SSL / TLS December 12, 2025

Change in TLS/SSL certificate validity as of February 2026

As of February 24, 2026, TLS/SSL certificates will have a maximum validity period of 199 days. The change responds to a new requirement from the CA/Browser Forum and aims to strengthen digital security globally.

Cambio en la vigencia de certificados TLS/SSL a partir de febrero de 2026

As of February 24, 2026 , certificates TLS/SSL issued through DigiCert CertCentral will have a maximum validity period of 199 days , instead of the current 397 days.
This modification also applies to the EU Qualified Website Authentication Certificates (QWAC) and to QWAC PSD2.

The reduction in certificate validity is a measure defined at the industry level , established by CA/Browser Forum , with the objective of improve security , limit the impact of possible compromised keys and allow more agile cryptographic update against new threats and standards.

While shorter validity periods may require adjustments in certificate management, they also contribute to reduce risks and increase resilience of digital environments . From CertiSur accompanies our clients to anticipate and adapt to this change.

Impact on TLS/SSL certificates

  • It will be possible to request certificates with validity periods greater than 199 days until February 24, 2026.

  • All certificates issued as of that date will have a maximum validity of 199 days , even if the original order contemplates a longer period.

  • Pending requests issued from that moment will be will adjust automatically to the new validity.

  • Certificates issued issued before February 24, 2026 will not be affected and will maintain their original expiration date.

  • However, if a certificate is reissued from that date, its validity will be limited to 199 days , although it was originally longer.

Changes in organization and domain validations

As of February 24, 2026 the validation reuse periods will also be modified:

  • The organization validations (OV) will change from 825 to 397 days.

  • The domain validations will be reduced from 397 to 199 days.

Impact on API requests

Certificate requests made through the CertCentral API with a validity greater than 199 days will be will adjust automatically to the new limit. This measure seeks to prevent unexpected errors and ensure the correct issuance of certificates.


From CertiSur we recommend to organizations anticipate this change , review their certificate management processes and advance in strategies for automation that facilitate future renewals.

Our team is available to advise you and help you assess the impact of this update on your digital environments. If you have any questions, contactar a nuestro equipo de support.