Sectigo

Blogs

Apple Releases Draft Ballot to Shorten Certificate Lifespan to 45 Days

Earlier this week, on October 9, during the second day of the fall CA/Browser Forum Face-to-Face meeting, Apple revealed that it had published a draft ballot for commentary to GitHub. This proposal, which is sponsored by Sectigo, offers to incrementally phase maximum term for public SSL/TLS certificates down to 45 days between now and 2027. The draft also phases down the DCV reuse period over time, until it reaches 10 days in 2027.

Table of Contents

1. An accelerating trend of shortening digital certificate lifespans
2. Why are these numbers what they are?
3. It’s time to automate certificate lifecycle management

An accelerating trend of shortening digital certificate lifespans

This move from Apple follows Google’s previous announcement in its “Moving Forward, Together” roadmap of its intention to reduce the maximum validity for public SSL/TLS certificates from 398 days to 90 days, in a future policy update or a CA/B Forum ballot proposal.

At this stage, it’s important to note that it is just in the proposal for discussion stage, but it clearly sends a strong message to the industry with the two largest browsers – Google and now Apple – both advocating for shorter digital certificate lifespans.

If this ballot gets officially issued and passes in the coming months, this is what the reality could look like for businesses renewing their public SSL/TLS certificates:

Chart of certificates lifetimes expectations

Why are these numbers what they are?

The public certificate lifespans proposed by Apple may seem complex at first, but they follow a simple logic of ideal certificate term + early renewal window:

  • 200 days = 180 days (6 months) + 20 days early renewal
  • 100 days = 90 days (3 months) + 10 days early renewal
  • 45 days = 42 days (6 weeks) + 3 days early renewal

But although there’s logic behind this, the gradual decrease in certificate lifespans will no doubt prove a headache for busy IT security teams, juggling with lots of certificates expiring at different times. It’s easy to predict that companies that use manual methods for tracking and monitoring certificate expiries will soon find themselves overwhelmed by the rapidly changing certificate lifespans. After all, what Apple is suggesting is that certificate lifecycles now change every year!

In addition to the reduction in maximum certificate terms, the DCV reuse period is also going to decrease as follows, if the proposal passes:

Date Maximum certificate term DCV reuse period
9/15/25 200 days 200 days
9/15/26 100 days 100 days
4/15/27 45 days 45 days
9/15/27 10 days

It’s time to automate certificate lifecycle management

This proposal highlights the critical importance for businesses of all sizes to seriously consider and implement fully automated certificate lifecycle management (CLM). There’s real urgency for organizations to adopt a “set it and forget it” approach to certificate renewals, so any future change in renewal windows don’t impact their operations or cause unnecessary downtime and outages.

Sectigo is fully committed to supporting these initiatives from the browsers. Our decision to sponsor this latest ballot proposal is a testament to our dedication towards the integrity of the WebPKI ecosystem and the security of our customers. Sectigo Certificate Manager (SCM) is the most comprehensive certificate lifecycle management platform on the market, designed to proactively address the SSL challenges of tomorrow. Schedule a demo today to learn how your company can benefit from SCM, or start a free trial.

Sectigo Featured Resources

Learn more about how Sectigo can provide your business with the robust, scalable security solution it needs to thrive in today’s digital landscape.

