FreeNo signup, no email

47-day certificate readiness check

Public TLS certificate lifetimes are being cut to 47 days: 200 days now, 100 from March 2027, 47 from March 2029, and Let’s Encrypt reaches 45 days a year earlier. This 47-day certificate readiness check reads the certificate a host serves, tells you whether it is renewed by automation or by hand, and counts the hand renewals a year each ceiling implies.

No signup. No email. Live TLS read of the certificate visitors get, and whether it is renewed by hand.

What the check covers

Automated or by hand

A certificate of 100 days or fewer is only issued through ACME, so a client renews it. A longer one from a commercial CA with no sign of a regular cadence is renewed by a person, and every hand renewal is a chance to miss one.

Hand renewals a year, on the real schedule

For a certificate renewed by hand: how many times a year at today’s 200-day ceiling, at 100 days from 15 March 2027, and at 47 days from 15 March 2029. The dates are the CA/Browser Forum’s, not ours.

The certificate that is actually served

The check reads the live certificate from outside, the way a visitor does: its issuer, its lifetime and its expiry. Not what a CA portal says you bought.

Common questions

What is the 47-day certificate change?

The CA/Browser Forum, which sets the rules browsers and certificate authorities follow, voted to cut the maximum lifetime of a public TLS certificate to 47 days. The cut is staged: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. Let’s Encrypt is moving faster: its default certificates go to 64 days on 10 February 2027 and 45 days on 16 February 2028.

Why does it matter whether a certificate is renewed by hand?

A one-year certificate renewed by hand is one calendar reminder a year. At 47 days it is eight, and a missed one is an outage. Anything renewed by hand today needs automation, or an internal CA for hosts that cannot do ACME, before the ceiling reaches it.

How do you tell automation from a hand renewal?

By lifetime and issuer. Certificates of 100 days or fewer only come through ACME, so they are automated. Longer certificates from a commercial CA are usually renewed by hand unless the host’s renewal history shows the regular cadence automation produces, or you tell CertPost the host renews itself.

Does this check devices inside my network?

No. It reads what a host serves to the internet. Firewalls, printers, load balancers and other internal appliances that cannot run an ACME client need an internal certificate authority; the 47-day rule applies only to publicly trusted certificates.

Monitor this certificate free

One check now, or every day from now on.

3 certificates free forever · No agent · No credit card