As part of its ongoing efforts to improve online security, Google has proposed a significant change to the SSL/TLS certificate system. In a recent announcement, the tech giant revealed its plan to cut the maximum validity period of SSL/TLS certificates to just 90 days.
Currently, SSL/TLS certificates can be valid for up to two years, providing a long-term security solution for website owners and users alike. However, Google argues that shorter certificate lifetimes will increase online security by forcing website owners to update their certificates more frequently and stay up-to-date with the latest security standards.
While this proposal has been met with some resistance from website owners relying on longer certificate lifetimes for their business operations, cybersecurity experts generally agree that shorter lifetimes can be good for online security.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
By reducing the maximum validity period to just 90 days, website owners will need to renew their certificates more frequently, which can help to prevent potential security breaches and keep users’ sensitive data safe. Additionally, shorter certificate lifetimes can help to mitigate the impact of any compromised certificates, as they will expire sooner and be less useful to attackers.
However, this proposal does come with some potential drawbacks, including increased administrative costs for website owners and the potential for more certificate-related issues and errors.
While Google’s proposal may shock some, it’s clear that the tech giant is committed to improving online security for everyone. As this proposal continues to develop, it’s important for website owners and users alike to stay informed about the potential impacts on their online security and take steps to protect themselves accordingly.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 14, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.