In April 2025, the CA/Browser Forum unanimously approved Ballot SC-081v3, a measure that is reducing the maximum lifetime of publicly trusted SSL/TLS certificates from 398 days to just 47 days. The change is not theoretical. The first reduction already took effect in March 2026.
If your association manages its own website hosting, runs a member portal, or operates any web application that requires HTTPS, this affects you. Here is what changed, what is coming next, and what your organization should do about it.
What Changed and When
The reduction is happening in three phases, each one cutting the maximum certificate lifetime roughly in half:
Phase 1 (March 15, 2026): Maximum certificate lifetime dropped from 398 days to 200 days. This is already in effect. Any certificate issued after this date cannot be valid for longer than approximately six and a half months.
Phase 2 (March 15, 2027): Maximum certificate lifetime drops to 100 days. Domain validation information can only be reused for 100 days as well. At this point, your organization is renewing certificates at least three to four times per year.
Phase 3 (March 15, 2029): Maximum certificate lifetime drops to 47 days. Domain validation data can only be reused for 10 days. Manual certificate management becomes effectively impossible at this cadence.
The ballot was proposed by Apple and supported by Google, Mozilla, and Microsoft. Every major browser vendor voted in favor. This is not a proposal under debate. It is the new baseline requirement for every certificate authority in the world.
Why This Matters for Associations
Most association staff never think about SSL certificates. The certificate sits on the server, the browser shows a padlock, and everything works until it does not. The problem is what happens when a certificate expires.
An expired SSL certificate does not just remove the padlock icon. Modern browsers actively block visitors from reaching the site. Chrome, Firefox, Safari, and Edge all display full-page security warnings that tell visitors the connection is not secure and recommend they leave. Most visitors do leave. They do not call your office to report the issue. They simply go somewhere else. If your association relies on its website for member logins, event registration, donation processing, or any transaction that requires trust, an expired certificate is a full service outage.
Under the old 398-day maximum, an association could purchase a certificate once a year and not think about it again for twelve months. Under the new rules, that same organization needs to manage certificate renewals three to four times per year by 2027, and roughly every six weeks by 2029.
The Real Problem: Manual Renewal Does Not Scale
Many associations still renew SSL certificates manually. Someone on staff, or an IT contractor, logs into the hosting dashboard or certificate authority portal, generates a certificate signing request, validates the domain, downloads the new certificate, installs it on the server, and verifies that the site loads correctly. This process takes anywhere from fifteen minutes to several hours depending on the hosting environment and the technical skill of the person doing it.
When that process happens once a year, it is manageable. When it happens every 47 days, it is a liability. Every renewal is a window for human error. A missed email notification, an expired credit card on the CA account, a staff transition where nobody knows the login credentials — any of these turns a routine renewal into a site outage.
The CA/Browser Forum knows this. Apple explicitly stated in the ballot proposal that the industry has been telling organizations for years that automation is essentially mandatory for effective certificate lifecycle management. The 47-day timeline makes that statement impossible to ignore.
What Automation Looks Like
The solution the industry is converging on is ACME (Automatic Certificate Management Environment), the same protocol that powers Let's Encrypt. ACME automates the entire certificate lifecycle: domain validation, certificate issuance, installation, and renewal. When properly configured, certificates renew themselves with no human intervention.
Most modern hosting platforms already support automated certificate management. Pantheon, WP Engine, Kinsta, Platform.sh, and Acquia all handle SSL certificates automatically as part of their hosting service. If your association is on one of these platforms, you are likely already covered.
The risk is concentrated in three areas:
Self-managed servers. If your association runs its own web server (a VPS on DigitalOcean, an AWS EC2 instance, an on-premises server), you are responsible for setting up and maintaining certificate automation. This requires installing an ACME client like Certbot, configuring it to run on a schedule, and monitoring for failures.
Legacy hosting providers. Some older or budget hosting providers do not support ACME or automated certificate renewal. If your hosting provider requires you to manually upload certificates through a control panel, you will need to either switch providers or implement a workaround before 2027.
Complex multi-domain configurations. Associations often run multiple subdomains — members.yourorg.org, events.yourorg.org, learn.yourorg.org — each potentially with its own certificate. Automating renewal across all of them requires deliberate configuration and ongoing monitoring.
What Your Association Should Do Now
Audit your current certificates. Find out what SSL certificates your organization uses, where they are installed, when they expire, and how they are renewed. If nobody on your team can answer these questions confidently, that is a problem you should solve now rather than during the next renewal.
Confirm your hosting supports automated renewal. Contact your hosting provider and ask whether they support automatic SSL certificate renewal. If the answer is yes and it is already enabled, you are in good shape. If the answer is no, start evaluating alternatives.
If you manage your own server, set up ACME now. Do not wait until the 100-day deadline in March 2027. Install Certbot or your preferred ACME client, configure automatic renewal, and test a renewal cycle. Catching configuration issues now, while you still have months of buffer, is far better than discovering them when your certificate expires in 47 days.
Plan for the organizational knowledge gap. Certificate management is a technical operation. If the only person who understands your SSL setup is a part-time contractor or a board member who volunteers their IT expertise, your organization is one staff change away from a site outage. Document everything. Better yet, ensure your hosting or web partner handles it for you.
The Bigger Picture
SSL certificate automation is one piece of a much larger trend: website infrastructure is getting more complex, not less. Between certificate lifecycle management, security patching, CMS updates, AMS integration maintenance, and accessibility compliance, the technical overhead of operating an association website continues to grow.
This is precisely why more associations are moving toward partnership models with technical teams who handle this infrastructure continuously rather than treating each issue as a one-off support ticket. A web partner who monitors your certificates, manages your hosting, and ensures your infrastructure stays current eliminates the class of problems that shrinking certificate lifespans are about to create.
Our partnership plans are built for exactly this situation. Every plan includes infrastructure monitoring, certificate management, and proactive maintenance so your team can focus on serving members instead of troubleshooting SSL renewals.
Stop Fighting With Free Platforms
Our partnership plans give associations and nonprofits a dedicated web team without the overhead of hiring one. From ongoing maintenance to full-scale builds, every plan includes strategy, development, and support tailored to organizations like yours.