Your website's certificate stopped lasting a year in March, and the next cut is already booked
- Technology
- IT consultancy
- Hosting
- Knutsford
In March, the maximum life of a website security certificate dropped from 398 days to 200. Certificates issued just after the change run out at the end of this month.
For most firms that will pass unnoticed, because the certificate renews itself and always has. The businesses this catches are the ones where renewal is a person remembering, and there are three more cuts scheduled.
What changed, and who decided it
The rules for these certificates are set by the CA/Browser Forum, where the certificate authorities and the browser makers agree what browsers will accept. In April 2025 it adopted a timetable for shortening certificate lifetimes. Apple, Google, Microsoft and Mozilla all voted in favour, as did 25 of the 30 certificate authorities that cast a vote, so this is settled rather than proposed.
- 398 days
- Issued before 15 March 2026
- 200 days
- From 15 March 2026
- 100 days
- From 15 March 2027
- 47 days
- From 15 March 2029
The rules also tell certificate authorities not to issue right up to the cap, so real certificates come out a day or two short of those figures. A certificate issued on the day the 200-day limit began expires around the very end of September, which is why this is worth reading now rather than in the spring.
Nothing about your website has changed. It is the same certificate doing the same job, with a shorter shelf life. The reasoning behind the shortening is that a certificate is a statement about who controlled a domain on the day it was issued, and the longer it stays valid, the greater the chance that statement has quietly stopped being true.
The technology was never the problem
A certificate that renews on a schedule is a solved problem and has been for years. What breaks is the arrangement around it.
The pattern is familiar. The site was built by a freelancer or a small agency some time ago. The certificate was set up in their account, under their email address, because that was the sensible thing on the day. Every renewal notice since has gone to that address. Nobody in the business has ever seen one, which is fine right up until the moment it is not.
When a certificate lapses, visitors do not get a subtle hint. They get a full-page warning telling them the connection is not private, and most of them leave. The business finds out from a customer, on a Monday, and then spends a day working out whose account the certificate lives in.
This is the same failure as the domain that renews to an inbox nobody reads, and it has the same fix, which is knowing where your things are kept before you need them.
An annual renewal was never a good process. It was a bad one that failed slowly enough to get away with.
That is the honest reading of what has happened here. A yearly certificate gave a manual habit twelve months to look reliable. At 200 days it looks shakier. At 100 it fails twice as often, and at 47 it stops being something a person can reasonably be asked to do.
Automatic renewal is old, boring and usually free
Let's Encrypt has issued 90-day certificates, renewed by software rather than by anyone remembering, since 2015. That is comfortably inside every limit in the table above, including the 2029 one. A site running that way in 2015 needs no action for any of the changes described in this article.
Most hosting control panels have had a switch for this for years, and turning it on generally costs nothing. If someone is invoicing you annually to do it by hand, that is a fair question to ask them.
There are honest reasons to buy a certificate. Organisation-validated certificates put a vetted company name inside the certificate, and paid ones come with a warranty. Both matter to a minority of businesses, mostly ones handling payments or regulated data. For an ordinary small business website, the free automated certificate is not a compromise. It is the better answer, because it renews whether or not anyone is paying attention.
Ten minutes, once
- 01Open your own site with https:// and click the padlock. The browser will name the issuer and the expiry date
- 02Establish how it renews: automatically through the host, or by a person acting on an invoice or a diary note
- 03Find out which mailbox the expiry warnings arrive in, and whether anyone still opens it
- 04If it is manual, ask whoever runs the hosting to switch automatic renewal on
Step three is the one that finds the real problem. Plenty of firms have automatic renewal set up correctly and could still not tell you which address the failure notice would reach, which means the day it does go wrong they lose an afternoon before they start fixing anything.
What March 2027 asks of you
At 100 days a certificate needs replacing three or four times a year. In 2029 it becomes roughly every six weeks. Nobody expects a person to do that, and the industry is already moving faster than its own rules require: Let's Encrypt has said it will drop to 64-day certificates in February 2027 and 45-day in February 2028.
So the deadline in March 2027 is not really about certificates. It asks a narrower question, which is whether the things your business depends on renew themselves or depend on somebody remembering. Domains, certificates, card details on the hosting account, the licence for the software the office runs on. Certificates are simply the first of them to have a published schedule for getting harder.
We build, host and look after sites for clients, so the certificates on them renew without anyone thinking about it, which is the standard to hold any hosting arrangement to. If you do not know how yours renews, or who would be told if it stopped, ask us to look. It is a ten-minute answer, and the good outcome is that we tell you it is already handled.
We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.
If any of this sounds like your business, we will tell you plainly whether we can help.
