Defaults.Exposed

Defaults.ExposedReports

The 90-Day Web: Certificate Lifetimes in 2026

Published

Figures as of 16 August 2026 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.

The headline: seven in ten certificates now live exactly 90 days

Of 231.5 million TLS certificates observed in our August 2026 census, 156.8 million — 67.7% — were issued for a lifetime of exactly 90 days. The median certificate on the public web now lives three months. Ten years ago the default was one to three years. The annual certificate, the one a person renews by hand and forgets about, is down to a 5.0% share and shrinking on a regulatory timetable that ends at 47 days in 2029.

One number in this dataset matters more than any other, and it is not the 90-day figure. It is what sits between: 45.9 million certificates — 19.8% of the web — issued for 197 to 199 days. That cluster did not exist as a major cohort before this year. It is the industry’s maximum-lifetime cap stepping down in real time, visible in a single census snapshot.

Key numbers

Where these numbers come from

We scanned 432 million domains for the August 2026 census round and captured the leaf certificate presented by every domain that completed a TLS handshake: 231.5 million certificates in total. For each one we computed the issued lifetime — the gap between the certificate’s notBefore and notAfter fields. That is the lifespan the issuer chose, not the time remaining when we looked. The distinction matters and we return to it in the methodology section.

A small residue of certificates computed to negative lifetimes — expiry timestamps before their own issue timestamps, which is clock garbage on the serving side. We excluded them, leaving 231,444,701 certificates in the distribution. Every percentage below uses that denominator.

Why is 90 days the default certificate lifetime?

Because automation won, and 90 days is the lifetime automation picked.

Let’s Encrypt launched free, automated certificates in late 2015 with a fixed 90-day lifetime, arguing that short lifetimes limit the damage window of a stolen key and force operators to automate renewal rather than calendar it. (That history is industry context, not census data.) The other high-volume issuers that grew up around the ACME protocol — hosting-panel integrations, CDN-managed certificates — adopted the same rhythm.

The census shows how completely that argument carried. The 90-day spike stands at 156,808,864 certificates. Widen the window by a single day either side, to 89–91 days, and the cohort reaches approximately 159.5 million — 68.9% of everything. The median certificate lifetime across the entire distribution is 90 days flat.

There is a hard implication buried in that spike, and it is the reason this report exists. Nobody renews a certificate by hand every 90 days across years without missing one. A 90-day certificate is a machine’s certificate. Seven in ten domains on the TLS web are now renewed by software, on a loop, with no human in the path. That is the good news.

What is the 200-day certificate cluster?

The strangest shape in the distribution is the sharp cluster at 197–199 days: a towering 45,867,988 at 198 days, with smaller cohorts at 197 and 199. Add the surrounding 180–200-day band and the cohort reaches approximately 47.2 million — 20.4% of the web running on a roughly six-and-a-half-month certificate.

Six-and-a-half months is not a lifetime anyone chooses for human reasons. It maps to a rule. In April 2025 the CA/Browser Forum — the body that sets the rules public certificate authorities must follow — adopted a schedule that steps the maximum certificate lifetime down from 398 days to 200 days in March 2026, 100 days in March 2027, and 47 days in March 2029. (That schedule is public industry knowledge, not something our scanner measured.) Our census ran in August 2026: five months into the 200-day era. CAs that previously issued year-long certificates now issue just under the new cap, with a couple of days’ margin — 198 days, overwhelmingly.

So the 198-day mountain is the transition itself, caught mid-stride. Certificates issued before March 2026 could still carry up to 398 days; certificates issued after cannot. The 45.9-million-strong cluster is the first renewal wave under the new ceiling, and by next year’s census it should have swallowed most of what remains of the annual cohort — before the 100-day cap starts shrinking it again.

The old ceiling is visible too. A band of 3.7 million certificates sits at 390–398 days — issuers padding right up against the previous 398-day maximum, a cap in force since September 2020 (industry context). Those are the last of their kind. When they expire, nothing issued by a public CA can replace them at that length.

The annual certificate is dying

Issued lifetimeCertificatesShare of 231.5M
≤ 90 days (automated rhythm)~159,500,000~68.9%
91–200 days (incl. the 198-day transition cluster)~48,800,000~21.1%
201–363 days~190,000~0.08%
~1 year (364–366 days)11,473,1675.0%
367–398 days (old 398-day cap band)~7,100,000~3.1%
Over 398 days~2,600,000~1.1%

Two cohorts in this table tell opposite stories.

