Wiki - Industry Changes
-
In this section, we provide an insightful overview of the most prevalent global industry changes pertaining to SSL certificates, code signing products, S/MIME products, and other related offerings. Stay informed as we explore the evolving landscape of these critical digital security solutions, highlighting trends, advancements, and best practices that shape the way businesses protect their online communications and transactions.
-
1Code Signing new standards (2023)
Starting on June 1, 2023, at 00:00 UTC, industry standards will require private keys for OV code signing certificates to be stored on hardware certified as FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent.
-
2SSL Certificate Lifecycles Are Shortening
SSL/TLS certificates once lasted upwards of five years; now, they have 398-day lifespans. But that’s going down--they are on track to expire every 47-days by 2029...
-
3DNSSEC checks will become mandatory for certificate issuance
New CA/Browser Forum rules are tightening how Certificate Authorities validate domains before issuing certificates. If a domain is DNSSEC-enabled, the CA must validate DNSSEC when performing...
-
4Sectigo Public Root CAs Migration
The migration to Sectigo's new Public Root CAs is a proactive step to ensure our certificates remain highly secure, trusted, and compliant with modern industry standards...
-
5Code Signing Certificate Validity Is Shortening (2026)
The industry is reducing the maximum validity period for publicly trusted Code Signing certificates. Beginning March 1, 2026, the Code Signing Baseline Requirements set a maximum validity of 460 days per issued certificate...
-
6DigiCert G1 Root Retirement (2026)
On April 15th 2026, major browsers will stop trusting DigiCert’s first-generation (G1) public TLS root certificates. Any TLS chain that still ends at a DigiCert G1 root will fail in browsers that follow the Mozilla and Chrome root programs...
-