India English
Kenya English
United Kingdom English
South Africa English
Nigeria English
United States English
United States Español
Indonesia English
Bangladesh English
Egypt العربية
Tanzania English
Ethiopia English
Uganda English
Congo - Kinshasa English
Ghana English
Côte d’Ivoire English
Zambia English
Cameroon English
Rwanda English
Germany Deutsch
France Français
Spain Català
Spain Español
Italy Italiano
Russia Русский
Japan English
Brazil Português
Brazil Português
Mexico Español
Philippines English
Pakistan English
Türkiye Türkçe
Vietnam English
Thailand English
South Korea English
Australia English
China 中文
Somalia English
Netherlands Nederlands

SSL Validity Is Shrinking to 47 Days: What SA Businesses Must Know Before 2029

  • Home
  • Website Guides
  • SSL Validity Is Shrinking to 47 Days: What SA Businesses Must Know Before 2029

Buy domains, business emails, hosting, VPS and more: Get Started

Cheapest Domains in South Africa

Get your .Co.Za or .Com domain now for just 45.00 ZAR

.CO.ZA for 45.00 ZAR | .COM for 150.00 ZAR

Your web developer just mentioned something called the 47-day rule. It sounds like another item on a long technical to-do list. 

Before you panic, know this: most small South African businesses barely need to lift a finger.

This guide explains what SA businesses must know before 2029. It also shows exactly who needs to act, and who can relax.

The short version

  • SSL certificates for public websites are shrinking from 398 days down to 47 by March 2029.
  • The change rolls out in three stages: 200 days now, 100 days from 2027, then 47 in 2029.
  • If your host renews your SSL automatically, this change will run itself.
  • Only businesses managing their own certificates by hand need to build new habits.

What Actually Changed

An SSL certificate is what puts the padlock and https:// on your website. It used to last up to 398 days, just over a year, before needing renewal.

In April 2025, the CA/Browser Forum voted to shrink that window. This group sets the rules that Chrome, Safari, and every other major browser follow. The vote passed unanimously, with Apple as the original sponsor.

The new maximum drops in three stages, ending at 47 days by 2029. That is roughly six weeks, instead of the current thirteen months.

DateMaximum validityWhat it means
March 15, 2026 (already in effect)200 daysNew certificates issued now must renew roughly twice a year
March 15, 2027100 daysRenewal moves to about four times a year
March 15, 202947 daysRenewal moves to about eight times a year

Existing certificates keep their original validity until they naturally expire. Only newly issued certificates follow the new limits.

So a certificate issued last year, before the change, still runs its full original term. The rule only bites on certificates issued from each new date onward.

Why Browsers Are Forcing This Change

A shorter certificate limits how long a stolen or misissued one stays dangerous. If a certificate leaks, a 47-day lifespan closes that window fast.

Shorter cycles also push the whole industry toward automated renewal. Manual renewal, once a year, tolerated small mistakes and outdated details.

Automated renewal, every few weeks, catches problems before they ever reach your visitors.

Does This Actually Affect Your Business?

Here is the question that matters most. It comes down to how your current SSL certificate gets renewed.

  • Free SSL through your hosting provider, like Let’s Encrypt? It already renews automatically, often every 90 days.
  • A paid certificate your host installs and renews for you? Your host absorbs the extra renewals.
  • A certificate you or your IT team manages manually? You will feel this change directly.
  • Multiple domains, subdomains, or servers managed by hand? Expect renewal work to multiply fast.

Most small South African businesses fall into the first two categories. If that describes you, this whole industry shift changes almost nothing about your day.

Where Businesses Actually Feel the Pain

The panic in most 47-day articles is aimed at large enterprises. Picture a company running hundreds of internal servers and certificates.

Each certificate on that list needs attention once a year. Under the new rule, that same list needs attention up to eight times a year. 

Multiply a small task by eight, and it becomes a real operational burden.

A small business with one or two websites faces a completely different scale. The real risk is not the renewal frequency itself, but forgetting a certificate exists at all.

An Example Of One Site, Two Very Different Outcomes

Lets say two small businesses in Cape Town, both running online stores. Both currently use SSL certificates issued this year.

The first hosts a provider that auto-renews Let’s Encrypt certificates every 90 days. Nothing about the 2029 deadline changes her routine at all.

