Most coverage of CA/B Forum Ballot SC-081v3 focuses on the 47-day certificate validity headline. The equally significant change buried in the same ballot is the reduction of Domain Control Validation (DCV) reuse periods to 10 days by March 2029. For organizations validating domains manually today, this change is operationally more disruptive than the validity reduction.
Today, when you complete DCV for a domain, that validation result can be reused to issue multiple certificates for up to 398 days without repeating the process. In 2029, that window drops to 10 days. At 47-day certificate validity and 10-day DCV reuse, domain validation must happen approximately 35 times per year per domain. Manual DCV processes that currently take 5-15 minutes per domain, done once or twice a year, must become weekly operations or they must be automated.
The Math That Makes This Concrete
Organizations that manage SSL certificates manually need to work through these numbers for their own domain portfolios:
| Domains owned | Manual DCV events per year (2029) | At 15 minutes each | At 30 minutes each |
| 1 domain | ~35 DCV events | 8.75 hours/year | 17.5 hours/year |
| 5 domains | ~175 DCV events | 43.75 hours/year | 87.5 hours/year |
| 10 domains | ~350 DCV events | 87.5 hours/year (2+ working weeks) | 175 hours/year (4+ working weeks) |
| 25 domains | ~875 DCV events | 218.75 hours/year (5+ working weeks) | 437.5 hours/year |
| 50 domains | ~1,750 DCV events | 437.5 hours/year (11+ working weeks) | 875 hours/year |
The 35 DCV events per year figure is derived from 365 days divided by a 10-day DCV reuse window, minus the first validation. The actual number depends on certificate expiry dates and renewal timing. Some certificates may require DCV immediately before issuance rather than reusing any cached validation. The time estimates above assume straightforward DNS or HTTP validation with no complications. Systems with DNS access controls, multiple approval layers, or change management gates for DNS changes will take longer per event.
The DCV Reuse Reduction Schedule Under CA/B Forum SC-081v3
CA/B Forum Ballot SC-081v3, passed April 11, 2025, established the following DCV reuse reduction schedule alongside the certificate validity reductions. DigiCert’s implementation documentation confirms the specific dates:
| Effective date | DCV reuse window | Certificate max validity | DCV events per domain per year |
| Today (June 2026) | 398 days (legacy) / 199 days (new validations from Feb 2026) | 199 days | 1-3 per year |
| March 15, 2027 | 100 days | 100 days | ~4 per year |
| March 15, 2029 | 10 days | 47 days | ~35 per year |
The 10-day DCV reuse window will likely be issued as 9 days in practice, for the same reason 200-day certificates are issued as 199-day: the CA/B Forum limit is a maximum, and CAs round down by at least one day to avoid microsecond boundary violations that constitute misissuance. The operational planning number is 9-10 days; plan for 9.
Email-Based DCV Is Also Being Eliminated
The DCV reuse reduction compounds with a parallel change that directly affects the most common manual validation method. Email-based DCV, where the CA sends a validation email to a standard administrative address (admin@yourdomain.com, webmaster@yourdomain.com, or the WHOIS contact) and the certificate applicant clicks a link to confirm, is being phased out across the industry.
Let’s Encrypt deprecated email DCV in July 2025. CA/B Forum Ballot SC-090 is sunsetting all remaining email-based, phone-based, and related legacy validation methods for public CAs. After the SC-090 implementation timeline, the remaining DCV methods will be:
- HTTP-01 (file-based DCV): place a specific file at http://yourdomain.com/.well-known/acme-challenge/[token]. Requires direct access to the web server or content management system. Automatable via the ACME protocol.
- DNS-01 (DNS TXT record DCV): add a specific TXT record to the domain’s DNS zone. Requires DNS management access. Automatable if the DNS provider has an API. This is the only method that works for wildcard certificates.
- DNS CNAME-based (some CAs): add a CNAME record pointing to a CA-controlled domain. One-time setup that makes subsequent validations fully automated.
Organizations that currently use email DCV because it requires no technical access to the web server or DNS must migrate to either HTTP-01 or DNS-01. Both require technical access and both are more amenable to automation than email DCV, but both also require more initial setup than clicking a link in an email.
If your current SSL certificate renewal process involves receiving a validation email and clicking a link, this process will stop working after the CA/B Forum SC-090 email DCV sunset timeline. Begin evaluating DNS API access or HTTP validation access for your domains before the sunset date. The combination of email DCV elimination and 10-day DCV reuse windows makes manual validation operationally untenable by 2029 even for organizations with small domain portfolios.
The Three Paths Forward
Path 1: ACME automation with free certificates (Let’s Encrypt or ZeroSSL)
The ACME protocol (RFC 8555) was specifically designed for the automated certificate lifecycle that SC-081v3 requires. An ACME client (Certbot, acme.sh, or an ACME library in your platform) handles DCV and renewal automatically without human intervention. At 47-day validity and 10-day DCV reuse, ACME automation handles all 35+ annual validation events per domain silently.