Resource Type
Select some options
Resource Type
Sectigo - Case Studies
Trusted Digital Payments' Success with Sectigo
As a global payment services leader, Worldline needed a secure and efficient way to manage its di...
Sectigo - Case Studies
Manufacturing's Success with Sectigo
In the manufacturing sector, operational downtime and security risks can be costly. This case stu...
Sectigo - Case Studies
Supply Chain Management's Success with Sectigo
Managing multiple certificate vendors created inefficiencies and security challenges for a major ...
Sectigo - Case Studies
Energy & Utilities' Success with Sectigo
For energy and utility companies, digital security is crucial to safeguarding critical infrastruc...
Sectigo - Case Studies
Finance and Banking's Success with Sectigo
In the highly regulated finance and banking sector, secure and efficient certificate management i...
Sectigo - Case Studies
Fast Moving Consumer Goods (FMCG)'s Success with Sectigo
For a fast-moving consumer goods (FMCG) company, managing multiple digital certificate vendors pr...
Sectigo - Case Studies
Sectigo + Rijkswaterstaat’s Success with Sectigo
RWS, a leader in language services and technology, needed a comprehensive solution to manage its ...
Sectigo - Case Studies
Schreder's Success with Sectigo
Schreder, a global leader in outdoor lighting solutions, faced challenges in managing and securin...
Sectigo - Datasheets
CA Agnostic Certificate Lifecycle Management
Sectigo’s CA-Agnostic solution offers flexibility in certificate management, allowing organisatio...
Sectigo - Datasheets
Effective certificate management relies on enhanced disco...
Effective certificate management starts with knowing what certificates you have and where they ar...
Sectigo - Datasheets
Vendor Consolidation
Managing multiple certificate vendors can lead to inefficiencies and increased security risks. Th...
Sectigo - Datasheets
Sectigo as your public Certificate Authority (CA)
Public Certificate Authorities (CAs) are vital for securing external communications and building ...
Sectigo - Datasheets
Sectigo as your private Certificate Authority (CA)
Private Certificate Authorities (CAs) are essential for organisations requiring internal security...
Sectigo - Whitepapers
The Critical Need for Certificate Automation
Manual certificate management can lead to costly errors and security risks. The Sectigo Automatio...
Sectigo - Whitepapers
Moving beyond Microsoft AD CS
For organizations relying on Microsoft Active Directory Certificate Services (AD CS), managing an...
Sectigo - Whitepapers
Embracing Quantum Readiness
In today’s rapidly evolving digital environment, managing the lifecycle of digital certificates e...
Sectigo - Whitepapers
Certificate Lifecycle Management Maturity
In today’s rapidly evolving digital environment, managing the lifecycle of digital certificates e...
Sectigo - Blogs
The evolving SSL/TLS certificate lifecycle & how to m...
Certificates are dynamic security solutions within PKI, crucial for verifying identities and encr...
Sectigo - Blogs
Understanding the 5 pillars of Certificate Lifecycle Mana...
Certificate Lifecycle Management (CLM) involves discovering, issuing, renewing, and revoking digi...
Sectigo - Blogs
Why SSL certificate renewal automation is essential for b...
Automating SSL certificate renewals is essential for businesses of all sizes to avoid outages and...
Sectigo - Blogs
Why SSL certificates expire: exploring the benefits of sh...
SSL certificates expire to enhance security, comply with evolving regulations, and encourage time...
Sectigo - Blogs
What is quantum computing and what businesses need to kno...
Quantum computing is a hot concept these days, delivering both excitement and trepidation among f...
Sectigo - Blogs
Sectigo’s CLM maturity model for digital certificate mana...
Automated certificate lifecycle management (CLM) simplifies the complex process of managing SSL/T...
Sectigo - Blogs
The risks of expired SSL certificates for enterprise orga...
Expired SSL certificates can expose enterprises to security risks, downtime, loss of customer tru...
Sectigo - Blogs
Quantum computing: Exploring top concerns & the posit...
Quantum computing could revolutionize cybersecurity, but also introduces serious risks, including...
Sectigo - Blogs
Overcoming Certificate Lifecycle Management challenges &a...
Automated certificate lifecycle management (CLM) helps organizations manage digital certificates ...
Sectigo - Blogs
Apple Releases Draft Ballot to Shorten Certificate Lifesp...
Earlier this week, on October 9, during the second day of the fall CA/Browser Forum Face-to-Face ...

Ensure Digital Trust Today

Take the Next Step Toward Comprehensive Certificate Lifecycle Management (CLM).

Fill out the form below, and our team of experts will reach out to discuss how Sectigo can simplify your certificate management, reduce risks, and future-proof your security. Don’t let unmanaged certificates compromise your operations—embrace innovation with Sectigo.