
If you’re a reader of this blog, it should come as no surprise that SSL lifetimes are changing. And by 2029, 47-day certificate lifetimes will be the norm. This applies to multi-year SSL plans too. While the plan covers several years, each certificate within it is limited to the current maximum validity, so it still needs replacing just as often.
With this shortening, will inevitably come a change in how SSL certificates are managed across the board. Because manually replacing your SSL roughly once a month isn’t practical, particularly if you or your business has multiple certificates across various sites and services to take care of.
This article covers how to migrate your current manual setup to an automated version in a few manageable steps. Let’s dive in.
Step 1 – Audit your certificates and renewal process
The first step is taking stock of every certificate your business owns, because you can’t start automating SSLs you don’t know exist. Create an inventory and record the following details for each SSL:
- The domains and SANs
- The CA and certificate type
- The location and expiry date
- The owner
- The renewal method, deployment method, and automation status
And be sure to check places like APIs, load balancers, staging, and internal services for potential forgotten certificates.
When noting down everything that’s needed for replacement or renewal, be sure to include every place human intervention is currently needed, from generating the CSR or performing business validation to installing the certificate. Pay particular attention to anything that will be hard to automate, such as DNS hosted with a provider that doesn’t offer API access or business validation for OV and EV certificates.
Step 2 – Prioritize
Now that you’ve made an inventory of all your certificates, it’s time to figure out which SSL certificates to migrate first. Trying to do it all at once might prove a headache, particularly the more certificates you have. Set aside any SSLs that are already automated and do it in three stages.
- Start with those that are easy to automate and low-risk, like a staging environment or minor subdomain. For example, DV certificates on common setups like a standard web server or hosting that already offers automation.
- In the second stage, you can go for easy certificates in more critical settings, like major public sites, login pages, checkout, or APIs.
- Last comes any SSLs that need organization validation or SSLs on legacy systems that might be a little more complicated to automate.
Step 3 – Choose an automation and deployment tool
The right automation tool will depend on your setup and how many certificates you need to manage. If you manage multiple types, you may need to choose a couple of different tools. The main SSL automation tools available are:
- Your hosting provider – Many hosting providers can issue and install SSLs automatically, though this is often limited to DV
- ACME – The standard protocol for SSL automation that covers most standard issuance and replacement needs.
- Certificate Authority (CA) APIs – These let your own scripts, tools, or platforms request and reinstall certificates directly.
- CLM platforms – Short for certificate lifecycle management, these platforms monitor, renew, install, and manage all of your organization’s certificates in one place.
Whichever you choose, make sure it handles deployment as well as issuance. A new certificate is only useful once it’s installed and your server can use it.
All of these will automatically cover DV certificates, but OV and EV automation can be a little more tricky. Generally, it depends on the CA and platform. And while renewal and installation can be automated, you will still need to perform business validation manually.
Step 4 – Start with a trial run
Choose 2-5 certificates from the first group of easy-to-automate certificates to do a test run of your new automation process. So everything from issuance and validation through to deployment, installation, and checking that the SSL is actually working.
If a certificate is already close to expiry, let the tool renew it on schedule. For the rest, trigger a renewal manually or use your tool’s dry-run option rather than waiting months. For any SSLs close to expiration, be ready to renew manually if anything goes wrong, so your site or service isn’t taken offline.
Once you’re done, take note of what worked and what didn’t so that you can address and fix it next time. Some common issues include a renewal tool being unable to access your DNS provider or failure alerts that aren’t actually reaching anyone.
Step 5 – Start migrating the next stages
If the trial run was a success, it’s time to roll out groups 2 and 3 from step 2. Start with the second, critical sites and services, then move on to the third, OV and EV certificates, as well as legacy systems.
Back up the current certificate, private key, and server configuration, so that if anything goes wrong, you can restore them quickly. If a setup is different from the ones in your trial run, test it in a staging environment first. Once each migration is complete, run the same checks as in your trial run to ensure the SSLs have been installed properly.
Step 6 – Monitor renewals and assign ownership
You may think your work is done now that you’re fully automated, but monitoring is still essential. Without monitoring, any failure to renew or install may end up going unnoticed until you realize a site or service has been left unsecured and is showing visitors a security warning.
Using an independent tool is crucial for picking up if an SSL fails to install. Check out a list of the best free and paid options in 2026. Be sure to assign specific certificates to a person or team and send alerts to more than one channel. That way they’re less likely to fall through the cracks, forgotten in someone’s inbox. And set business validation reminders for OV and EV certificates in the calendar, so those aren’t forgotten either.
The takeaway
Don’t wait for 47-day certificates to fix a renewal process that already relies too much on manual work. As we’ve outlined in this article, migration to automation doesn’t need to be complicated. Take it step by step: build your inventory, start small, and add monitoring, and the transition should be smooth. The 100-day limit arrives on March 15, 2027, so aim to have your process tested and reviewed well before then.
Frequently asked questions
Do I need to replace my existing certificates now?
No, your currently installed certificates will stay valid until they expire. New limits will only apply to SSLs issued after the dates new SSL lifetimes are rolled out.
Can OV and EV certificates be automated?
Yes, as long as your CA allows it. You will still need to perform manual business validation roughly once a year.
What happens if an automated renewal fails?
It should still keep using the current SSL certificate until the expiry date. If you have monitoring set up, it should alert you if your automation tool fails.

Cora is a digital copywriter for SSLs.com. Having eight years of experience in online content creation, she is a versatile writer with an interest in a wide variety of topics, ranging from technology to marketing.