- Key Takeaways
- What does the CA/B Forum actually govern?
- What is Ballot SC-081v3 and why does it matter?
- What happens when organizations do not follow CA/B Forum guidelines?
- How should organizations prepare for shorter certificate validity?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Ready for 47-Day Certificates
The CA/Browser Forum (CA/B Forum) is a voluntary consortium of Certificate Authorities, browser vendors, and other software makers that sets baseline requirements for issuing and validating SSL/TLS, code signing, and S/MIME certificates.
The CA/Browser Forum is an industry group of Certificate Authorities and browser makers that writes the baseline requirements governing how SSL/TLS certificates are issued, validated, and revoked. Its most consequential recent action is Ballot SC-081v3, which phases maximum TLS certificate validity down from 200 days in March 2026 to 47 days by March 2029.
Key Takeaways
- The CA/B Forum sets Baseline Requirements for SSL/TLS certificates, including mandatory Certificate Transparency logging so mis-issued certificates can be detected and revoked.
- Ballot SC-081v3 phases maximum public TLS certificate validity down on a fixed schedule: 200 days from March 15, 2026, 100 days from March 15, 2027, and 47 days from March 15, 2029.
- Extended Validation (EV) certificates still require stricter identity verification, but most browsers no longer display distinct EV indicators such as the company name in the address bar.
- The Forum also governs code signing, S/MIME, and Network and Certificate System Security Requirements through dedicated working groups.
- Automation via ACME and centralized tools like CertSecure Manager is now the practical way to keep pace with shrinking certificate validity periods.
What does the CA/B Forum actually govern?
The Forum’s Baseline Requirements for SSL/TLS certificates cover domain validation, Certificate Transparency logging, and revocation mechanisms like OCSP and CRLs. Separate working groups extend this governance to code signing certificates, S/MIME, and the Network and Certificate System Security Requirements that CAs must follow to protect their own issuance infrastructure.
What is Ballot SC-081v3 and why does it matter?
Ballot SC-081v3 is the CA/B Forum decision that phases down maximum public TLS certificate validity on a fixed, multi-year schedule, replacing earlier informal “90-day certificate” framing with a concrete, staged timeline.
| Effective date | Maximum validity |
|---|---|
| March 15, 2026 | 200 days |
| March 15, 2027 | 100 days |
| March 15, 2029 | 47 days |
This schedule follows an earlier reduction from 825 days to 398 days that took effect in September 2020, continuing a long-running trend toward shorter certificate lifetimes to limit the exposure window if a private key is compromised.
What happens when organizations do not follow CA/B Forum guidelines?
- Expired certificates: an unrenewed certificate can prevent encrypted traffic inspection, delaying detection of an active compromise on that server, as happened with the 2017 Equifax breach involving 147 million affected individuals.
- Mis-issued certificates: Certificate Authorities that skip proper validation risk having their issuance trusted revoked by browsers, as happened when major browsers phased out trust in Symantec-issued certificates following mis-issuance findings in 2017.
- Compromised CA infrastructure: an attacker who breaches a CA’s issuance systems can issue fraudulent certificates for high-value domains, as occurred in the DigiNotar breach in 2011, which led to the CA’s collapse.
How should organizations prepare for shorter certificate validity?
- Automate certificate management: manual renewal cannot keep pace with a 47-day validity window; ACME-based automation and centralized tools like CertSecure Manager become mandatory rather than optional.
- Audit and monitor continuously: regular audits catch expired or soon-to-expire certificates before they cause an outage.
- Enforce role-based access control: restrict who can request, renew, or revoke certificates to reduce the risk of unauthorized changes.
- Plan incident response ahead of time: a documented revoke-and-reissue plan limits damage if a certificate or its private key is compromised.
How Encryption Consulting Helps
CertSecure Manager automates certificate issuance, renewal, and revocation in step with the CA/Browser Forum’s shortened validity schedule, while CodeSign Secure enforces role-based access control over code signing keys the Forum’s requirements also govern. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is the CA/Browser Forum’s role in internet security?
The CA/B Forum writes the Baseline Requirements that Certificate Authorities and browsers follow to issue, validate, and revoke SSL/TLS certificates. Its standards underpin the trust indicators, such as a valid certificate, that browsers rely on to warn users about insecure sites.
What is Ballot SC-081v3?
Ballot SC-081v3 is the CA/B Forum decision that phases down the maximum validity period for public TLS certificates on a fixed schedule: 200 days starting March 2026, 100 days starting March 2027, and 47 days starting March 2029.
Do EV certificates still matter after CA/B Forum changes?
EV certificates still require stricter identity validation than standard certificates, but most browsers stopped showing distinct EV indicators, such as the company name in the address bar, years ago, which has reduced their practical impact on user behavior.
How can organizations prepare for 47-day certificates?
Automating certificate issuance, renewal, and revocation through ACME and a centralized certificate management platform is the practical path, since manual renewal cannot realistically keep pace with a 47-day validity window across a large certificate estate.
Get Ready for 47-Day Certificates
Take the next step
CertSecure Manager automates certificate lifecycles ahead of the CA/Browser Forum’s SC-081v3 schedule, so your organization is ready well before the 47-day requirement takes effect in March 2029. Get ready for 47-day certificates.
- Key Takeaways
- What does the CA/B Forum actually govern?
- What is Ballot SC-081v3 and why does it matter?
- What happens when organizations do not follow CA/B Forum guidelines?
- How should organizations prepare for shorter certificate validity?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Ready for 47-Day Certificates
