A Radius Channels partner resource The Certificate Doomsday Clock
LOADING
12
— minutes to midnight Ticking down to the industry's next mandatory certificate deadline
—
—
100-day maximum validity
takes effect March 15, 2027
—
—
—
47-day maximum validity
takes effect March 15, 2029
—
TODAY
Mar 2026
200-day cap
Mar 2027
100-day cap
Mar 2029
47-day cap
What happens when this gets ignored
8 in 10
companies have already had an unplanned outage from an expired certificate. The average incident takes hours to detect and pulls in a dozen-plus people to fix.
✕

Equifax, 2017. An expired certificate on a single monitoring appliance blinded the company's own network inspection tool. Attackers moved undetected for months. The result: 147 million people's names, social security numbers, and driver's license data exposed — one of the largest breaches in history, and the certificate wasn't even the way in. It was why nobody noticed.

✕

Ericsson / O2, 2018. One expired certificate on a core network node knocked out mobile data and SMS for roughly 32 million UK customers alone, and disrupted service across 11 countries. The bill: close to £100 million in compensation and an apology from the CEO.

✕

Microsoft Teams, February 2020. An expired authentication certificate took Teams offline worldwide for hours — at the exact moment remote work was becoming a lifeline for millions of employees.

✕

Epic Games, 2021. A single expired wildcard certificate was baked into hundreds of backend services. Fortnite and Epic's other titles went dark for over five hours before the fix even finished rolling out.

None of this required an attacker. Every incident above was self-inflicted — a renewal that didn't happen. At a 47-day cadence, the same window of exposure doesn't shrink. It just comes back around roughly 8 times a year instead of once.

Why partners lead with DigiCert

The CA/Browser Forum's ballot behind this schedule passed 29 votes to 0 — Apple, Google, Mozilla, and Microsoft all backed it. This isn't a proposal a customer can wait out; it's an already-adopted requirement, phasing in whether they're ready or not.

DigiCert Trust Lifecycle Manager is built for exactly this shift. It's CA-agnostic — one platform to discover, issue, deploy, and automatically renew certificates from DigiCert and other authorities alike, across public and private PKI, instead of stitching together per-vendor tools as renewal frequency multiplies.

That breadth is why IDC named DigiCert a Leader in its 2026 Certificate Lifecycle Management MarketScape — and why it's the platform that keeps working as the cadence tightens from 200 days to 47, not just today's baseline.

The pitch writes itself: the customer who automates on DigiCert before March 2027 treats every deadline on this page as a non-event. Everyone else finds out the hard way — publicly, and on repeat.

Analyst standingIDC Leader, 2026
PlatformCA-agnostic
CoveragePublic + private PKI
Renewals / yr at 47d~8
Industry vote29–0
Check a certificate

Want to check a specific domain's certificate right now? DigiCert runs its own free, official checker — no lookup limits, no third-party proxy, straight from the source.

Check a certificate on DigiCert.com →