Security1 publisher2 min readPublished
Shrinking public TLS certificates to 47 days turns a 1,000-certificate estate into 21 renewals a day
DigiCert's survey of IT and security leaders puts a price on the outages that certificate expiry already causes, and it shows how unevenly enterprises are preparing for the 47-day deadline in 2029.
The Watch · Security desk

What happened
- Public TLS certificates drop to 47-day lifetimes by 2029, and DigiCert's Certificate Management Outlook says enterprises will renew more than eight times as often and run 40 times as many domain validations.
- 34% of surveyed companies have already had a service outage caused by an expired certificate, and 40% reported downtime linked to certificate mismanagement.
- Nearly three-quarters of respondents logged at least five hours of certificate-related downtime in the past year, and 21% logged 25 hours or more.
- 57% of respondents file certificate outages as IT infrastructure issues and 17% treat them as security incidents.
- 70% say they are preparing for shorter lifespans, the rest are aware of the change and have not started, and U.S. organizations are further along than those in the U.K. and Australia.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost Nearly one in four organizations already own a certificate incident that cost more than $250,000.
- constraint 49% of respondents already touch certificate work at least 12 times a year; at 47-day lifetimes it becomes a standing weekly task for anyone still renewing by hand.
- decision DevOps integration, visibility and compliance all rank above automated renewal on the next 12 months of certificate work, so the first spend is discovery and pipeline integration, not a renewal client.
- exposure Nearly three-quarters expect certificate volumes to rise over the next two years, so the 47-day multiplier will apply to a larger estate than the one being counted now.
Forty-seven days is 7.8 renewals per certificate per year [1]. More than half of the organizations in DigiCert's Certificate Management Outlook manage more than 1,000 digital certificates [9]. An estate that size on 47-day lifetimes issues about 7,800 certificates a year, roughly 21 a day [2].
Renewal frequency rises more than eightfold [2]. Domain validation rises fortyfold [3], about five times faster than issuance [3]. Help Net Security's summary of the report does not include the validation reuse window behind that figure or the survey's respondent count [4].
A certificate expires, the service stops answering, and the first notice often comes from a customer. No attacker is involved. "An expired certificate can shut down a critical service just as quickly as any other infrastructure failure," said Mike Nelson, Global Vice President, Field CTO at DigiCert [14]. "With certificate lifecycles shrinking to 47 days, spreadsheets and calendar reminders simply won't scale," he said [15].
52% of respondents said managing internal and external systems at the same time is a concern, which the report attributes to certificates being spread across different platforms and environments [11].
The numbers are the vendor's own, and the report's advice is that companies prepare by automating more of the certificate lifecycle [21]. Inside the same survey, automated certificate lifecycle management ranks third among cybersecurity priorities, behind AI-powered security operations and software threat detection and response [17].
The CA/Browser Forum is shortening lifespans to improve Web PKI security: shorter certificates keep certificate and validation information current and cut the period in which a compromised or outdated credential remains valid [16]. Subscribers absorb that as renewal frequency [2].
What to watch
- Whether DigiCert publishes the respondent count and methodology behind the $250,000 incident figure.
- The domain validation reuse window that produces the 40x number, once the full report is out.
- Whether U.K. and Australian organizations close the preparation gap DigiCert reports against U.S. firms before 2029.