Update: The 397-day limit described below was the first step in a longer industry timeline. Since March 11, 2026, SSL.com has issued SSL/TLS certificates under a shorter 198-day validity period per CA/Browser Forum Ballot SC-081v3, with a further reduction to 100 days beginning March 15, 2027 and to 47 days beginning March 15, 2029. Your annual service term and billing are not affected. See SSL Certificate Validity Changes: What You Need to Know for the current rules.
Publicly trusted SSL/TLS certificates issued on or after September 1, 2020 with a validity period greater than 398 days will not be trusted by Apple’s Safari browser and iOS/iPadOS/watchOS/tvOS devices.
In response, at a time to be determined in August 2020, SSL.com will limit the lifespan of SSL/TLS certificates to a maximum of 397 days, as recommended by Apple. This will ensure that all certificates issued by SSL.com will continue to be trusted on Apple’s devices and software.
Yes. This article covers the September 2020 change to 397 days. Since March 11, 2026, SSL.com issues certificates for 198 days under CA/Browser Forum Ballot SC-081v3, with further reductions to 100 days (March 2027) and 47 days (March 2029) already approved. Your annual service term and billing cycle are not affected.
When do I need to update my server’s current SSL/TLS certificate to comply with the new 398-day limit?
If your certificate was issued before September 1, 2020, it will not be affected by Apple’s policy change. However, when that certificate expires, it should be replaced with a certificate with a maximum lifespan of 397 days.
If you reprocess a two-year certificate after we have switched over to 397-day certificates, the reissued certificate will be limited to 397 days. However, you will be credited by SSL.com for the time remaining on the order. When the reprocessed certificate expires, you can issue a new certificate to cover the time remaining on the order.
Yes! SSL.com will continue to offer our customers certificate bundles with up to five years of coverage. For orders exceeding 397 days (or any other valid expiration date set by the customer), we issue free replacement certificates upon expiration and re-validation of site ownership throughout the duration of the certificate order. In this way, you can continue to benefit from multi-year discounting while remaining compliant with Apple’s new certificate lifetime requirements.
No. Apple’s change only extends to publicly trusted root CA certificates pre-installed on its devices, including SSL.com’s roots. Root certificates installed by a user or administrator are not affected by the 398-day restriction.
- Renew your SSL/TLS Certificate
- Effortlessly Reprocess and Rekey an SSL/TLS Certificate
- Reprocess a Certificate
- Reprocessing a Multi-Domain UCC/SAN Certificate
- Certificate Lifecycle Management guide
If you have any questions, please contact us by email at Support@SSL.com, call 1-877-SSL-SECURE, or just click the chat link at the bottom right of this page. You can also find answers to many common support questions in our knowledgebase. As always, thank you for choosing SSL.com!
