The way SSL/TLS certificates are managed is changing.
Since 15 March 2026, publicly trusted SSL/TLS certificates issued or reissued under the new industry requirements have a maximum validity of 200 days. On 15 March 2027, that maximum will fall to 100 days. From March 2029, it will be reduced further to 47 days.
For hosting providers and other digital service providers managing certificates at scale, this means one thing in particular: certificate lifecycle events will happen more often.
More frequent certificate requests and renewals do not, however, have to result in more manual work.
Shorter certificate lifetimes help improve security by reducing the period in which outdated certificate information or compromised key material can remain usable.
But they also change the operational side of SSL management.
When certificates have to be renewed more frequently, processes based on calendars, reminders, support tickets or other manual actions become harder to maintain at scale. Each additional manual step also creates another opportunity for a renewal to be delayed or missed.
This makes now a good time to review how certificates move through your infrastructure.
Where are requests and renewals still handled manually? Which systems already support automation? And what will your current workflow look like when the maximum certificate validity falls to 100 days next year?
ACME, or Automated Certificate Management Environment, is a standardised protocol for automating certificate requests and renewals.
Instead of manually requesting a new certificate each time one approaches expiry, an ACME client can communicate with the certificate provider and handle supported certificate lifecycle actions automatically.
At Realtime Register, you can create an ACME subscription for a supported SSL product and specify the domains it may cover. We provide the Directory URL and External Account Binding credentials required to connect the subscription to an ACME client.
This means supported commercial SSL certificates can become part of the ACME-enabled platforms, control panels and deployment processes you or your customers already use.
The ACME client remains in your or your customer's environment, so you stay in control of its configuration, renewal schedule, deployment and monitoring.
ACME is available for supported SSL products across the Realtime Register portfolio.
This includes supported products from PerfectSSL, Sectigo, DigiCert, GeoTrust, Thawte and RapidSSL.
Depending on the selected product and brand, this can include Domain Validation (DV), Organisation Validation (OV) and Extended Validation (EV) certificates.
Note: ACME automates certificate requests and renewals, but it does not remove the validation requirements associated with a certificate. DV certificates still require proof of domain control, while OV and EV certificates continue to require the applicable organisation validation.
The goal is not to bypass these trust requirements. It is to remove unnecessary manual steps from the certificate lifecycle around them.
We are also making it easier for hosting providers using WHMCS to integrate ACME into their existing commercial workflow.
Version 2.0.0-beta of the Realtime Register WHMCS SSL Addon introduces support for creating and selling ACME subscription products for supported DigiCert and Sectigo DV and OV products.
Hosting providers can configure supported products and pricing, including capacity for domains and wildcards. Customers can purchase and manage their subscription through WHMCS and retrieve the credentials required to connect their preferred ACME client.
WHMCS handles the product, subscription and commercial side of the process. The ACME client continues to handle certificate lifecycle automation within the service provider's or customer's own environment.
As this functionality is currently in beta, we recommend testing the workflow in a controlled environment before a wider rollout.
The move to shorter certificate lifetimes is already underway.
That does not mean every existing SSL workflow needs to be replaced. Realtime Register also supports other automation models, including DigiCert AuthKey for partners working directly with our SSL Lifecycle API.
What matters is understanding where certificate lifecycle control should sit within your infrastructure and reducing unnecessary manual dependencies where possible.
Start by reviewing where certificate requests, renewals and deployments still require manual intervention. Identify which environments already support ACME and test automation with a controlled selection of domains and supported SSL products.
By the time the maximum validity falls to 100 days in March 2027, a more automated certificate lifecycle will become increasingly valuable.
Every SSL environment is different. If you are unsure where to start with automation or which approach best fits your infrastructure, our team can help you explore the available options and find a setup that works for your business.
Shorter certificate lifetimes mean more frequent renewals. With the right automation in place, they do not have to mean more manual work.