← Back to news 20.07.2026

The certificate nobody renewed

An expired TLS certificate blocks a service for every browser, loudly and instantly. Until now a manageable nuisance, because a certificate lasted about a year. But the CA/Browser Forum is cutting the maximum lifetime in stages from 398 to 47 days. Why manual certificate upkeep reaches its end, and what takes its place.

An expired TLS certificate does not take a server down. It merely blocks it for every browser that visits, with a red warning page nobody overlooks. The outage is noticed immediately, and the cause is almost always mundane: a reminder in the wrong calendar, a colleague on vacation, a list nobody maintains anymore.

The time you had for it is shrinking

Until now this was a manageable nuisance, because a certificate lasted about a year. That is changing fundamentally. The CA/Browser Forum, where Apple, Google, Mozilla and Microsoft among others set the rules for browser trust, adopted a schedule in 2025: the maximum lifetime of public TLS certificates falls from 398 days in stages to 47. The first stage already applies, since March 2026 it is 200 days, from 2027 it is 100, and from 2029 finally 47. What you did by hand once a year will soon recur several times a year.

By hand it can no longer be managed

For a handful of certificates a calendar entry may still do. Reality looks different: certificates sit not only on the main domain but on internal services, test environments, load balancers and devices someone set up years ago. The dangerous expiry is never the one you know about but the one you forgot. The shorter the lifetimes, the more often you run into exactly these forgotten certificates, and the less a process built on manual work forgives.

How isidaten runs certificate management

Certificate management in isidaten keeps all TLS certificates in a central inventory, with lifecycle events, renewal workflows and provider management. You do not have to gather the certificates by hand: whatever attack surface management finds on your external surface is imported directly, including the ones nobody thought of anymore. The expiry alert is configurable per certificate and already knows the CA/Browser Forum schedule, with staggered thresholds along the 200, 100 and 47 day stages. The silent risk becomes a monitored process.

More is shown on the certificate management module page. How the certificates come in from the attack surface is covered by attack surface management.

Matching solution isidaten for ISO/IEC 27001

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.