100-day TLS certificates
The public maximum is already 200 days. 100 days is next. 47 days follows.
The CA/B Forum caps
Publicly trusted TLS certificates are capped by CA/B Forum ballot, not by your ACME client. The dates that matter:
- Until 14 March 2026 the historical public max was 398 days.
- From 15 March 2026 the public max is 200 days. That is in effect now.
- From 15 March 2027 the public max is 100 days.
- From 15 March 2029 the public max is 47 days.
Let’s Encrypt and other public CAs will not issue longer than the cap in force on the issue date. Private PKI is a different world and is not covered here.
Renewals per year
A rough integer is enough for capacity planning: ceil(365 / max lifetime that year).
- 2026 at 200 days → 2 renewals/year
- 2027 at 100 days → 4 renewals/year
- 2029 at 47 days → 8 renewals/year
That is why a monitor that only emails once, a week out, gets worse every time the cap drops. There are more chances to miss a reload, and less calendar to recover.
What to do
Automate issuance (Certbot, lego, Caddy, or your CA’s ACME). Then monitor the live handshake, because automation fails in ways logs do not surface. Use the lifetime calculator if you want the 2026 / 2027 / 2029 numbers for a given issue date, and check a host if you want days remaining on the wire.
SSLert does not issue certificates. It tells you when the one you are actually serving will die.