[ 1. Certificate Validity Timeline (Official CA/B Forum Schedule) ]
[ Until March 15, 2026: Max validity = 398 days ]
[ From March 15, 2026: Max validity = 200 days ]
[ From March 15, 2027: Max validity = 100 days ]
[ From March 15, 2029: Max validity = 47 days (final target) ]
This applies to all publicly trusted SSL/TLS certificates (DV, OV, EV).
[ 2. Domain Validation (DCV) Re‑Use Limits ]
[ Until March 15, 2026: Reuse allowed for 398 days ]
[ From March 15, 2026: Reuse allowed for 200 days ]
[ From March 15, 2027: Reuse allowed for 100 days ]
[ From March 15, 2029: Reuse allowed for 10 days (very strict) ]
[ 3. Identity (OV/EV) Validation Re‑Use ]
[ SII (Subject Identity Information) reuse drops from 825 days to 398 days starting March 15, 2026 ]
[ 4. Why This Policy Exists ]
[ Reduce exposure if a private key is compromised ]
[ Reduce reliance on weak revocation systems (OCSP/CRL) ]
[ Force automation and modern PKI practices ]