
Shorter SSL Certificates in Monaco
SSL certificates now last 200 days, and 100 from March 2027. What Monaco businesses must automate before a silent expiry takes their website offline.
There is a change working its way through the internet's plumbing that most Monaco business owners have not heard about, and that will take websites offline over the next three years if nobody acts. It concerns the SSL/TLS certificate — the thing that puts the padlock in the browser bar and the "s" in https — and specifically how long one is allowed to live before it must be replaced.
Until March 2026, a certificate could be valid for just over a year. You renewed it annually, or your hosting provider did it quietly for you, and it never crossed your desk. That era is ending on a published schedule, and the practical consequence is simple: renewal has to become automatic, because it is about to happen too often to do by hand.
The schedule, in plain terms
The CA/Browser Forum — the body where certificate authorities and browser makers agree the rules that Chrome, Safari, Firefox and Edge all enforce — approved the change in 2025. The maximum lifetime of a publicly trusted certificate drops in three steps:
- From 15 March 2026: 200 days (already in force)
- From 15 March 2027: 100 days
- From 15 March 2029: 47 days
Certificates issued before each date keep running for their full term, so nothing breaks overnight. But every renewal from here on lands you in the shorter bracket. By 2029, a website will need a new certificate roughly every six weeks — around eight times a year, against once a year today.
There is a second change that matters just as much and gets less attention: the period for which a certificate authority may reuse your domain validation is shrinking alongside the lifetime, down to 10 days by 2029. In practice, proving you still control your own domain becomes a routine, frequent event rather than an annual formality.
Why this is happening
Shorter certificates are a security measure, not a commercial one. If a private key is stolen or a certificate is issued in error, the window in which it can be abused is limited by how long it stays valid. Revocation — the mechanism meant to cancel a bad certificate early — has never worked reliably across all browsers, so the industry decided the pragmatic fix was to make certificates expire quickly on their own.
It also forces the ecosystem toward automation, which is the real point. Manual certificate management is where outages come from.
What actually goes wrong
An expired certificate does not degrade gracefully. Visitors do not see a small warning; they see a full-page red interstitial telling them the connection is not private and that the site may be trying to steal their information. Most people leave immediately. Search engines and ad platforms stop sending traffic. Payment flows break. If you sell online, the checkout simply stops working.
For a Monaco business whose site is the first impression on an international client, that screen is expensive in a way that is hard to quantify and easy to avoid.
The failure mode we see most often is not negligence — it is drift. The certificate was set up years ago by someone who has since left. The renewal reminder goes to an email address nobody reads. The site sits with one provider, the domain with another, and each assumes the other is handling it. At an annual cadence, that arrangement survives on luck. At 100 days, luck runs out.
What to check this month
You do not need to be technical to run this audit. Ask four questions and write down the answers:
- Who issues our certificate? Your host, a certificate authority you pay directly, a CDN like Cloudflare, or a platform such as Shopify.
- Is renewal automatic? If the answer is "someone does it" rather than "the system does it", that is your risk.
- Where do expiry alerts go? They should reach a monitored shared mailbox, not an individual.
- What else uses a certificate? Beyond the main website: your mail server, a booking system, a client portal, an API, a subdomain for a campaign, an office VPN or firewall appliance. These are the ones that get forgotten.
That last point is where most surprises hide. The main site is usually fine. The staging server, the legacy portal or the payment appliance is not.
Getting to automation
For the vast majority of Monaco businesses, the fix is neither difficult nor expensive.
Modern hosting handles this natively. Managed platforms, most quality hosts, and services like Cloudflare issue and renew certificates automatically using the ACME protocol — the same standard behind Let's Encrypt. If your site runs on a well-configured stack, shorter lifetimes are genuinely a non-event, and this is one of the quiet advantages of a properly built site over a cheap one. It is the sort of thing we design in from the start on any web development project.
Where attention is needed:
- Self-managed servers and older setups, particularly custom WordPress installations on legacy hosting, where certificates were installed manually years ago.
- Anything behind a load balancer, firewall or appliance, where the certificate lives on hardware rather than in the web stack.
- Online stores, where an expiry means direct lost revenue and where custom domains, checkout subdomains and payment integrations all need covering — worth a look as part of your broader e-commerce setup.
Add independent expiry monitoring on top, so you find out from an alert rather than from a client. This is exactly the kind of thing that belongs in ongoing website maintenance rather than in someone's calendar.
The Monaco context
Nothing here is specific to Monegasque law — these are global browser rules that apply to any site your clients can reach, whether it sits on a .mc domain or anywhere else. But two local realities make it worth acting sooner.
First, many Monaco businesses run lean, with a website built once by an external partner and rarely revisited. Those are precisely the setups where nobody currently owns renewal.
Second, the clientele is unforgiving. A prospective client searching from Geneva, London or Dubai who hits a security warning does not investigate further — they close the tab. You will never know it happened.
What to do now
Between now and March 2027 you have a comfortable window, and using it costs very little. Inventory every certificate you rely on, confirm each one renews automatically, point the alerts somewhere a person actually looks, and fix the one or two legacy systems that turn up. Do it once properly and the 2027 and 2029 steps pass without you noticing.
If you would rather someone simply checked your site and told you whether you are exposed, get in touch — it is a short audit, and it is far cheaper than the morning your site goes red.