SC-081

47-day certificate lifetimes: why ACME automation is now mandatory

The CA/Browser Forum approved Ballot SC-081v3 in April 2025. It steps maximum TLS certificate validity down on fixed calendar dates — not when your team finishes a migration project. If you still renew by spreadsheet and calendar reminder, the phase-in turns that process into a volume problem long before 2029.

SC-081 effective dates

Max TLS certificate validity Effective date
398 days Today (14 July 2026)
200 days 15 March 2026
100 days 15 March 2027
47 days 15 March 2029

The 200-day step is already in effect as of this writing. The table above reflects the full schedule so you can plan headcount and automation against fixed dates — not the friendly "47 days" headline at the end.

Domain validation reuse shrinks to 10 days

SC-081 also reduces how long a CA may reuse your domain-control validation (DCV) evidence. At the final step, reuse drops to 10 days. A 47-day certificate outlives that window, so each renewal requires fresh domain validation — not an annual DNS TXT paste. HTTP-01 and DNS-01 automation must be reliable, monitored, and idempotent, not a quarterly runbook entry.

Renewal math at 47 days

Operations teams plan in renewal events, not certificate lifetimes alone. At 398 days you might touch each cert once a year. At a 47-day maximum, renewing with a safety margin means a cadence near every 30–35 days — about eight renewals per certificate per year (365 ÷ 47 ≈ 7.8).

One hundred certificates at one renewal per year is one hundred ticketable events. The same hundred at eight events per year is eight hundred, each now carrying fresh DCV. Manual processes do not scale linearly — they scale with people, and people miss shifts.

Enterprise volume and outage rates

DigiCert's 2025 enterprise research reports organizations averaging more than 50,000 certificates, with two in three experiencing an outage caused by certificate expiry in the prior year. SC-081 multiplies renewal frequency before most estates shrink certificate count. Expiry-driven outages are already common; shorter lifetimes raise the event rate without adding slack.

Why manual renewal stops scaling

ACME automation is not a 2029 project. The honest decision point is whether you build an ACME pipeline before the 200-day step costs you headcount, or after an outage forces the issue.

Model your estate

Use the ACME renewal timeline to map not_after dates to cron windows, and the cert expiry risk calculator to stress-test alert thresholds against shorter lifetimes. Read the full narrative on the manual renewal cliff blog post.

Automate Certificates inventories certificates, runs ACME v2 renewal, deploys to Azure, AWS, and GCP targets, and exports audit records per renewal. See pricing (from €199/month (Team), Business €499, MSP from €1,499 per month) or compare enterprise CLM options on the comparison hub.

Questions

  • What is CA/Browser Forum ballot SC-081?

    SC-081v3 (approved April 2025) reduces the maximum validity period for publicly trusted TLS certificates in stepped phases: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. No public CA can issue longer-lived certificates after each effective date.

  • How many renewals per year at 47-day maximum lifetime?

    Planning on a 30–35 day renewal cadence to retain margin, each certificate requires roughly eight renewal events per year (365 ÷ 47 ≈ 7.8). Each event includes domain validation — SC-081 also reduces domain-control validation reuse to 10 days at the final step.

  • When does manual renewal break?

    Many teams feel pressure at the 200-day step in March 2026, when quarterly calendar reminders no longer align with expiry. Manual DNS TXT paste, spreadsheet tracking, and 14-day alerts designed for 398-day certs become insufficient as lifetimes shrink.

  • What did DigiCert research find about enterprise certificate volume?

    DigiCert 2025 enterprise research reports organizations averaging more than 50,000 certificates, with two in three experiencing an outage caused by certificate expiry in the prior year — before SC-081 fully applies.

  • Does Automate Certificates support SC-081 renewal cadence?

    Yes. Automate Certificates renews via ACME v2 on schedule (default 30 days before not_after), deploys to linked cloud targets, and alerts on challenge failures — not only on expiry — so stalled validation surfaces while there is still time to fix DNS or deployment hooks.