Cert Renewal ForecastGuide

100-day certificates from March 2027: find the ones you renew by hand

Updated 2026-10-10 ยท by Hieu Tran, written with AI agents and checked against the sources below

Public TLS certificates issued from 15 March 2027 can last at most 100 days, and from 15 March 2029 at most 47 days (CA/Browser Forum ballot SC-081v3). Let's Encrypt moves its default to 64 days on 10 February 2027. Certificates renewed by an ACME client won't notice. The ones someone buys, downloads and installs by hand will need doing three to four times as often.

Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar

Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.

The dates

Step 1: list every public certificate you have

Every publicly trusted certificate is published in Certificate Transparency logs. Search your domain on crt.sh or SSLMate's Cert Spotter and you'll see the ones you've forgotten too: VPN gateways, mail servers, phone systems, old marketing sites.

Step 2: separate automated from manual

Step 3: automate what you can, calendar the rest

  1. Web servers: certbot or acme.sh on Linux, win-acme or Posh-ACME on Windows/IIS. Most commercial CAs offer ACME with External Account Binding (EAB).
  2. Appliances: check your firmware. F5 BIG-IP 21.1 added native ACME (HTTP-01 only); NetScaler Console supports ACME with DNS-01; Cisco Expressway has ACME; PAN-OS uses SCEP rather than ACME.
  3. Exchange and IIS bindings: after renewal, check the certificate is bound to the right sites and services (SMTP, IIS). A renewal that isn't bound is still an outage.
  4. Everything still manual: put each renewal on a shared calendar, 14 days before expiry, with an owner. Let's Encrypt stopped sending expiry emails in 2025, so don't count on the CA to remind you.

Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar

Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.