timeline reduces from 398 days to 200 days (March 2026), 100 days (March 2027), and 47 days by March 15, 2029.
Do enterprises need automation for 47-day certificates?
Yes. Enterprise environments with high certificate volumes and distributed ownership require automation to manage discovery, renewal, and monitoring effectively.
What is certificate lifecycle management (CLM)?
CLM is the process of managing certificates across their full lifecycle, including discovery, issuance, renewal, monitoring, and revocation.
Explore Sections
- What Are 47-Day TLS Certificates?
- TLS Certificate Lifetime Reduction Timeline
- Why Are TLS Certificate Lifetimes Being Reduced?
- Rethink Public Trust in a 47-Day Certificate World
- Why 47-Day Certificates Create an Enterprise Challenge
- How to Prepare for 47-Day TLS Certificates: Key Readiness Questions Enterprises Must Ask
- Prepare for the 47-Day Certificate Era
- Frequently Asked Questions
Take Control of Your PKI Strategy
Discover how Entrust PKI solutions help you gain visibility, align trust models to business use cases, and reduce the impact of changing certificate requirements.