SSL Certificate Billing Overview
Billing Rules and Validity Period Description
This article explains the billing mode and validity period of SSL certificates. The validity period of SSL certificates is being shortened year by year. According to current regulations of the CA/B Forum, the maximum validity period of an SSL certificate shall not exceed 398 days. CA vendors support the purchase of multi-year certificates, which must be issued in batches, and the maximum validity period for each issuance shall not exceed 398 days.
Currently, the maximum validity period of SSL certificates does not exceed 398 days, but according to relevant regulations, the validity period of certificates will be shortened year by year. The specific dates are as follows:
- Starting from March 15, 2026: The maximum validity period shall be 200 days.
- Starting from March 15, 2027: The maximum validity period shall be 100 days.
- Starting from March 15, 2029: The maximum validity period will eventually be reduced to 47 days.
I. Billing Mode
-
Mainstream Billing Cycles
- Short-cycle certificates: Some vendors support certificates with a minimum validity period of 90 days (sslTrus DV/Sectigo DV/Digicert EE).
- Annual billing: The default validity period of SSL certificates is usually 1 year, taking effect immediately after issuance, with a maximum of 398 days (approximately 13 months).
-
Validity Period and Product Comparison Table
Certificate Validity Period Supported Products/Brands 90 days sslTrus DV, Sectigo DV, Digicert EE 1 year Standard certificates from all mainstream brands 13 months Digicert (paid customization), Globalsign, sslTrus (renewal), Sectigo (renewal), CFCA (special customization)
II. Billing Scenarios
-
Test Certificate Instructions
There are currently no public SSL certificates for testing purposes. The test certificates used by customers are essentially officially issued certificates with a specified validity period used for testing. Therefore, the so-called "test certificates" must be cancelled within the unconditional refund validity period to avoid incurring charges. -
Multi-year Purchase Rules
SSL certificates support one-time ordering for multiple years, but they must be issued in batches.The following table summarizes the validity periods, available order terms and renewal rules of mainstream certificate brands for your reference and planning. It is recommended to select a suitable certificate brand according to business needs and formulate a renewal plan in advance to ensure the secure and compliant operation of your website.
Certificate Brand Available Years
for One-Time OrderDefault Validity Period
for Single IssuanceRenewal Rules sslTrus 1-5 years 1 year Renew within one month in advance,
13-month validity available for issuanceSectigo 1-5 years 1 year Renew within one month in advance,
13-month validity available for issuanceDigicert 1-3 years 1 year Renew within one month in advance,
the expiration date is extended by 1 year from the current year's expiration dateGlobalsign 1-3 years 13 months Renew within one month in advance,
13-month validity available for issuanceCFCA 1-3 years 1 year Renew within one month in advance,
the expiration date is extended by 1 year from the current year's expiration dateCertum 1 year 1 year 12-month certificates are issued by default
-
Rules for Certificate Reissuance and Domain Replacement
SSL certificate reissue refers to the process of reissuing an existing certificate. Generally, a reissue is required when the customer's private key is lost or compromised, or when certificate information needs to be changed. Reissuing a certificate incurs no fees, and customers can reissue SSL certificates an unlimited number of times within the certificate's validity period, but domain name changes are usually not supported (to learn about the rules for changing domain names via reissue, see 《Can I change the domain name when reissuing an SSL certificate within its validity period?》). -
Certificate renewal The validity period of all certificates starts from the date of issuance. Therefore, certificate renewal cannot directly extend the validity period of the previous certificate; instead, a new certificate is issued. For more information about certificate renewal, see 《SSL Certificate Renewal Time Rules》