Study · Certificates
How long do the top 10,000 sites' certificates last? Our September 2026 scan
Checked against sources on 2026-09-29 · 4 min read
On 28 and 29 September 2026 we read the TLS certificate of each of the 10,000 most-visited sites on the Tranco list. Of the 7,847 certificates we could read, 50.1% last 90 days or less, 48.8% come from a CA that renews automatically over ACME, and 37.5% look renewed by hand: a CA without automated renewal and a lifetime over 90 days. From 15 March 2027 no public certificate may last more than 100 days.
Six months after the 200-day rule started, this is a snapshot of where the busiest part of the web stands. It is also a preview of the work agencies face on client sites, which rarely have that much engineering behind them.
How long the certificates last
| Lifetime | Share of certificates |
|---|---|
| 47 days or less | 0.8% |
| 48 to 90 days | 49.3% |
| 91 to 200 days | 30.7% |
| More than 200 days (issued before 15 March 2026) | 19.2% |
Since 15 March 2026 a new public certificate may last 200 days at most, so everything over 200 days was issued before that date and will be replaced by a shorter one. 81% of the certificates we read were issued on or after 15 March 2026. Very short-lived certificates (10 days or less) barely appear yet: 1 of 7,847.
The next steps are fixed: 100 days from 15 March 2027 and 47 days from 15 March 2029, when domain validation may be reused for only 10 days. We plan to repeat this scan with the same method after each date, so the numbers can be compared year on year.
Who issues them
| Certificate authority | Share | Median lifetime |
|---|---|---|
| Google Trust Services | 27% | 90 days |
| Let's Encrypt | 21.4% | 90 days |
| DigiCert (incl. GeoTrust, Thawte, RapidSSL) | 16.6% | 199 days |
| Amazon (AWS Certificate Manager) | 12% | 198 days |
| GlobalSign | 7.5% | 199 days |
| Sectigo (incl. Comodo, USERTrust) | 5.5% | 199 days |
| GoDaddy (incl. Starfield) | 1.8% | 198 days |
| Other issuers | 7.6% | 199 days |
We sort CAs into three groups, the same way our monitor does when it judges renewal. Known ACME CAs (Let's Encrypt, ZeroSSL, Google Trust Services) are almost always renewed by software. Provider-managed CAs (Amazon's certificate manager, Cloudflare) are renewed by the provider on its own schedule. Everything else is sold per certificate, and whether renewal is automated depends on the customer.
- Known ACME CA: 48.8% of certificates.
- Provider-managed: 12.3%.
- Other CAs: 38.9%.
How many look renewed by hand
37.5% of certificates came from a CA outside those first two groups and lasted more than 90 days. That is our heuristic for "probably renewed by hand", and it overcounts: large companies automate long certificates from commercial CAs too, and we can't tell them apart from outside. Treat it as an upper bound. Those are the certificates that will need attention about four times a year once the maximum is 100 days.
Automated renewal also fails. Of the Let's Encrypt certificates we read, 5.1% were still being served after the point where an ACME client would normally have replaced them (fewer days left than a third of the lifetime minus three). Some hosts renew late on purpose; from outside we can't tell which. From 10 February 2027 Let's Encrypt's default certificates last 64 days, which leaves less time to notice a stuck renewal.
Expiring soon, and the ones we couldn't read
On the day we looked, 6.2% of certificates had 30 days or fewer left and 0.6% had already expired. For short-lived certificates 30 days is normal: a 90-day certificate renews at about that point. We don't name any of these sites, here or anywhere else.
For 2,152 of the 10,000 names neither the www name nor the bare domain gave us a certificate: 1,406 had no address in DNS (many top-list entries are CDN, API or tracking domains without a website), 250 timed out, 266 refused or reset the connection, 209 failed the TLS handshake, and 21 pointed at private addresses, which we don't contact.
What it means for agency client sites
- Sort each client's hostnames by issuer: ACME, provider-managed, or bought. The 47-day readiness checker does this for one domain and its subdomains.
- For the bought ones, decide before 15 March 2027: move them to ACME renewal, or put the renewals in someone's calendar about four times a year.
- For the automated ones, watch for renewals that stop. The bulk SSL checker shows expiry dates and issuers for 25 hosts at a time.
If you look after many client sites, our page for web design agencies shows how ExpiryOwl groups certificates by client and flags the ones renewed by hand.
How we measured
- List: Tranco, list 64X3X, generated 27 September 2026 from five providers' data for 29 August to 27 September 2026; the top 10,000 registrable domains.
- One TLS handshake on port 443 per name with our own certificate checker, the same one our monitor uses: www first, the bare domain once if www gave no certificate. No web page was requested, no port was scanned, nothing was crawled.
- At most eight connections at a time, 2.5 new connections a second, a 5-second timeout, no other retries. The run took 85 minutes, from 28 Sep 23:26 to 29 Sep 00:50 UTC, from one connection in Bahrain.
- We never contacted private or reserved addresses, and we kept per-site results on our own computer. Only totals are published.
- Top lists lean towards large companies and infrastructure domains. Agency client sites are smaller and run by fewer people, so read these numbers as a picture of the best-run part of the web, not the average site.
- Not measured: certificates on other ports or names, internal certificates, whether a renewal is actually automated (we infer it from the issuer), and anything about the sites' content.
Want your site left out of a future run, or have a question about the method? Write to [email protected].