
Tim Callan at Sectigo explains why organisations need to take proactive steps to validate public TLS certificates
Google’s decision to reduce the maximum validity period for public TLS (Transport Layer Security) certificates, also known as SSL (Secure Sockets Layer) certificates, to 90 days from 398 days will send shockwaves across the cyber-security landscape.
In its "Moving Forward, Together" roadmap, shared on 3 March 2023, Google revealed its plan to reduce the maximum validity of public TLS certificates to just 90 days. This may seem minor, but in fact, this is a significant change and one that demands the attention of senior leaders everywhere.
At the moment, it looks as though this forthcoming industry change will be implemented via a CA Browser Forum ballot. However, if Google chooses to unilaterally enforce the depreciation of certificate lifespans, by making it a requirement of its root program, this would become a de-facto industry standard, forcing every commercial public Certificate Authority (CA) to follow suit.
Since browsers have the autonomy to establish their own root program requirements, this modification could take place even if there’s no mandate from the CA/B Forum. By proactively communicating its plans, Google is affording the industry ample time to brace itself for the impending transition, and its implications.
While there is no specific date as to when Google plans to implement the change, it is likely that this 90-day maximum validity period will take effect by the end of 2024. As such, organisations should take the opportunity, and time afforded, to prepare for change.
To understand why Google is pushing for this move, it’s essential to acknowledge the significance of SSL/TLS certificates, their ubiquity, and critical functionality across the digital landscape.
Digital certificates provide security and encryption for today’s data. Similar to passports, certificates based on public key infrastructure serve as digital IDs that contain the identity information of their holders such as software, code, bots, IoT/OT, laptops, and devices. Acting as authenticators for both humans and machines, these certificates facilitate seamless communication in the digital world.
Public key cryptography is the backbone of all things digital, ensuring secure business transactions within and beyond enterprise networks. These cryptographic systems secure an array of systems and processes, ranging from a home-office printer to intricate IoT devices in factories, and critical national infrastructure systems.
Certificates, functioning as digital trust stamps, authenticate and verify the vast and ever-increasing number of human and machine identities accessing IT ecosystems every second.
In recent years, the lifespan of public SSL/TLS certificates has been steadily declining, from three years to two, then one, and now Google intends to reduce it further to just 90 days.
The fact is, 398 days (the current maximum term allowed by the CABF Baseline Requirements and by various major root programs) is a long time for a compromised certificate to exist. After all, the longer a certificate remains valid, the more likely it is to become compromised.
By implementing shorter lifespans for certificates, the chances for cyber-criminals to exploit outdated certificates are significantly reduced. These situations commonly occur when companies shut down operations, merge with other entities, transfer domain names, or undergo rebranding processes.
The transition to 90-day TLS certificates plays a crucial role in limiting the window of opportunity for compromised certificates to be exploited. As a result, this measure strengthens the integrity of the entire ecosystem and mitigates the risks associated with service outages and security breaches.
Ultimately, it empowers organisations to swiftly adapt to quantum-resistant algorithms, safeguarding their sensitive data against potential threats posed by quantum computers in the future.
However, in spite of the significant operational challenges faced by businesses, surprisingly 47% of businesses continue to rely on manual methods for certificate management.
This approach poses inherent problems as it is highly susceptible to human error, resulting in expired or misconfigured certificates. Also, the lengthy nature of manual management discourages organisations from actively monitoring and addressing expired or compromised certificates, thereby escalating the risk of service disruptions, security breaches, and non-compliance with industry standards and regulations.
The remedy to this issue is evident: adopting automation as a means of ensuring effective certificate management.
Despite the critical need for efficient certificate management, a staggering 47% of organisations still need to manage their certificates manually. But with Google’s upcoming 90-day maximum term, organisations will now face the daunting task of renewing and deploying every certificate in their servers more than five times a year.
This isn’t just about a handful of certificates - we’re talking about hundreds or even thousands. The message from Google is clear, manual management is no longer practical, and the ecosystem must enable automation for certificate management with challenges like rogue certificates, gaining visibility for cryptographic decisions, and individual deployment, the task will soon become downright impossible without automation.
Google’s upcoming move is not just about the lifespan of SSL/TLS certificates depreciating, it will also reduce the length of domain validation reuse. This is where it gets even more complicated. The current baseline requirements allow for up to 398 days of reuse, Google aims to protect domain owners and prevent certificate misuse by relying on up-to-date information.
This will mean that businesses will not only have to keep track of their certificates but also re-verify their domains every 90 days. This is where automation becomes even more critical.
IT teams must act now and embrace automation for certificate management, including CA-agnostic Certificate Lifecycle Management (CLM) platforms. These solutions enable the efficient discovery of certificates in enterprise environments regardless of the issuing Certificate Authority.
They also provide timely notifications for impending expirations and automate the provisioning and installation of renewal and replacement certificates. By doing so, they help prevent outages and security breaches resulting from the incorrect use or renewal of certificates.
To minimise the risk of being caught off guard by this industry change, it is crucial for businesses to proactively safeguard their operations through automated certificate management.
Tim Callan, Chief Experience Officer at Sectigo
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543