 Her certificate was already renewed faster than the new rule requires.

The second business bought a one-year certificate manually years ago, and installed it by hand each time. 

Every renewal used to mean one calendar reminder, once a year. By 2029, that same manual process will repeat roughly eight times a year instead.

Same starting point, same industry, completely different amount of work ahead. The difference was never the rule itself, but how each certificate gets renewed.

Common Misunderstandings About This Change

A few myths tend to spread faster than the actual ballot text. Let’s clear up the most common ones.

Myth: Every website needs a new certificate right now

Not true. Existing certificates keep running until their original expiry date. Only certificates issued from each new cutoff onward follow the shorter limit.

Myth: This only affects large companies

The rule technically applies to any publicly trusted certificate, of any size. In practice, the workload only grows for businesses managing certificates by hand.

Myth: Private company networks are affected too

Internal, private certificate systems sit outside this rule entirely. The CA/Browser Forum only governs certificates trusted by public browsers like Chrome and Safari.

A Quick Health Check for Your Own Website

Run through these four questions for every website you manage. Each one takes less than a minute to answer.

1) Who issued your current SSL certificate?

Check your hosting control panel or ask your web developer directly. Free Let’s Encrypt certificates already follow a short renewal cycle.

2) Does it renew automatically?

Most modern hosting panels handle this without any action from you. If you are unsure, this is the single most important question to answer.

3) Do you manage any certificates by hand?

A manually purchased and installed certificate needs a calendar reminder now. Under the new rule, that reminder needs to repeat far more often.

4) Does your site have more than one domain or subdomain?

Each one may carry its own separate certificate and renewal date. List them all in one place, so nothing gets forgotten.

How to Ask Your Web Developer the Right Question

If someone else manages your website, one message settles this entirely. Send them this exact question: Does our SSL certificate renew automatically, and where?

A confident yes, naming the hosting provider, means you are covered already. A vague answer, or mention of a manual process, deserves a follow-up conversation soon.

Keep that answer written down somewhere you can find it again. It becomes useful the next time a client or auditor asks about your security setup.

What Automatic Renewal Actually Looks Like

Truehost, for South African hosting customers, already issues free SSL through Let’s Encrypt on every plan. 

That certificate renews automatically, well within the new limits, without any manual step.

In practice, this means the 2029 deadline changes nothing for that certificate. Your host already operates on a shorter, automated cycle than the rule requires.

For businesses that want extra trust signals, paid Organization or Extended Validation certificates remain available too.

Those add a verified business name to the certificate details. Truehost’s SSL plans start from about R70 a year.

If You Do Manage Certificates Yourself

Some businesses run their own servers or manage certificates directly. If that is you, three habits are the most important from here forward.

  • List every certificate you manage, across every domain and subdomain, in one place.
  • Set a renewal reminder well before each expiry, not on the exact date.
  • Consider moving to a host with automatic renewal, to remove this task entirely.

That third option is worth genuine consideration. Manual renewal only gets harder as the cycle shortens further toward 2029.

What Happens If a Certificate Expires Unnoticed?

An expired certificate does not quietly fail in the background. Visitors see a blunt warning page instead of your website, often reading “Your connection is not private.”

Most visitors leave immediately rather than click through that warning. For an online store, that means lost sales for every hour the certificate expires. 

This is the real cost behind the 47-day conversation, not the renewal task itself.

Shorter validity periods raise the odds of this happening to businesses on manual renewal.

 That is precisely why automatic renewal matters more now than it did a few years ago.

The Bottom Line for South African Businesses

So yes, SSL validity really is shrinking, down to 47 days by 2029. For most small businesses, though, this is a background change your host already handles.

The one action worth taking today is simple. Confirm your certificate renews automatically, then stop thinking about the 2029 deadline entirely.

Not sure if your current SSL renews on its own? Check Truehost’s SSL certificates or see what’s already included with your hosting plan.

Anne Purity
Author

Anne Purity

Conversion Focused SEO Copywriter Nairobi, Kenya

Anne is a conversion-focused SEO copywriter specializing in the web hosting and domain industry. She creates high-performing content that not only ranks on search engines but also turns visitors into customers. By combining keyword strategy with user intent and persuasive messaging, she helps businesses attract qualified traffic and drive meaningful growth.

View All Posts