Core change: SSL certificates will become short‑lived, and validation must be repeated more frequently.
Until March 15, 2026: Max validity = 398 days
From March 15, 2026: Max validity = 200 days
From March 15, 2027: Max validity = 100 days
From March 15, 2029: Max validity = 47 days (final target)
This is the global rule for all publicly trusted SSL/TLS certificates (DV, OV, EV).
Validation data cannot be reused for long periods anymore.
Until March 15, 2026: Reuse allowed for 398 days
From March 15, 2026: Reuse allowed for 200 days
From March 15, 2027: Reuse allowed for 100 days
From March 15, 2029: Reuse allowed for 10 days (very strict)
This means frequent re-validation is mandatory.
SII (Subject Identity Information) reuse drops from 825 days to 398 days starting March 15, 2026.
Reduce exposure if a private key is compromised
Reduce reliance on broken revocation systems (OCSP/CRL)
Force automation and modern PKI practices