Cost: free. Technical requirement: server access for HTTP-01 validation, or DNS API access for DNS-01 validation. ACME automation with Let’s Encrypt or ZeroSSL is the correct path for organizations comfortable with technical configuration. The operational investment is front-loaded (setting up the automation), then essentially zero.
Path 2: Commercial CLM platform (Certificate Lifecycle Management)
Enterprise organizations with large certificate portfolios, compliance requirements, or heterogeneous infrastructure (mix of on-premises, cloud, and SaaS) may require a commercial CLM platform that provides discovery, policy enforcement, automated issuance, and renewal across all certificate types and CAs. DigiCert Trust Lifecycle Manager, Venafi, Sectigo Certificate Manager, and AppViewX are the major platforms in this category.
Cost: enterprise licensing, typically per-certificate or per-organization pricing. Appropriate for: organizations managing hundreds or thousands of certificates, organizations with regulatory compliance requirements for certificate inventory, organizations using both public and private CA certificates.
Path 3: Manual validation 35 times per year per domain
For organizations that cannot implement ACME automation and cannot justify a CLM platform, manual validation remains technically possible after March 2029. The math above shows the operational cost. This path is viable for organizations with very small domain portfolios (one or two domains) where the annual manual effort is manageable. It is not viable for organizations with 10 or more domains.
What Paid Multi-Year Certificates Do and Do Not Change
A question that arises naturally: does buying a multi-year paid certificate subscription from an authorized reseller reduce the DCV burden?
The honest answer: not meaningfully by 2029, but they provide a window of relative calm before the 10-day regime takes effect.
- DCV reuse period currently (2026): 199 days for new validations. A multi-year subscription means you pay for multiple certificate terms upfront, and certificate reissuance within the subscription is free. DCV is required on the current 199-day schedule. Fewer DCV events than the future standard.
- DCV reuse period in 2027: 100 days. A multi-year subscription still reduces the payment friction (you’re not re-purchasing), but DCV occurs on the 100-day schedule.
- DCV reuse period in 2029: 10 days. A multi-year subscription with a commercial CA does not change the DCV reuse requirement. Every 10 days, DCV must be repeated. Commercial paid certificates have no DCV exemption under SC-081v3. The only way to reduce DCV burden at 10-day reuse windows is automation.
What multi-year subscriptions do provide: price stability through the transition period, no per-renewal purchase friction, and for OV subscribers, stability of the organizational validation reuse window (which reduces from 825 days to 398 days by March 2026, but is separate from the DCV reuse window).
The optimal strategy for organizations not yet ready to implement ACME automation: buy a multi-year OV subscription before the March 2026 organizational validation reuse reduction takes full effect, begin testing ACME automation in a staging environment during the 2026-2027 window, and complete the automation implementation before the March 2027 100-day DCV reuse reduction. By 2029, have ACME automation handling all DCV for public certificates, with paid OV certificates if organizational identity verification is needed.
Frequently Asked Questions
Does the 10-day DCV reuse period apply to private CA certificates?
No. CA/B Forum SC-081v3 applies only to publicly trusted certificates from CAs in browser root programs. Private CA certificates issued for internal systems, device authentication, or private network services are not subject to these requirements. Organizations running private PKI infrastructure can set their own DCV reuse periods. This is one of several operational reasons why the Client Authentication EKU removal (which affects public TLS certificates) is driving organizations toward private CA infrastructure for client certificate use cases.
We use email DCV today because we do not have server or DNS access. What do we do?
This is the situation the SC-090 email DCV sunset will force into resolution. Two paths: first, obtain DNS management access from your DNS provider. Most major DNS providers (Cloudflare, Route 53, GoDaddy, Namecheap) provide API access for DNS record management. DNS-01 DCV via the DNS provider API is automatable with acme.sh’s DNS plugins, which support over 100 DNS providers. Second, if DNS API access is not feasible, obtain access to add files to the web server root directory. HTTP-01 DCV requires placing a specific file at /.well-known/acme-challenge/. On cPanel hosting, this can be done via the File Manager. On managed WordPress hosting, it can be done via SFTP or a file manager plugin. Work with your hosting provider to establish the access level needed for HTTP-01 DCV before the email DCV sunset takes effect.
The 10-day DCV window feels extremely short. Is there a chance it gets extended?
The ballot passed with zero opposition from browser vendors. Apple, Google, Microsoft, and Mozilla all voted yes. The explicit stated intent is to make manual certificate management mathematically impractical and automation mandatory. Forum participants acknowledged this directly during the ballot discussion period. Multiple CA/B Forum participants have stated that the timeline is firm. Planning for 10-day DCV reuse as a fixed constraint by March 2029 is the operationally prudent position. Some forum participants have noted that the ballot includes mechanisms for timeline adjustment if implementation problems are severe, but betting on an extension rather than implementing automation is a risk management decision each organization must make with awareness of the downside.
