Study · Certificates

How long do the top 10,000 sites' certificates last? Our September 2026 scan

Checked against sources on 2026-09-29 · 4 min read

On 28 and 29 September 2026 we read the TLS certificate of each of the 10,000 most-visited sites on the Tranco list. Of the 7,847 certificates we could read, 50.1% last 90 days or less, 48.8% come from a CA that renews automatically over ACME, and 37.5% look renewed by hand: a CA without automated renewal and a lifetime over 90 days. From 15 March 2027 no public certificate may last more than 100 days.

Six months after the 200-day rule started, this is a snapshot of where the busiest part of the web stands. It is also a preview of the work agencies face on client sites, which rarely have that much engineering behind them.

How long the certificates last

Base: 7,847 certificates read on 28 and 29 September 2026. Lifetime = the certificate's not-after minus not-before date.
LifetimeShare of certificates
47 days or less0.8%
48 to 90 days49.3%
91 to 200 days30.7%
More than 200 days (issued before 15 March 2026)19.2%

Since 15 March 2026 a new public certificate may last 200 days at most, so everything over 200 days was issued before that date and will be replaced by a shorter one. 81% of the certificates we read were issued on or after 15 March 2026. Very short-lived certificates (10 days or less) barely appear yet: 1 of 7,847.

The next steps are fixed: 100 days from 15 March 2027 and 47 days from 15 March 2029, when domain validation may be reused for only 10 days. We plan to repeat this scan with the same method after each date, so the numbers can be compared year on year.

Who issues them

Median lifetimes only where a CA issued at least 25 of the certificates. Brand families are grouped the way our checker groups them.
Certificate authorityShareMedian lifetime
Google Trust Services27%90 days
Let's Encrypt21.4%90 days
DigiCert (incl. GeoTrust, Thawte, RapidSSL)16.6%199 days
Amazon (AWS Certificate Manager)12%198 days
GlobalSign7.5%199 days
Sectigo (incl. Comodo, USERTrust)5.5%199 days
GoDaddy (incl. Starfield)1.8%198 days
Other issuers7.6%199 days

We sort CAs into three groups, the same way our monitor does when it judges renewal. Known ACME CAs (Let's Encrypt, ZeroSSL, Google Trust Services) are almost always renewed by software. Provider-managed CAs (Amazon's certificate manager, Cloudflare) are renewed by the provider on its own schedule. Everything else is sold per certificate, and whether renewal is automated depends on the customer.

  • Known ACME CA: 48.8% of certificates.
  • Provider-managed: 12.3%.
  • Other CAs: 38.9%.

How many look renewed by hand

37.5% of certificates came from a CA outside those first two groups and lasted more than 90 days. That is our heuristic for "probably renewed by hand", and it overcounts: large companies automate long certificates from commercial CAs too, and we can't tell them apart from outside. Treat it as an upper bound. Those are the certificates that will need attention about four times a year once the maximum is 100 days.

Automated renewal also fails. Of the Let's Encrypt certificates we read, 5.1% were still being served after the point where an ACME client would normally have replaced them (fewer days left than a third of the lifetime minus three). Some hosts renew late on purpose; from outside we can't tell which. From 10 February 2027 Let's Encrypt's default certificates last 64 days, which leaves less time to notice a stuck renewal.

Expiring soon, and the ones we couldn't read

On the day we looked, 6.2% of certificates had 30 days or fewer left and 0.6% had already expired. For short-lived certificates 30 days is normal: a 90-day certificate renews at about that point. We don't name any of these sites, here or anywhere else.

For 2,152 of the 10,000 names neither the www name nor the bare domain gave us a certificate: 1,406 had no address in DNS (many top-list entries are CDN, API or tracking domains without a website), 250 timed out, 266 refused or reset the connection, 209 failed the TLS handshake, and 21 pointed at private addresses, which we don't contact.

What it means for agency client sites

  1. Sort each client's hostnames by issuer: ACME, provider-managed, or bought. The 47-day readiness checker does this for one domain and its subdomains.
  2. For the bought ones, decide before 15 March 2027: move them to ACME renewal, or put the renewals in someone's calendar about four times a year.
  3. For the automated ones, watch for renewals that stop. The bulk SSL checker shows expiry dates and issuers for 25 hosts at a time.

If you look after many client sites, our page for web design agencies shows how ExpiryOwl groups certificates by client and flags the ones renewed by hand.

How we measured

  • List: Tranco, list 64X3X, generated 27 September 2026 from five providers' data for 29 August to 27 September 2026; the top 10,000 registrable domains.
  • One TLS handshake on port 443 per name with our own certificate checker, the same one our monitor uses: www first, the bare domain once if www gave no certificate. No web page was requested, no port was scanned, nothing was crawled.
  • At most eight connections at a time, 2.5 new connections a second, a 5-second timeout, no other retries. The run took 85 minutes, from 28 Sep 23:26 to 29 Sep 00:50 UTC, from one connection in Bahrain.
  • We never contacted private or reserved addresses, and we kept per-site results on our own computer. Only totals are published.
  • Top lists lean towards large companies and infrastructure domains. Agency client sites are smaller and run by fewer people, so read these numbers as a picture of the best-run part of the web, not the average site.
  • Not measured: certificates on other ports or names, internal certificates, whether a renewal is actually automated (we infer it from the issuer), and anything about the sites' content.

Want your site left out of a future run, or have a question about the method? Write to [email protected].

Sources

  1. Tranco: a research-oriented top sites ranking
  2. Tranco list 64X3X
  3. CA/Browser Forum Ballot SC-081v3
  4. Let's Encrypt: Decreasing certificate lifetimes to 45 days

FAQ

Questions

What share of top sites use certificates of 90 days or less?

50.1% of the 7,847 certificates we read on the Tranco top 10,000 in September 2026 lasted 90 days or less.

Which certificate authority issues the most certificates on top sites?

In our September 2026 scan: Google Trust Services (27%), then Let's Encrypt (21.4%) and DigiCert (incl. GeoTrust, Thawte, RapidSSL) (16.6%).

Did you store or publish the sites you checked?

Per-site results stayed on our own computer for the analysis. We publish only totals and never name a site.

Start with five domains, free.

The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.