News

The SSL Certificate Risk Report: why shorter lifecycles are making automation essential

Andrew J Moore
By Andrew J Moore
Published 08 October 2026
Preparing audio The SSL Certificate Risk Report: why shorter lifecycles are making automation essential
--:--

It’s now been six months since the beginning of the planned step down from 398-day SSL renewals to the final 47-day renewal window. In theory, that means that a large share of SSL certificates are now on a 200-day renewal cycle, and more importantly, we are now only six months away from the reduction to 100-days. That’s when the increased cadence of the renewals will start to bite. So, it’s a good time to take stock of what the environment is like out there.

We went through the SSL certificate orders placed with us across 2025 and the first quarter of 2026 to try and get a feel for what the current state of affairs is with SSL/TLS certificates, and what it reveals about the risks that brands are exposed to.

The result is The SSL Certificate Risk Report, and the short version is this: a lot of certificate estates are still built for a world that stopped existing in March.

Certificate management has become about business risk

At the moment, SSL/TLS gets filed under security, which made sense when the job was encrypting traffic and little else. That is, unfortunately, now out of date. Due to all the browsers moving to requiring HTTPS, certificates have become what makes your websites, your APIs, your customer portals and your internal services reachable and trusted. When one expires, all of that ceases functioning.

And it doesn’t break in a quiet way. Instead, it’s loud. Internal functions stop working, while customers see a browser warning telling them your site isn’t safe, which isn’t something any brand wants. All of which means that somebody has to drop everything to fix it urgently.

Which is a dramatic way of saying: Certificate lifecycle management is now a brand problem. It’s a business risk problem. It’s not something that you can fail on, and so it’s something you need a robust plan for.

The shortening SSL/TLS lifecycle

This is doubly true because the clock is already running, and the move of certificate management from an occasional job to one on a strict cadence is already well underway. As we mentioned before, SSL certificate maximum validity dropped from 398 days to 200 days on March 15, 2026. It falls to 100 days in March 2027, and to 47 days in March 2029. At the same time, domain control validation reuse periods are shrinking on the same curve, from 367 days all the way down to a mere 10.

All that means that, at 47 days, you are renewing every certificate you own roughly eight times a year. (We covered the full timeline and the reasoning behind it in our guide to how shorter SSL/TLS certificate lifetimes will impact your business, so we won’t repeat it all here.)

That’s why we commissioned this report. Because every manual step in your renewal process is about to be performed eight times more often, it pays to know what sort of SSL certificates serious businesses (the type who are the clients of BrandShelter) are using. And knowing that, what it says about how prepared we all are for what’s coming.

What our client data shows

We’re not going to regurgitate the entire report here, because it’s worth taking a look at it yourself, but there are two headline stats that we think are particularly interesting.

81.3% of certificates are DV

Among our customers, Domain Validation certificates dominate. This shouldn’t be surprising, as DV is cheaper, faster to issue, and consumer browsers stopped visibly distinguishing between DV, OV and EV years ago. The business case for paying more just hasn’t been there, and most organizations have quite reasonably chosen less cost and less effort.

This isn’t a problem: DV certificates work. They’re simple. Prove that you control the domain, and you’ll get it reissued. And this is even more efficient when you consider that domain control validation and the separate OV/EV checks (to prove you are the organization you say you are) are desyncing during the SSL certificate stepdown, creating a logistical mess. So, 81.3% of companies being on DV makes sense, especially as these operations get more complicated.

Except it’s never that simple, is it? Because that efficiency and lower price have a cost. And that cost is on the security end. All DV confirms is that somebody controls a domain at a given moment. It doesn’t confirm who they are, which is exactly why criminals running phishing and lookalike sites find DV so convenient. Whether that cost is worth the extra hassle comes down to how much effort a company is willing to put into managing it.

54% of organizations use certificates from more than one CA family

This finding is the one that might come up in an infrastructure review. Slightly more than half of the organizations in our data are running certificates from multiple certificate authorities. And that, unlike the DV certificates, is a problem.

This is because of what we call certificate fragmentation. It results in different renewal workflows, different validation methods, different support and billing processes, and confusion over who, exactly, is the official owner of each certificate. In short, it’s messy.

These situations come about because of entropy. Just the gradual accumulation of certificates over time, each individually acquired as projects require them, or via acquisition of another company’s workflows. And that entropy creates its own inertia, meaning a little more effort is required to get renewals right. Which matters a great deal when renewals are going to be running every six or seven weeks. Fragmentation isn’t a risk on its own. It’s a multiplier on every other risk you have.

This is no one’s fault, but it is something you probably want to fix.

The full report goes further into this, including how many organizations are spread across three or more CA families, and how the mix of single-domain, wildcard and multi-domain certificates affects the total number of events a team has to track. Download the full SSL Certificate Risk Report to see the complete data set. [LINK: report download]

Automation is the only version of this that scales

The key conclusion from our own data is that your SSL infrastructure is better measured in events than in certificates. Every issuance and every renewal has to land correctly, every time, forever. Certificates are not getting more numerous nearly as fast as they are getting more frequent.

There’s no clever manual process that survives the move to 47 day certificate lifecycles. You have to go away from manual ordering and manual renewal tracking, toward API-driven issuance and centralized overviews of all your certificates.

That’s why we built our SSL API with ACME protocol support, so it works with the tooling your teams already use. Not merely because we think it’s a product that will be nice for our customers to have, but because it’s a product that our customers will require. If your operator doesn’t have it, you will need to move to one that does.

Because regardless of who you buy from, organizations that get automation-ready before 47-day certificates arrive will find 2029 uneventful. Those that don’t will spend that April rapidly working out how to do it, while also putting out fires.

Get the full report

The SSL Certificate Risk Report covers what we found across our customers’ certificates in 2025 and Q1 2026: the full data on DV dependence, CA fragmentation and certificate scope, the six business risks that poor certificate lifecycle management creates, and what an automation-first model looks like in practice.

It’s short, and it will tell you fairly quickly whether your own SSL certificates look like the ones that are about to have a problem.

Download The SSL Certificate Risk Report here.

Share article
A person typing on a laptop