Free tool

Free SSL/TLS Certificate Readiness Scan

Find out how your public certificates stack up against the CA/Browser Forum's shrinking certificate lifetimes. We check each domain's certificate and send you a PDF report with your renewal workload, timeline and risks.

Request your free scan

What the scan checks

  • Expiration date

    The exact expiry date of each certificate and how many days are left.

  • Issuer

    Which certificate authority issued each certificate.

  • Lifetime vs. the new limits

    How each certificate's lifetime compares with the 200-day limit (in effect since March 15, 2026), the 100-day limit (March 15, 2027) and the 47-day limit (March 15, 2029).

  • ACME automation

    Whether a certificate looks ACME-automated (for example Let's Encrypt, ZeroSSL or Google Trust Services), which usually means its renewals are already handled.

What's in your report

  • Executive summary

    Your overall risk level and the key numbers at a glance.

  • Scan results

    Each domain's certificate: issuer, expiry date and lifetime compliance.

  • Renewal workload by phase

    Renewals per year at today's and each future lifetime limit, in hours and staff time.

  • Timeline

    What to do before each CA/B Forum deadline.

  • Risk factors

    How certificate volume, compliance, upcoming expirations and automation affect your risk score.

  • Recommendations

    Prioritized next steps for your environment.

Sample report page: Executive Summary with key findings, the overall risk level and a workload table for the 398-, 200-, 100- and 47-day phases
Sample report page: Renewal Calculations showing annual renewals, hours and staff time for each CA/B Forum phase, plus internal PKI recommendations
Sample report page: Certificate Scan Results with a scan summary and one domain’s issuer, expiry date, days left and 200/100/47-day compliance

The CA/B Forum certificate lifetime timeline

  1. March 15, 2026 → maximum lifetime 200 days

    In effect

  2. March 15, 2027 → maximum lifetime 100 days

  3. March 15, 2029 → maximum lifetime 47 days

    Domain validation reuse also drops to 10 days

A public scan only sees part of the picture

An outside scan can only see internet-facing certificates. Certificates on your internal CAs, servers, SAML single sign-on apps and appliances need agent-based discovery from inside your network. That's what CertMS does.

Frequently asked questions

Is it free?

Yes. The scan and the PDF report are free.

What do you do with my domains and email?

We use them to run your scan and send your report, and we may follow up about CertMS. We don't sell your information. See our privacy policy for details.

How long does it take?

While our instant scanner is being rebuilt, we run each scan ourselves and email your report within one business day.

Can you scan internal certificates?

No. A scan from the internet can only see public-facing certificates. Certificates on internal CAs, servers, SSO apps and appliances need agent-based discovery inside your network, which is what CertMS does.

See every certificate, not just the public ones

Book a demo to see CertMS discover certificates across your CAs, servers and SSO apps, or compare plans.