It's official: 47-day SSL/TLS certificates will be the new standard
The newly approved measure, initially proposed by Apple and endorsed by Sectigo in January 2025, will gradually reduce certificate lifespans from the current 398 days to 47 days through a phased approach.
This change, supported by Sectigo and major browsers like Apple and Google, marks a turning point for digital certificate management. Organizations will now need to renew certificates nearly every month, an unsustainable pace without automation.
Here’s what this means for your business ➔


Manual certificate management is overwhelming
Manual certificate management is already difficult and tedious. With 47-day TLS, it will become impossible.
With certificates needing renewal every 47 days, as opposed to the current 398-day term, businesses will need to renew all their public certificates every month, as opposed to every year.
This means:
- 12x more certificates
- 12x more work
- 12x higher risk of missing a renewal
Challenges you might face if you manually manage your digital certificates:

Complexity
Managing multiple validations and configurations is time-consuming.

Risk
Forgotten certificates can lead to security breaches and outages.

Inefficiency
Manual processes are prone to errors and delays
Certificate outages impact everyone
Around 81% of companies have experienced a certificate-related outage in the past two years. Certificate outages happen when digital certificates expire or become invalid, causing security and operational issues. Certificate Lifecycle Management (CLM) prevents this by ensuring certificates are always up-to-date.

What happens if no action is taken
When a certificate expire and is not renewed on time it triggers a browser warning informing users that their connection is no longer private, causing them to leave assuming (rightly so) that the site is unsafe.
These warnings not only drive customers away but also damage a business's reputation. The financial impact can be severe, with businesses losing both immediate sales and future revenue as customer trust deteriorates.
But this is just the tip of the iceberg. A missed certificate renewal can also lead to outages, data breaches, service disruptions, and costly non-compliance fines.

It’s time to automate. Here’s your path forward:
Carry out a full SSL/TLS certificate discovery for an inventory of both internal and external certificates.
Compile a comprehensive list of vendor technologies that require those certificates to function.
Identify the relevant automation protocols for each technology in your inventory.
Build out an effective 47-day deployment and implementation plan.
Ensure long-term security and agility for continuous cryptographic readiness.
47-day survival guide
Let's put an end to manual certificate management. The time to prepare for 47-day lifespan certificate is now. Download your free 47-day survival guide and ensure your organization preparedness.


SCM can prepare your organization for 47-day TLS
