SSL Certificates Are Getting Shorter.
From March 15, 2026, SSL certificates issued to your website can be valid for a maximum of 200 days – down from 398. This isn’t a proposal or a future consideration. It’s already in effect. The CA/Browser Forum approved it unanimously in April 2025, and every major browser vendor – Apple, Google, Mozilla, Microsoft – signed off on it.
For most WestHost customers on managed hosting, nothing changes on your end. For those running their own certificate infrastructure or DNS, there are steps worth taking now. This article covers both.
What changed and when
The CA/Browser Forum – the standards body that governs SSL certificates globally – passed Ballot SC-081v3 in April 2025, setting a phased reduction in maximum certificate validity:
- March 15, 2026: 200-day maximum (in effect now)
- March 15, 2027: 100-day maximum
- March 15, 2029: 47-day maximum, with domain validation reusable for 10 days only
Certificates issued before March 15, 2026 under the old 398-day rules run to their natural expiry without disruption. The new limits apply to any certificate issued from that date forward.

Why the industry made this call
A certificate valid for 398 days can carry stale information for over a year. Domain ownership transfers. Businesses restructure. Keys get compromised. The old model relied on certificate authorities doing thorough checks upfront and then trusting the result for the better part of two years.
Shorter validity periods mean more frequent verification that the organisation presenting the certificate still legitimately controls the domain. It’s a meaningful security improvement, and the move toward automation it requires makes certificate management more resilient across the board.
If WestHost manages your hosting and SSL
No action required. We will handle the reissuance process automatically through a DNS verification record. Your site stays secure, your certificate stays active, and the process runs in the background without interruption.
You may receive an automated notification email from the certificate issuer sent to your domain’s admin contact. This is routine – it confirms the process ran. It rarely requires a response, but make sure that contact address is current.
If you manage your own SSL or DNS
This is where preparation matters. Run through the following before your next certificate renewal:
- DNS access: Confirm you can add and modify DNS records on short notice. Third-party DNS providers vary in how quickly changes propagate – know your setup.
- Automation tooling: Check whether your certificate management system supports automated renewal via ACME protocol or equivalent. Manual processes work at 200 days. At 100 days they become harder. At 47 days they become a liability.
- Admin contact address: Verify the email address registered as your domain’s admin contact is monitored. Certificate issuers send verification and notification emails here.
- Renewal calendar: If you’re still tracking renewals manually, update your records now. A 200-day certificate issued today expires before the end of the year – not in twelve months.
The bigger picture
The 200-day change is the first in a deliberate sequence. By 2029 the industry will require near-continuous automated verification. The direction is clear and the timeline is fixed – this isn’t a change that can be waited out.
Questions about your SSL setup or whether any of this applies to your configuration? Our support team is available 24/7.