Reference Source

TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

Forward-dated schedule of when each TLS certificate and certificate authority requirement takes effect, and which programme it binds. Each record is one requirement with its effective date, the Baseline Requirements section it amends, and the authority imposing it. Covers the CA/Browser Forum TLS Baseline Requirements effective-date table, the Google Chrome Root Program policy, and the Mozilla Root Store Policy. Answers 'when does the 200 day certificate lifetime take effect', 'TLS certificate maximum validity 100 days date', '47 day certificates 2029 timeline', 'when does domain validation reuse drop to 200 days', 'SC-081 phased schedule', and 'when do CAs have to do DNSSEC validation'. The dates changed recently and change again with every ballot, so an answer from model memory describes a world that has already moved; the maximum subscriber certificate validity drops to 200 days on 2026-03-15 and to 100 days on 2027-03-15, and the domain-validation reuse period and the subject-identity reuse period fall on different schedules to each other.

Records45
Sources3
Verified2026-08-05
Review by2026-11-03
LicenceFacts extracted from freely published governance documents. The CA/Browser Forum publishes the Baseline Requirements publicly for implementation; the Chrome Root Program policy and Mozilla Root Store Policy are published openly by their respective root programmes. Each record quotes a short verbatim span and links back to the document section.

The data

RequirementEffective dateBaseline Requirements sectionAuthorityScope
CAs MUST NOT rely on Methods 3.2.2.4.16, 3.2.2.4.17, 3.2.2.5.2, and 3.2.2.5.5 to issue Subscriber Certificates.2027-03-153.2.2.4 and 3.2.2.5CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT rely on Methods 3.2.2.4.4, 3.2.2.4.13, and 3.2.2.4.14 to issue Subscriber Certificates.2028-03-153.2.2.4 and 3.2.2.5CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT rely on HTTPS websites to identify Domain Contact information. CAs MUST rely on IANA resources for identifying Domain Contact information.2025-01-153.2.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT rely on Method 3.2.2.4.8 to issue Subscriber Certificates.2026-03-153.2.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT rely on Methods 3.2.2.4.2 and 3.2.2.4.15 to issue Subscriber Certificates.2025-07-153.2.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.2026-03-153.2.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with the validation of domain authorization or control by the Primary Network Perspective.2026-03-153.2.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT rely on Method 3.2.2.5.3 to issue Subscriber Certificates.2027-03-153.2.2.5.3CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated CAA record lookups.2026-03-153.2.2.8.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective.2026-03-153.2.2.8.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.2026-03-153.2.2.8.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST corroborate the results of domain validation and CAA checks from multiple Network Perspectives where specified.2025-03-153.2.2.9CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Domain Name and IP Address validation maximum data reuse period is 10 days.2029-03-154.2.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Domain Name and IP Address validation maximum data reuse period is 100 days.2027-03-154.2.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Domain Name and IP Address validation maximum data reuse period is 200 days.2026-03-154.2.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Subject Identity Information validation maximum data reuse period is 398 days.2026-03-154.2.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657.2027-03-154.2.2.1.2CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
If the CA does not identify the Subscriber account via an ACME Account URL as described in RFC 8555, the CA MUST define the supported format of the accounturi in Section 4.2 of their CP and/or CPS, and SHOULD comply with the acct URI scheme defined in RFC 75652027-03-154.2.2.1.2CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs SHALL NOT issue Certificates containing Domain Names that end in an IP Reverse Zone Suffix.2026-03-154.2.2CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
The CA SHALL implement a Linting process to test the technical conformity of the to-be-issued Certificate with these Requirements.2025-03-154.3.1.2CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Subscriber Certificate OCSP responses MUST be available 15 minutes after issuance.2025-01-154.9.9CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Audit logs of verification activity MUST include specific information.2026-07-155.4.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
CAs SHALL assert in section 5.7.1 of their CPS or combined CP/CPS their mass revocation plan, testing, and continuous improvements.2025-12-015.7.1.2CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Maximum validity period of Subscriber Certificates is 100 days.2027-03-156.3.2CA/Browser Forum TLS Baseline RequirementsSubscriber Certificates only
Maximum validity period of Subscriber Certificates is 200 days.2026-03-156.3.2CA/Browser Forum TLS Baseline RequirementsSubscriber Certificates only
