Tech

Inside the Shift to 47-Day TLS Certificates and What It Means for Enterprise IT

Zaara Abbas

By: Zaara Abbas

4 min read

Publicly trusted TLS certificates are being shortened from 398 days to 47 days in phases through 2029, turning renewal from an annual chore into a near-daily operational process. ManageEngine is betting that the real bottleneck is not renewal itself but the manual deployment steps that follow, and has added post-deployment automation to Key Manager Plus to close that gap before the 2027 cutover.

For years, renewing a public TLS certificate has felt like changing the batteries in a smoke alarm. A calendar reminder pings once a year, an engineer requests a new certificate, installs it, and the task disappears from view until the same date rolls around. That routine is about to end.

Under a ballot passed by the CA/Browser Forum in April 2025, the maximum validity of publicly trusted TLS certificates is being cut from 398 days to 47 days over three phases. The ceiling dropped to 200 days in March 2026. It will fall to 100 days in March 2027 and to 47 days by March 2029. Apple proposed the measure. Google, Microsoft and Mozilla backed it. No member voted against. For enterprise IT teams, the schedule turns certificate management from a scheduled task into a continuous operational process.

The arithmetic is straightforward. An organization holding 1,000 public certificates today performs a handful of renewals in a typical month. Under a 47-day maximum, published estimates put the same estate at roughly 7,700 renewals a year, or about 21 every business day.

The Bottleneck is not Renewal

Certificate issuance itself is largely a solved problem. The ACME protocol and its commercial equivalents have automated it for close to a decade, and most enterprises with any certificate tooling already automate discovery, expiry alerting and, in many cases, renewal itself.

What remains manual is what happens after a certificate is issued. Someone still has to push the new file to the target server, run dependent scripts, restart the services that rely on it, and confirm the new certificate is being served to end users. Load balancers, network appliances, legacy application servers and edge devices often cannot accept an automated push, which is why deployment has stayed a human task in most environments. Certificate expiry has caused documented outages at Microsoft, LinkedIn and Spotify. The common thread has rarely been an attacker; it has been a renewal that completed cleanly while the service in front of it continued serving an older file.

The ballot, known as SC-081v3, also reduces the domain control validation reuse window, which falls to 10 days by 2029. The evidence proving an organization controls a domain will expire faster than the certificates it supports, meaning domain ownership must be re-proven at close to every renewal.

A Vendor Response Aimed at the Last Manual Step

On July 15, ManageEngine, the IT management division of Zoho Corporation, added post-deployment automation for TLS certificates to Key Manager Plus, its certificate life cycle and machine identity management product. The feature pushes renewed certificates to target servers, runs configured scripts, restarts dependent services and notifies stakeholders. It is certificate-authority-agnostic and runs identically on-premises and in the cloud.

"Certificate renewal is rarely the hard part. The work that piles up on teams is what comes after it, at scale: pushing certificates to the server, restarting the services, and confirming they actually went live. End-to-end automation is what turns a 47-day renewal cycle from a scramble into something that runs on its own. With Key Manager Plus, we are eliminating the last manual step in the life cycle management loop," said Vasudevan Seshadri, director of product management at ManageEngine.

One reference customer is RevSpring, a payment and consumer engagement provider whose infrastructure team is moving from fewer than 200 certificates to an effective workload above 2,000.

"We’re going from under 200 certificates to over 2,000, across a lot of domains, different server setups, credentials and post-deployment actions for nearly all of it. We’ve had to dedicate significant engineering time to certificate management alone since the change to 200 days. With the 47-day certificate renewals coming up, automation is the only way we can keep up, and Key Manager Plus’ CA-agnostic, certificate life cycle management has helped us automate the whole thing," said Jonathan Choiniere, infrastructure manager at RevSpring.

The Real Deadline is 2027, Not 2029

Certificate life cycle management is a competitive category. Venafi, Keyfactor and AppViewX all sell into the same deadline. Two questions separate the products. The first is whether the platform can reach devices that cannot speak ACME. The second is whether it verifies that a certificate is actually being served after deployment, rather than reporting a successful renewal and stopping there.

The public discussion has fixated on the headline 47-day figure, but the operational cliff is earlier. The 100-day phase in March 2027 is where manual processes stop scaling for most organizations. Machine identity, once a footnote in security architecture, is becoming a first-class operational category, and the 47-day rule is the forcing function.


Related articles

Operation Endgame: Hacking the Hackers to Bring Down a Global Credential Theft Network

How Outpost24’s New CyberFlex Program Helps Security Teams Keep Pace With AI-Era Risk

UAE Organisations Show Stronger Resilience Against Cyber Attacks

Share this article

Related Articles