Starting February 24, 2026, industry-wide changes from the CA/Browser Forum reduce the maximum validity period for new SSL/TLS certificates. This article explains what's changing and how it affects your certificate lifecycle.
What's changing
The CA/Browser Forum — the industry group that sets baseline requirements for SSL/TLS certificates — is reducing the maximum certificate validity period from 397 days to 199 days, effective February 24, 2026.
What this means for your certificates
You can still purchase certificates in 1-year terms, but each certificate issued under the new rules is valid for 199 days rather than the full year. To keep your certificate active for the full term you paid for, Ascio automatically reissues it partway through. Note: After a reissue, you must reinstall the new certificate on your server — it isn't applied automatically.
How this affects your certificate lifecycle
Any certificate request still pending after February 24, 2026 follows the new 199-day process. Certificates issued before that date aren't affected and keep their original validity period. Tip: If you're planning to order or renew a certificate close to this date, order before February 24, 2026 to avoid the shorter validity period on that order.
Reduced validation reuse periods
Alongside the validity period change, the CA/Browser Forum is also reducing how long a completed validation can be reused for future orders:
Validation type | Previous reuse period | New reuse period |
Organization-validated (OV) | 825 days | 397 days |
Domain-validated (DV) | 397 days | 199 days |
Next steps
- Learn what SSL certificates do — see What Are SSL Certificates?
- Review the validation methods affected by the reduced reuse periods — see What Are the Validation Methods?
Questions? Contact Ascio Support.
How helpful was this article?
Thanks for your feedback!
Do you still need help? If so please submit a request here.