CA/B Forum SC-081v3 — 200-day certificates are in effect now

By 2029, Your Certificates Expire Every 47 Days.

Evergreen SSL runs DNS-01 wildcard issuance and renewal, then delivers the private keys into your own vault or secrets manager.

DNS-01 wildcard issuance
Keys secure in your vault
Managed renewal schedule
Issuance audit trail

The certificate lifetime schedule is already set

CA/Browser Forum ballot SC-081v3 was approved in April 2025. These dates are fixed, and the first reduction took effect in March 2026.

Until March 2026 398days

The lifetime most renewal processes were built around.

In effect now 200days

Maximum validity roughly halved on March 15, 2026.

March 15, 2027 100days

About four renewals a year, for every certificate you hold.

March 15, 2029 47days

About eight renewals a year. Domain validation reuse also drops to 10 days.

By 2029, a process that ran once a year has to run about eight times a year. Automating before the 100-day limit takes effect in March 2027 leaves time to migrate.

Why Evergreen SSL?

DNS-01 wildcard issuance, with renewal on a configurable interval ahead of expiry.

Renewal On A Configurable Interval

Renews each certificate on a configurable interval ahead of expiry. As the maximum lifetime falls from 200 days to 100 and then 47, that same setting produces more renewals a year.

ACME With DNS-01 Challenges

Works with Let's Encrypt and other ACME-compatible certificate authorities. Wildcard certificates require DNS-01 validation, automated here for every supported DNS provider.

Keys Delivered Into Your Vault

Issued certificates and private keys are written to the Azure Key Vault or AWS Secrets Manager instance you configure. They are encrypted before they are written, and every write is recorded against your account.

Supported DNS and vault providers

Available at launch in November 2026.

DNS providers

DNS-01 challenge automation, which wildcard certificates require

  • Azure DNS
  • GoDaddy
  • AWS Route 53

Vault backends

Where your certificates and keys are delivered

  • Azure Key Vault
  • AWS Secrets Manager

Cloudflare DNS, DigitalOcean DNS, and HashiCorp Vault are planned for after launch.

How your private keys are handled

Where certificates and keys are stored, who can reach them, and what is recorded.

Where do private keys end up?

Certificates and private keys are written to the Azure Key Vault or AWS Secrets Manager instance you configure, using credentials you provide and control. Your vault is the only place they are stored.

Can Evergreen SSL read them?

Evergreen SSL holds only the vault credentials you grant it, and uses them only to write certificates and keys to the location you configure. Key material is encrypted before it is stored. Issuance happens inside the service, so it handles key material in transit before writing it to your vault.

What can you prove afterwards?

Evergreen SSL emits an audit event for every operation it performs against your account: each issuance, each renewal, and each write to your vault. The record shows which certificate changed, what changed it, and when.

Who is behind this?

Optic Nerve AI, LLC, a United States company. Our privacy policy and terms of service are linked in the footer of this page, and the service is offered to US customers at launch.

Starter is $29 a month

One plan at launch, priced publicly and billed monthly.

Starter
$29 / month

Up to 5 domains, wildcards included

  • Up to 5 domains, wildcard certificates included
  • Azure DNS, GoDaddy, or AWS Route 53 for DNS-01
  • Delivery into Azure Key Vault or AWS Secrets Manager
  • Automatic renewal on a configurable interval ahead of expiry
  • Certificate inventory with a full issuance and renewal audit trail

Launch pricing for the November 2026 MVP. Waitlist members are notified before any billing begins.

Why pay for a free protocol?

Evergreen SSL owns the operational work: renewal scheduling as lifetimes shrink, a maintained DNS-01 integration for each supported provider, delivery into your vault, and an audit record of every operation it performs.

Renewal survives your server rebuilds

A renewal timer on your own host depends on that host surviving, and on someone still owning it. Renewal here runs on separate infrastructure, so the schedule outlives changes to yours.

One integration per DNS provider, maintained for you

Each DNS provider has its own API, authentication model, and propagation behavior. Those integrations are written once here and kept current.

Vault-secured certificates are ready to use

Certificates are written to the Key Vault or Secrets Manager instance you configure, so the renewed certificate is in place as soon as it is issued.

Dashboard view of certificate inventory

One view of every certificate you hold, when it was issued, and when it renews next, ready for a compliance review.

Frequently asked questions

Launch timing, supported providers, pricing, and key handling.

When does Evergreen SSL launch?

The MVP is targeted for November 2026. Joining the waitlist gets you notified before launch, and before any billing begins.

Do I have to run certbot or any ACME client myself?

No. Evergreen SSL runs issuance and renewal for you. ACME clients like certbot, acme.sh, and lego are free to install; running them yourself means owning the renewal scheduling, the per-provider DNS-01 integration, and the audit trail.

Which DNS providers are supported?

Azure DNS, GoDaddy, and AWS Route 53 at launch. Cloudflare DNS and DigitalOcean DNS are planned for after launch.

Which certificate authorities can I use?

Let's Encrypt and other ACME-compatible certificate authorities, validated through DNS-01.

What happens when certificate lifetimes drop to 47 days?

The interval you set is measured against each certificate's expiry date, so a shorter lifetime brings that interval round more often. Your configuration stays as it is while the cadence rises from one renewal a year to roughly eight.

Where do my private keys end up?

In the Azure Key Vault or AWS Secrets Manager instance you configure, using credentials you provide and control. Key material is encrypted before it is stored. Issuance happens inside the service, so it handles key material in transit before writing it to your vault.

What does it cost, and when am I billed?

Starter is $29 a month for up to 5 domains, wildcards included. One plan at launch, billed monthly. Waitlist members are notified before any billing begins.

Is Evergreen SSL available outside the United States?

The service is offered to customers in the United States at launch. Evergreen SSL is operated by Optic Nerve AI, LLC, a United States company.

Reserve Your Spot

Get notified when Evergreen SSL launches!

Your email is safe with us. Unsubscribe anytime.

We'll only send product news and launch updates.