Key Technical Changes for SSL and Code Signing in 2026

The SSL industry is facing three major technical changes in 2026, dictated by the CA/Browser Forum. These changes affect everything from standard website certificates to software signing.

1. Reduction of SSL Lifetime to 47 Days

The most significant change is the phased reduction of SSL certificates' technical validity. From March 15, 2026, the maximum lifetime will be reduced to 200 days, in 2027 to 100 days, and in 2029 down to 47 days.

Sep 2020
398 days
Mar 2026
200 days
Mar 2027
100 days
Mar 2029
47 days

What does this mean for you? Your 1-year order period still covers all technical issuances, but the certificate must be installed more frequently on the server. We strongly recommend automation to handle the more frequent changes.

See the detailed timeline for SSL lifetime here →

2. Code Signing Limited to 15 Months

Code signing certificates (both standard and EV) have historically been issuable for up to 3 years. From February 24, 2026, this limit will be reduced to a maximum of 459 days (approx. 15 months) across all global issuers like DigiCert and GlobalSign.

The goal is to increase security by ensuring that private keys stored on hardware tokens are verified more often.

3. Removal of Client Authentication (EKU)

The CA/Browser Forum has decided that "Client Authentication" Extended Key Usage (EKU) will be removed from public SSL/TLS certificates. The change takes effect during 2026 (DigiCert from May 1).

If you use your SSL certificates to log in to VPNs, authenticate against an API, or similar "mutual TLS" (mTLS) scenarios, you will need to use dedicated client certificates instead of standard SSL certificates in the future.

Need Help?

At FairSSL, we are specialists in handling these changes. We advise on the right products and ensure that your setup is future-proof. Create an account or contact our support to learn more.