Certificate Lifecycle Management (CLM)

47-day certificates are coming. Is your team ready?

As of March 2026, public TLS certificate lifetimes dropped to 200 days, and they keep shrinking. Organizations that prepare now won’t scramble later. Find out in three minutes where you stand.

For CIOs, CISOs and IT leaders responsible for public certificates.

Maximum TLS certificate lifetime
Before
398 days
2026
200 days
2027
100 days
2029
47 days

8× more renewals by 2029. Manual renewal becomes impossible at scale.

The deadline

Three dates every certificate owner should know

In effect now

March 2026

Maximum TLS certificate lifetime drops to 200 days.

Less than 12 months away

March 2027

100 days. Renewals double in frequency.

Act now

March 2029

47 days. Manual renewal becomes impossible at scale.

Preparing now gives your team time to adapt, automate and stay ahead. Don’t wait until certificate renewals become a daily challenge.

The problem

Why this matters

More renewals by 2029

Going from 398-day to 47-day lifetimes multiplies renewal work 8-fold. Most teams are not ready for this.

73%

Of certificate outages are preventable

They happen because no one had a complete, live view of what was about to expire.

1

Person holds the knowledge

In most organizations, certificate knowledge lives in one person’s head or one spreadsheet: a single point of failure.

Free CLM Readiness Assessment

How ready is your team? Find out in three minutes.

Sixteen questions show exactly where you stand on visibility, ownership, process and automation, with an honest score and recommended next steps. 16 questions · about 3 minutes · results immediately.

Public certificate management is changing.

Certificate lifecycles are becoming shorter. Renewal activity is increasing. Public certificates are often spread across multiple systems, teams and Certificate Authorities — a growing operational challenge that requires better lifecycle management and visibility.

1
VisibilityDo you know where your certificates live?
2
OwnershipIs responsibility clearly assigned?
3
ControlAre renewals and new certificates managed, or improvised?
4
SimplicityCan teams find what they need, fast?
5
Future readinessWill your process survive more frequent renewals?

There are no right or wrong answers. The objective is simple: discover whether your organization is operating with certainty or assumptions.

Where can we send your results?

Fill in your details and see your readiness score right away.

We only use your details to share your results and follow up on your assessment.

0%

Your CLM readiness score

Your recommended actions

    Final reflection — before moving on, ask yourself one last question:

    Are you absolutely certain you know which public certificate will expire next?

    If the answer is anything other than an immediate “yes”, there is value in gaining more clarity. Not because you should worry — because certainty is better than assumptions.

    You don’t have to fix this manually. BlueX Online does the heavy lifting.

    BlueX Online is AET Europe’s certificate lifecycle management platform, built to solve exactly the gaps in your report:

    Automatic discovery of every certificate
    One central overview of owners & expiry dates
    Automated renewals before anything expires
    Ready for 47-day lifecycles

    In a free consultancy call we walk through your scores together and show you what BlueX Online would automate for your organization.

    Or call us directly: +31 26 365 33 50

    Because digital trust should feel simple, predictable and under control.

    The solution

    How CLM works: 3 steps from chaos to full control

    1

    Discover everything

    We map your entire certificate estate. What you have, where it lives, when it expires. Most organizations find certificates they did not know existed.

    2

    Get clear insight

    One view of every certificate, owner and expiry date. No spreadsheets, no guesswork, just a clear picture of where you stand.

    3

    Automate the rest

    Renewals happen automatically before certificates expire. No manual tracking, no last-minute scrambles, no outages.

    Interested in early access to BlueX Online?

    BlueX Online is AET Europe’s certificate lifecycle management platform — built to give your team full visibility and automated control over every certificate in your environment.

    Learn more

    Insights on shrinking certificate lifetimes

    Insights

    Certificate Chaos: How Shrinking Validity Windows Are Exposing Critical Gaps for CISOs

    Digital certificates protect everything from websites to critical infrastructure, yet shrinking validity creates unseen risk.

    Read the article →

    Insights

    TLS Certificate Lifetimes Are Already Changing: What Your Team Needs to Do Now

    How digital trust depends on discovering, managing and renewing certificates before failures occur.

    Read the article →

    Updates

    New release of SafeSign IC 4.7.0.0

    We are happy to announce the release of SafeSign IC 4.7.0.0.

    Read the article →

    Free e-book

    Are you absolutely certain you know which public certificate will expire next?

    A calm, practical guide to understanding your CLM readiness. What is inside:

    • Why shorter lifecycles change the game for every team
    • The three questions every CIO and CISO should ask
    • Signs you may need better lifecycle management
    • What BlueX Online delivers, in time and money

    FAQ

    Frequently asked questions

    What happens when a certificate expires?

    Browsers and systems immediately stop trusting it — there is no gradual degradation. Services show security warnings, APIs refuse connections, and applications break without warning.

    Why are certificate lifetimes getting shorter?

    The CA/Browser Forum, backed by Apple, Google, Microsoft and Mozilla, has mandated shorter lifetimes to reduce the risk of compromised certificates being exploited. As of March 2026, the maximum is 200 days. By 2029 it will be 47 days.

    What changed on March 15, 2026?

    Newly issued public TLS certificates may be valid for a maximum of 200 days. This drops to 100 days in March 2027, and 47 days in March 2029.

    What is BlueX Online?

    BlueX Online is AET Europe’s certificate lifecycle management platform. It is designed to give organisations full visibility and automated control over their certificate estate.

    How can AET Europe help us prepare?

    Start with the free CLM Readiness Assessment on this page. Our specialists can then review your current certificate setup, assess your exposure to the 2026 deadline, and advise on the right approach for your organisation.

    Ready to talk?

    Not sure where to start? Let’s talk.

    Our specialists can review your current certificate setup, walk you through what the 2026 changes mean for your organisation, and show you what AET Europe is building to help.

    Or call us directly: +31 26 365 33 50

    Not ready yet?

    Get clarity first, at your own pace

    Start with the three-minute readiness check, or take the e-book with you for your team and board.