Maximum validity period of Subscriber Certificates is 47 days.2029-03-156.3.2CA/Browser Forum TLS Baseline RequirementsSubscriber Certificates only
CAs MUST NOT use Precertificate Signing CAs to issue Precertificates. CAs MUST NOT issue certificates using the Technically Constrained Precertificate Signing CA Certificate Profile specified in Section 7.1.2.4.2026-03-157.1.2.4CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
Sunset all remaining use of SHA-1 in Certificates and CRLs.2026-09-157.1.3.2.1CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
The CA SHOULD use a Linting process to test the technical accuracy of already issued Certificates against the sample set chosen for Self-Audits.2025-03-158.7CA/Browser Forum TLS Baseline Requirementsall publicly-trusted CAs issuing TLS server certificates
A Chrome Root Program Participant's CP or combined CP/CPS MUST explicitly state adherence to the latest published version of this policy and the CCADB Policy.2026-06-15Google Chrome Root ProgramCAs included in the Chrome Root Store
All subscriber certificates MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.2027-03-15Google Chrome Root ProgramCAs included in the Chrome Root Store
All unexpired and unrevoked subordinate CA certificates signed by a root CA certificate included in the Chrome Root Store MUST be integrated with an automation solution.2027-03-15Google Chrome Root ProgramCAs included in the Chrome Root Store
CA Owners MUST disclose at least one (1) automation solution for each Baseline Requirements certificate policy OID appearing in unexpired and unrevoked subscriber certificates, and issue Automation Test Certificates renewed at least once every 30 calendar days.2027-03-15Google Chrome Root ProgramCAs included in the Chrome Root Store
CA Owners MUST ensure that all TLS server authentication precertificates issued by such CAs are logged to at least one (1) CT log recognized by Chrome as Usable or Qualified before issuing the corresponding certificate.2026-06-15Google Chrome Root ProgramCAs included in the Chrome Root Store
CA Owners with more than two (2) self-signed root CA certificates in the Chrome Root Store MUST submit a written consolidation plan to the Chrome Root Program.2026-06-15Google Chrome Root ProgramCAs included in the Chrome Root Store
Root CA certificates with key material created between January 1, 2006 and December 31, 2007 (inclusive) will be removed from the Chrome Root Store.2026-04-15Google Chrome Root ProgramCAs included in the Chrome Root Store
Root CA certificates with key material created between January 1, 2008 and December 31, 2009 (inclusive) will be removed from the Chrome Root Store.2027-04-15Google Chrome Root ProgramCAs included in the Chrome Root Store
Root CA certificates with key material created between January 1, 2010 and December 31, 2011 (inclusive) will be removed from the Chrome Root Store.2028-04-15Google Chrome Root ProgramCAs included in the Chrome Root Store
Root CA certificates with key material created between January 1, 2012 and April 14, 2014 (inclusive) will be removed from the Chrome Root Store.2029-04-15Google Chrome Root ProgramCAs included in the Chrome Root Store
The Chrome Root Program will phase-out PKI hierarchies found in violation of subordinate CA extendedKeyUsage requirements.2026-06-15Google Chrome Root ProgramCAs included in the Chrome Root Store
The Chrome Root Program will phase-out PKI hierarchies found issuing new certificates containing a Baseline Requirements certificate policy OID lacking an automation solution attestation disclosure in the CCADB.2027-03-15Google Chrome Root ProgramCAs included in the Chrome Root Store
The Chrome Root Store will only include a maximum of two (2) self-signed root CA certificates per CA Owner.2027-09-15Google Chrome Root ProgramCAs included in the Chrome Root Store
For each annual audit period beginning on or after July 1, 2027, each CA operator with a CA certificate included in Mozilla's root store with the websites trust bit enabled MUST obtain a Detailed Controls Report (DCR).2027-07-01Mozilla Root Store PolicyCA operators whose certificates are included in Mozilla's root store with the websites trust bit enabled
WebTrust "Principles and Criteria for Certification Authorities - Network Security" Version 1.7 permitted for audit periods ending before 2026-11-29; Version 2.0.5 required thereafter.2026-11-29Mozilla Root Store PolicyCA operators whose certificates are included in Mozilla's root store
WebTrust "Principles and Criteria for Certification Authorities - SSL Baseline" Version 2.9 permitted for audit periods ending before 2026-11-29; WebTrust TLS Baseline Version 2.10 required thereafter.2026-11-29Mozilla Root Store PolicyCA operators whose certificates are included in Mozilla's root store

Where this came from

Every record above links the page it was taken from and quotes the sentence that states it. These are the 3 sources this dataset was assembled from.

Machine-readable

45 records. last verified against source 2026-08-05. due for re-check by 2026-11-03.

Licence. Facts extracted from freely published governance documents. The CA/Browser Forum publishes the Baseline Requirements publicly for implementation; the Chrome Root Program policy and Mozilla Root Store Policy are published openly by their respective root programmes. Each record quotes a short verbatim span and links back to the document section.