The 364–366-day cohort — 11.5 million certificates, 5.0% — is the classic annual certificate: bought, installed, and diarised for renewal in a year. Under the CA/B Forum schedule this product effectively ceased to be issuable by public CAs in March 2026. The census catches its long tail: every certificate in this cohort was issued before the cap changed, and the cohort mechanically goes to zero as they expire.

The over-398-day cohort — around 2.6 million certificates, ~1.1% — cannot have come from a public CA at all under rules in force since 2020. It is dominated by self-signed and private-CA material: certificates at exactly 3,650 days, the ten-year lifetime that ships as the default in countless OpenSSL tutorials and appliance setup scripts, plus multi-year certificates of various lengths, and — genuinely — certificates issued for a hundred years or more. Our census counted over 9 million certificates with chain or authorization issues overall, so long-lifetime junk is a substantial slice of that population. A hundred-year certificate is not a security plan. It is a device someone configured once and intends never to touch again.

Who is ready for the 47-day web?

Here is the question the whole distribution builds to. The same schedule that created the 198-day cluster ends at a 47-day maximum in March 2029. How much of the web could absorb that today?

The honest answer from the data: almost none of it runs at that rhythm yet — 175,097 certificates, 0.08%, currently carry lifetimes of 47 days or fewer — but most of it is already built for it. The 67.7% on 90-day certificates renew by automation; for them, 47 days is a config change on someone else’s server, and most will never notice the transition. The same is broadly true of the CDN-managed slice of the 198-day cohort.

The exposed population is the manual tail: the 5.0% on annual certificates plus the ~3.1% still riding the old 398-day band — roughly 18 million domains whose renewal process, whatever it is, has only ever been exercised once a year. Each step of the cap — 100 days in 2027, 47 in 2029 — multiplies the number of renewals that process must survive. An operation that renews by calendar reminder and a copy-paste session tolerates one renewal a year. It does not tolerate eight.

The failure mode is not abstract. A missed renewal is a browser interstitial on your own domain, and our census sees the wreckage of manual renewal constantly — expired certificates still being served long after anyone stopped watching. The fix is the same as it has been for a decade: ACME automation is free, supported by every major web server, and takes an afternoon. The 67.7% did it. The barrier for the rest is awareness, not cost.

How we measured this

FAQ

How long do TLS certificates last in 2026? Mostly 90 days. In our August 2026 census of 231.5 million certificates, 67.7% were issued for exactly 90 days and 87.5% for 200 days or fewer. The public-CA maximum is currently 200 days, stepping down to 100 days in March 2027 and 47 days in March 2029 (industry schedule).

Why are certificates getting shorter? Two reasons the industry gives: a stolen or mis-issued certificate is dangerous for at most its remaining lifetime, so shorter lifetimes shrink the damage window; and short lifetimes force renewal automation, which removes the human failure mode. Our data shows the second effect at scale — the 90-day cohort, 156.8 million strong, exists because machines renew it.

Can I still buy a one-year SSL certificate? Not from a public CA — the maximum issuable lifetime dropped to 200 days in March 2026 (industry context). The 11.5 million one-year certificates in our census — 5.0% of the total — were issued before the change and are expiring out of the population now.

What is the 47-day certificate rule? The CA/Browser Forum schedule caps new public certificates at 47 days from March 2029. Only 0.08% of certificates we observed already live at that rhythm, but the 67.7% on automated 90-day renewal will absorb the change invisibly. The cohort at risk is the roughly 18 million domains still on annual-or-longer certificates with, in many cases, manual renewal.

Do short certificate lifetimes mean I have to pay more? No. The dominant short-lifetime issuers are free, and ACME renewal automation is built into every mainstream web server and hosting panel. The 90-day majority of the web pays nothing for issuance. The cost of the short-lived web is an afternoon of setup, once.

What should I do about certificate lifetimes right now? First, find out how your certificate renews. If you cannot answer that question immediately, your renewal is probably manual — and manual renewal is the single biggest source of certificate expiry outages. Set up ACME-based automation (Let’s Encrypt via Certbot, Caddy’s built-in ACME client, or your hosting panel’s equivalent) and you inherit the 90-day default with zero ongoing effort. If you are on managed hosting or a CDN, check that auto-renewal is enabled; most platforms handle it silently, but the toggle is sometimes off by default on older accounts. For anything on a self-signed or multi-year certificate — admin panels, internal tools, legacy appliances — audit the expiry date today and set a calendar alert for 30 days before it. The 2029 deadline for 47-day renewals is not an excuse to defer: operators who automate now absorb every future cap reduction without noticing.

