Skip to main content

SSL Certificate Billing Overview

Billing Rules and Validity Period Description

This article explains the billing mode and validity period of SSL certificates. The validity period of SSL certificates is being shortened year by year. According to current regulations of the CA/B Forum, the maximum validity period of an SSL certificate shall not exceed 398 days. CA vendors support the purchase of multi-year certificates, which must be issued in batches, and the maximum validity period for each issuance shall not exceed 398 days.

Information

Currently, the maximum validity period of SSL certificates does not exceed 398 days, but according to relevant regulations, the validity period of certificates will be shortened year by year. The specific dates are as follows:

  • Starting from March 15, 2026: The maximum validity period shall be 200 days.
  • Starting from March 15, 2027: The maximum validity period shall be 100 days.
  • Starting from March 15, 2029: The maximum validity period will eventually be reduced to 47 days.

I. Billing Mode

  1. Mainstream Billing Cycles

    • Short-cycle certificates: Some vendors support certificates with a minimum validity period of 90 days (sslTrus DV/Sectigo DV/Digicert EE).
    • Annual billing: The default validity period of SSL certificates is usually 1 year, taking effect immediately after issuance, with a maximum of 398 days (approximately 13 months).
  2. Validity Period and Product Comparison Table

    Certificate Validity PeriodSupported Products/Brands
    90 dayssslTrus DV, Sectigo DV, Digicert EE
    1 yearStandard certificates from all mainstream brands
    13 monthsDigicert (paid customization), Globalsign, sslTrus (renewal), Sectigo (renewal), CFCA (special customization)

II. Billing Scenarios

  • Test Certificate Instructions
    There are currently no public SSL certificates for testing purposes. The test certificates used by customers are essentially officially issued certificates with a specified validity period used for testing. Therefore, the so-called "test certificates" must be cancelled within the unconditional refund validity period to avoid incurring charges.

  • Multi-year Purchase Rules
    SSL certificates support one-time ordering for multiple years, but they must be issued in batches.

    The following table summarizes the validity periods, available order terms and renewal rules of mainstream certificate brands for your reference and planning. It is recommended to select a suitable certificate brand according to business needs and formulate a renewal plan in advance to ensure the secure and compliant operation of your website.

    Certificate BrandAvailable Years
    for One-Time Order
    Default Validity Period
    for Single Issuance
    Renewal Rules
    sslTrus1-5 years1 yearRenew within one month in advance,
    13-month validity available for issuance
    Sectigo1-5 years1 yearRenew within one month in advance,
    13-month validity available for issuance
    Digicert1-3 years1 yearRenew within one month in advance,
    the expiration date is extended by 1 year from the current year's expiration date
    Globalsign1-3 years13 monthsRenew within one month in advance,
    13-month validity available for issuance
    CFCA1-3 years1 yearRenew within one month in advance,
    the expiration date is extended by 1 year from the current year's expiration date
    Certum1 year1 year12-month certificates are issued by default
Reissuance for Domain Replacement and Renewal
  • Rules for Certificate Reissuance and Domain Replacement
    SSL certificate reissue refers to the process of reissuing an existing certificate. Generally, a reissue is required when the customer's private key is lost or compromised, or when certificate information needs to be changed. Reissuing a certificate incurs no fees, and customers can reissue SSL certificates an unlimited number of times within the certificate's validity period, but domain name changes are usually not supported (to learn about the rules for changing domain names via reissue, see 《Can I change the domain name when reissuing an SSL certificate within its validity period?》).

  • Certificate renewal The validity period of all certificates starts from the date of issuance. Therefore, certificate renewal cannot directly extend the validity period of the previous certificate; instead, a new certificate is issued. For more information about certificate renewal, see 《SSL Certificate Renewal Time Rules》