All posts

Rethinking Application Delivery: Why Shorter Certificate Lifetimes Are a Wake-Up Call

Laptop with TLS lock and expiry countdown – certificates valid for just 47 days

Application delivery — getting applications to their users securely and with strong performance — has grown quietly over the years: a load balancer here, an appliance there, plus a certificate for each system. As long as everything worked, hardly anyone gave it much thought. That is changing right now. A concrete development with a fixed timeline is forcing companies to fundamentally rethink their application delivery: the lifetime of TLS certificates is dropping drastically. Rethinking application delivery starts here: shorter lifetimes are less a burden than a wake-up call.

The trigger: certificate lifetimes are shrinking

The maximum validity period of publicly trusted TLS certificates is being cut sharply in stages. The industry roadmap looks like this:

  • Since March 2026: a maximum of 200 days (previously 398 days).
  • From March 2027: a maximum of 100 days.
  • From March 2029: just 47 days.

For a company with hundreds of certificates, that means from 2029 onward: every single one has to be renewed roughly every seven weeks. Anyone still doing this by hand — system by system, through ticket processes and manual approvals — will inevitably fall behind. And an overlooked or failed certificate rotation takes critical services down: an expired certificate simply makes an application unreachable. In sectors such as banking, insurance, or healthcare, that is not a side note — it is a production outage.

Why traditional application delivery is reaching its limits

Certificates are only the most visible trigger. They expose a structural problem shared by many environments that have grown over the years: configuration happens by mouse click in graphical interfaces, without version control and without proper documentation. Ten years in, often nobody remembers who configured what, when, or why.

Add to that organizational fragmentation: the security department runs the platform, application development wants to roll out new features every week, and DevOps teams have long been working in a highly automated fashion. These worlds speak different languages. While development deploys on a weekly cadence, approving a configuration change can take weeks. That slows everything down — and it also collides with regulatory requirements such as DORA and ISO 27001, which demand complete change histories and audit trails.

The way out: automate instead of click

The answer is a change of principle: away from manual configuration, toward standardization and automation. Infrastructure is described as code, maintained in version control, and rolled out through pipelines. Changes are traceable, repeatable, and can be rolled back at any time. Security is considered from the start ("shift left") instead of bolted on afterwards. And certificate management runs fully automated, regardless of whether a lifetime is 200, 100, or 47 days.

As convincing as that sounds, very few companies want to build such a platform themselves and run it permanently. This is where a cloud-native solution comes into play.

Cloudflare as the solution: delivery and security from one platform

Cloudflare provides application delivery and application security as a single, cloud-native service: globally distributed and without dedicated hardware at every site. For the problems described here, the platform addresses exactly the right points:

  • Automated certificate management: Cloudflare issues TLS certificates and renews them automatically. The problem of shrinking lifetimes practically disappears on its own: no one has to renew manually anymore, whether the lifetime is 47 or 100 days.
  • Integrated application security: Web Application Firewall (WAF), DDoS protection, API protection, and bot management come from the same platform instead of many point solutions that each have to be maintained separately.
  • Global edge delivery: requests are processed and secured at the nearest location. That improves performance and availability without scaling appliances.
  • Configuration as code: via API and Terraform, the entire configuration can be versioned, tested, and rolled out automatically, with a complete change history for audits and compliance.

This turns application delivery from a recurring feat of strength into an automated, traceable process on global infrastructure.

Application security with KAEMI

Whether a platform delivers on its promise is decided in implementation and management. As a Cloudflare partner and managed service provider, we plan, implement, and manage modern application delivery and application security for mid-sized companies — requirements-driven and from a single source.

We set up automated certificate management, configure WAF, DDoS, and API protection around your actual requirements, move the configuration into versioned code, and then take over monitoring, hardening, and ongoing development. That includes clearly agreed response times and a dedicated point of contact. This keeps your environment stable while the conditions around it keep changing.

You can find more on how we secure web applications and APIs on our application security page .

The best time is now

The first step does not have to be a grand transformation. Automated certificate management, standardized templates for common application types, and a staging pipeline for testing changes are enough to get started. Getting started at all — before deadline pressure forces it — matters more than a perfect start. Companies that standardize and automate today will gain a tangible lead in efficiency, security, and compliance within a few years.

For a compact overview of all Cloudflare products for application security, see our Cloudflare page .

Want to protect your web apps and APIs from flaws like this for good?

KAEMI implements and manages WAF, DDoS protection, bot and API management on the Cloudflare platform — as a managed service.