How does the 90-day certificate picture compare to last year — is this getting better or worse? The July 2026 census was our immediately prior round; the step from annual to 90-day certificates has been a multi-year trend rather than a single-cycle jump, so the August figures confirm a structural shift rather than a surprise. The most significant change visible in the August data is the emergence of the 197–199-day cluster — 45.9 million certificates — which did not exist as a major cohort before March 2026 when the 200-day cap took effect. The trend direction is clear: the automated short-lived web is growing, the manual long-lived web is mechanically expiring out of the population, and each CA/B Forum step tightens that dynamic further.

Why does certificate lifetime matter for business owners and non-technical managers? A certificate expiry is one of the few security failures that is immediately, publicly visible to every visitor on your site: browsers replace your homepage with a full-screen warning that tells customers your connection is not private. That warning kills conversions, triggers customer service calls, and can take hours to resolve if your renewal process requires a human. Increasingly, certificate lifetime is also a compliance signal — auditors and procurement teams use certificate hygiene as a proxy for operational maturity. Moving to automated short-lived certificates costs nothing and eliminates the risk entirely; staying on annual manual renewals means one missed calendar reminder stands between your business and a public outage.

What this means for IT managers, security teams, and business owners

The 47-day deadline in 2029 is not a distant abstraction — it is three CA/B Forum steps away, and the first step (100 days in March 2027) arrives in less than 18 months. For IT managers, this census report is a forcing function: every organisation that has not yet audited its certificate renewal process needs to do so before the 100-day cap lands. Start by inventorying every public-facing certificate — including those on subdomains, APIs, staging environments, and legacy applications — and confirm that each one renews automatically. The 90-day cohort, 156.8 million strong, has already solved this problem. Joining it requires one afternoon of setup, not a budget cycle.

Security teams should focus on the tail that the public-CA ecosystem cannot reach: self-signed certificates, private-CA-issued certificates on internal services, and long-lifetime certificates on appliances and embedded devices. These represent the 2.6 million certificates with lifetimes over 398 days in our census, and they are the cohort most likely to be forgotten until they cause an outage or a browser warning that trains users to click through. A certificate with a 10-year lifetime is not a security posture; it is a device nobody is watching. Include these in your certificate management scope even if they are not exposed to the public internet — lateral movement from an internal expired certificate is a documented attack vector.

For business owners without a technical team, the single most important action is to ask whoever manages your website one question: “What happens when our SSL certificate expires?” If the answer is anything other than “it renews automatically,” you have a manual renewal process, and manual renewal processes fail at scale. The annual certificate is dying because it requires a human to remember something once a year, every year, forever. Automation is free, reliable, and available from every mainstream hosting provider. The risk of ignoring this is a browser interstitial on your homepage at the worst possible moment — a prospect’s first visit, a press mention, a compliance audit.

Data to cite — TLS certificate lifetimes 2026

Pull-quote statistics from the defaults.exposed August 2026 Domain Security Census (432M domains). These figures may be cited verbatim with attribution.

“67.7% of 231.5 million live TLS certificates observed in August 2026 were issued for exactly 90 days — the automated-renewal default.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“87.5% of all live TLS certificates on the public web were issued for 200 days or fewer as of August 2026, meaning the web has already crossed into the short-lived certificate era.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“45.9 million TLS certificates — 19.8% of the web — now sit in a new 197–199-day cluster that did not exist as a major cohort before March 2026, when the public-CA maximum dropped to 200 days.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“Only 175,097 certificates — 0.08% of the web — already operate at the 47-day rhythm that becomes mandatory for public CAs in March 2029.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“11.5 million TLS certificates — 5.0% of the web — are still on one-year lifetimes, a product public CAs can no longer issue; every certificate in this cohort is expiring out of the population and will not be replaced at that length.” — defaults.exposed August 2026 Domain Security Census (432M domains)

“1.8 million live TLS certificates carry lifetimes of 10 years or more — lifetimes no public CA has been permitted to issue since 2020, indicating a large unmanaged tail of self-signed and private-CA material.” — defaults.exposed August 2026 Domain Security Census (432M domains)


Check your domain free at defaults.exposed — see exactly how your domain scores on certificate lifetime, automation, and 33 other externally observable security checks. Takes 30 seconds. No account needed. Read the flagship census report: The State of Domain Security 2026 →

Aggregate data only. Data stored and processed in the EU.


How to cite this report

Press / blog: defaults.exposed (2026). The 90-Day Web: Certificate Lifetimes in 2026. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/certificate-lifetimes-2026-the-90-day-web

Academic: defaults.exposed. (2026, August 18). The 90-Day Web: Certificate Lifetimes in 2026. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/certificate-lifetimes-2026-the-90-day-web

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=231,455,163 certificates)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026