Reference Source

What changed — TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

The change history of TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla): Forward-dated schedule of when each TLS certificate and certificate authority requirement takes effect, and which programme it binds. Each record is one requirement with its effective date, the Baseline Requirements section it amends, and the authority imposing it. Covers the CA/Browser Forum TLS Baseline Requirements effective-date table, the Google Chrome Root Program policy, and the Mozilla Root Store Policy. Answers 'when does the 200 day certificate lifetime take effect', 'TLS certificate maximum validity 100 days date', '47 day certificates 2029 timeline', 'when does domain validation reuse drop to 200 days', 'SC-081 phased schedule', and 'when do CAs have to do DNSSEC validation'. The dates changed recently and change again with every ballot, so an answer from model memory describes a world that has already moved; the maximum subscriber certificate validity drops to 200 days on 2026-03-15 and to 100 days on 2027-03-15, and the domain-validation reuse period and the subject-identity reuse period fall on different schedules to each other.

Change dates1
Tracked since
Last change

No changes yet since the initial snapshot of . This register is re-checked against its sources on a schedule; a date appears below only when records were added or their values changed, so a quiet stretch means the register itself was quiet, not that nobody looked.

We keep the current verified state of each record, not the value it replaced — so each entry says which records changed and what they now state, never what they said before. Machine subscribers: poll changes.xml (Atom) or changes.json instead of re-fetching the dataset.

— Initial snapshot — 45 records

The first verified snapshot: every record was new on this date. The full register is on the dataset page.

… and 25 more records on this date. The full current state of every record is in data.json.