Calculator · BR 6.3.2 + 4.2.1 · SC-081v3 phase schedule
TLS Renewal Window Calculator — SC-081v3 phase schedule
Find the maximum certificate lifetime on any issue date, the next reduction, and how many renewals fall before a date you name.
Try:
Where do these dates come from?
The phase schedule is ballot SC-081v3, adopted by the CA/Browser Forum in April 2025 and written into Baseline Requirements sections 6.3.2 (maximum validity) and 4.2.1 (domain-validation reuse). Each step-down is a record here carrying the verbatim line from the BR effective-date table. Browse all 45 requirements.
Why does the SHOULD NOT number differ from the MUST NOT?
The BRs state both: certificates issued from 2026-03-15 SHOULD NOT exceed 199 days and MUST NOT exceed 200 days. Same pattern at each step (99/100, 46/47, 397/398). This is why DigiCert issues 199-day certificates, not 200 — the one-day gap is in the rule, not vendor caution.
What does this not cover?
Your CA may issue shorter certificates than the BR maximum (DigiCert cut to 199 days three weeks early; Let's Encrypt issues 90 or 45 days by profile). This calculator shows the BR ceiling — the longest any publicly-trusted CA is allowed to issue. It does not model ACME renewal timing, grace periods, or automation tooling.
About the phase schedule
The CA/Browser Forum's ballot SC-081v3 reduces maximum TLS certificate lifetime in three steps: 200 days from 2026-03-15 (in force now), 100 days from 2027-03-15, and 47 days from 2029-03-15. The domain-validation reuse period drops on the same dates but falls further — to just 10 days from 2029-03-15 — which is the number that decides whether a human can stay in the renewal loop. Both schedules are from BR sections 6.3.2 and 4.2.1. See every dated requirement.