Published on August 28, 2026 · The mitza.es team

Since March 12, 2026, any new SSL/TLS certificate is issued with a maximum validity of 199 days, compared to the longer periods that were standard until now. It's a technical change that goes unnoticed by most businesses, but it can become a real problem if nobody keeps track of renewal.
Who decides this, and why
The rule is set by the CA/Browser Forum, the consortium that brings together certificate authorities and the major browser makers, and whose job is to set standards so certificates work reliably across all browsers. In Spain, FNMT-RCM, as a certificate authority, applies the same schedule as the rest of the industry.
A gradual cut, not a one-time change
This adjustment to 199 days is only the first step of an already defined schedule: in 2027 a further reduction to around 100 days of validity is expected, roughly a quarterly renewal, and by 2029 the validity period would drop to just 47 days. The underlying trend is clear: certificates are going to require increasingly frequent renewal.
What happens to certificates you already have
If your certificate was issued before March 12, 2026, you don't need to do anything for now: it remains valid until its original expiry date. The change only affects certificates issued from that date onward, and from there, each subsequent renewal.
Why this change matters more than it seems
- An expired certificate makes browsers show "not secure" warnings to your visitors, with the direct impact on trust and conversion that implies.
- With renewals becoming ever more frequent, relying on manually remembering stops being a reasonable option.
- The trend toward shorter lifecycles aims to reduce the risk of compromised certificates, but it shifts the management burden onto whoever maintains the website.
The real solution: automate renewal
The sensible way to adapt to this schedule isn't setting increasingly frequent manual reminders, but having renewal automated from the start, something that's already part of good technical maintenance for any website. It's the same underlying approach we apply with the critical security updates we've been covering this year: the key isn't reacting in time every single time, but resolving it structurally. Our IT maintenance service includes a review of these aspects, and if you want a full audit of your website's technical security, you can request a tailored audit.