| CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates. | 2027-03-15 | 3.2.2.4 and 3.2.2.5 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates. | 2028-03-15 | 3.2.2.4 and 3.2.2.5 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information. | 2025-01-15 | 3.2.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates. | 2026-03-15 | 3.2.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates. | 2025-07-15 | 3.2.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control. | 2026-03-15 | 3.2.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective. | 2026-03-15 | 3.2.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates. | 2027-03-15 | 3.2.2.5.3 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups. | 2026-03-15 | 3.2.2.8.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective. | 2026-03-15 | 3.2.2.8.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. | 2026-03-15 | 3.2.2.8.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified. | 2025-03-15 | 3.2.2.9 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Domain Name and IP Address validation maximum data reuse period is 10 days. | 2029-03-15 | 4.2.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Domain Name and IP Address validation maximum data reuse period is 100 days. | 2027-03-15 | 4.2.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Domain Name and IP Address validation maximum data reuse period is 200 days. | 2026-03-15 | 4.2.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Subject Identity Information validation maximum data reuse period is 398 days. | 2026-03-15 | 4.2.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657. | 2027-03-15 | 4.2.2.1.2 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 7565 | 2027-03-15 | 4.2.2.1.2 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix. | 2026-03-15 | 4.2.2 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements. | 2025-03-15 | 4.3.1.2 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance. | 2025-01-15 | 4.9.9 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Audit logs of verification activity MUST include specific information. | 2026-07-15 | 5.4.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements. | 2025-12-01 | 5.7.1.2 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Maximum validity period of Subscriber Certificates is 100 days. | 2027-03-15 | 6.3.2 | CA/Browser Forum TLS Baseline Requirements | Subscriber Certificates only |
| Maximum validity period of Subscriber Certificates is 200 days. | 2026-03-15 | 6.3.2 | CA/Browser Forum TLS Baseline Requirements | Subscriber Certificates only |
| Maximum validity period of Subscriber Certificates is 47 days. | 2029-03-15 | 6.3.2 | CA/Browser Forum TLS Baseline Requirements | Subscriber Certificates only |
| CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4. | 2026-03-15 | 7.1.2.4 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| Sunset all remaining use of SHA-1 in Certificates and CRLs. | 2026-09-15 | 7.1.3.2.1 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits. | 2025-03-15 | 8.7 | CA/Browser Forum TLS Baseline Requirements | all publicly-trusted CAs issuing TLS server certificates |
| A Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy. | 2026-06-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth. | 2027-03-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| All unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution. | 2027-03-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates, and issue Automation Test Certificates renewed at least once every 30 calendar days. | 2027-03-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| CA Owners MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as Usable or Qualified before issuing the corresponding certificate. | 2026-06-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program. | 2026-06-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| Root CA certificates with key material created between January 1, 2006 and December 31, 2007 (inclusive) will be removed from the Chrome Root Store. | 2026-04-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| Root CA certificates with key material created between January 1, 2008 and December 31, 2009 (inclusive) will be removed from the Chrome Root Store. | 2027-04-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| Root CA certificates with key material created between January 1, 2010 and December 31, 2011 (inclusive) will be removed from the Chrome Root Store. | 2028-04-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| Root CA certificates with key material created between January 1, 2012 and April 14, 2014 (inclusive) will be removed from the Chrome Root Store. | 2029-04-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| The Chrome Root Program will phase-out PKI hierarchies found in violation of subordinate CA extendedKeyUsage requirements. | 2026-06-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| The Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB. | 2027-03-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| The Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner. | 2027-09-15 | | Google Chrome Root Program | CAs included in the Chrome Root Store |
| For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in Mozilla's root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR). | 2027-07-01 | | Mozilla Root Store Policy | CA operators whose certificates are included in Mozilla's root store with the websites trust bit enabled |
| WebTrust "Principles and Criteria for Certification Authorities - Network Security" Version 1.7 permitted for audit periods ending before 2026-11-29; Version 2.0.5 required thereafter. | 2026-11-29 | | Mozilla Root Store Policy | CA operators whose certificates are included in Mozilla's root store |
| WebTrust "Principles and Criteria for Certification Authorities - SSL Baseline" Version 2.9 permitted for audit periods ending before 2026-11-29; WebTrust TLS Baseline Version 2.10 required thereafter. | 2026-11-29 | | Mozilla Root Store Policy | CA operators whose certificates are included in Mozilla's root store |