
That was the question at the center of ASEE’s contribution to HIKS CSC 2026, where Marijana Mišić Mikulić, Team Lead & Product Manager in ASEE’s Security & Compliance Business Unit, took part in the conference program with her presentation, “TLS Certificate Lifetimes Are Dropping to 47 Days: Do You Have a Plan?”
Held from September 28 to 30 in Osijek, the 10th Cybersecurity Conference organized by the Croatian Institute for Cybersecurity (HIKS) brought together cybersecurity professionals to discuss current security challenges, technologies, and approaches to building more resilient digital environments.
For ASEE, the conference was an opportunity to bring attention to a change that is already reshaping one of the less visible, but increasingly important, parts of cybersecurity infrastructure: TLS certificate management.
TLS certificates are essential for securing websites, applications, APIs, and other digital services. Yet certificate management has traditionally been something teams could handle through periodic renewals and expiration reminders.
That model is changing.
The maximum validity period for publicly trusted TLS certificates was reduced to 200 days in March 2026. It will decrease again to 100 days in March 2027, before reaching just 47 days in March 2029.
In other words, the industry is moving toward a model where certificates will need to be renewed far more frequently than many organizations are used to.
And that raises a practical question: can your current certificate management process keep up?
For organizations managing only a handful of certificates, shorter validity periods may seem relatively easy to accommodate. The challenge grows much larger when certificates span multiple domains, applications, servers, cloud environments, APIs, and business units.
At that scale, keeping track of expiration dates manually can quickly become difficult.
A spreadsheet may tell you which certificates exist today. A calendar reminder may tell you that one is approaching expiration. But neither necessarily provides continuous visibility into the entire certificate inventory or ensures that renewal and deployment happen on time.
As certificate lifetimes shrink, the margin for manual processes also shrinks.
The result is a shift from periodic certificate renewal to continuous certificate lifecycle management.
This was one of the key points at Marijana’s presentation at HIKS CSC 2026.
Preparing for 47-day certificates is not simply about setting more reminders. Organizations need to consider certificate discovery, monitoring, renewal, validation, and deployment across their environments, and how much of that process is doable with automation.
Automation can help security and infrastructure teams maintain visibility into their certificate inventory while reducing repetitive manual tasks and the risk of overlooked certificates.
It also changes the way teams can approach certificate management: instead of reacting when an expiration date is approaching, they can build a process designed to continuously manage the certificate lifecycle.
And the 47-day validity period is not the only change to consider. The CA/Browser Forum’s requirements also introduce shorter periods for reusing domain and IP address validation information, adding further pressure to make certificate issuance and renewal processes more efficient.
March 2029 may sound far away, but the transition has already started.
The reduction from 200 to 100 days and eventually to 47 days is not a change organizations will need to address overnight. It allows security and infrastructure teams to assess how certificates are currently managed, identify manual processes, and start moving toward greater automation.
For organizations with large or growing certificate inventories, that preparation can make the difference between a manageable operational change and an increasingly difficult renewal workload.
At HIKS CSC 2026, ASEE brought this topic into the wider cybersecurity conversation because TLS certificates may be small components of a much larger security infrastructure, but managing them at scale is becoming a challenge of its own.
The 47-day deadline is coming. The time to rethink certificate management is now.
To learn more about automated TLS certificate lifecycle management, visit Certiligent.