Certificate Guidance for CertiNext Transition


Important Dates 

Date 

Milestone 

Before July 17, 2026 

Recommended onboarding and stockpile period 

July 17, 2026 

Final day to issue certificates through Sectigo 

July 17, 2026 

Final day for Sectigo console access 

October 17, 2026 

Last possible expiration date for 199-day Sectigo certificates 

December 31, 2026 

Last day to issue 199-day CertiNext certificates 

January 1, 2027 

Target date for automation adoption 

March 15, 2027 

CA/B Forum maximum certificate validity reduced to 100 days 

March 15, 2029 

CA/B Forum maximum certificate validity reduced to 47 days 

 

Certificates Ordered via Sectigo Console Manager (SCM) 

Early renewal of existing certificates can be used to extend the timeframe for onboarding to the CertiNext platform. For certificates ordered manually through SCM or via ServiceNow that expire before October 17, 2026: 

  • Use the “Renew” option within SCM or ServiceNow just prior to July 17th
  • Download and save the renewed certificate chain in case it is needed during the transition period
  • Renewed certificates will receive a new 199-day validity period
  • Existing CSRs and public keys are retained
  • Subject Alternative Names (SANs) are retained
  • Newly issued certificates function as drop-in replacements for currently deployed certificates 

Replacement certificates issued before July 17 do not require immediate deployment. Existing deployed certificates remain valid until their expiration dates. These stockpiled certificates will only need to be installed if you have any issues migrating to CertiNext and need a longer window for migration.

If migration to CertiNext is completed prior to certificate expiration, deployment of the stockpiled Sectigo certificates is not necessary. 

 

ACME Certificate Guidance 

For certificates managed through ACME:

  • SCM renewal functions are not supported for ACME-managed certificates
  • ACME clients must initiate renewal requests directly
  • IT Providers may choose to renew and install updated Sectigo certificates prior to July 17 for certificates expiring before October 17, 2026
  • After renewal, ensure ACME clients do not continue attempting automatic renewals prior to CertiNext migration activities

Additional CertiNext ACME endpoint guidance will be provided during onboarding. 

 

Automation & Integration Guidance 

As part of the CertiNext transition: 

  • Existing Sectigo automation workflows will require updates
  • ACME clients will need to transition to CertiNext endpoints
  • Organizations currently using Sectigo Network Agents should prepare to migrate toward supported CertiNext automation tools or ACME workflows. CertiNext Bots perform the same function as Sectigo Network Agents.
  • Manual certificate management may be required temporarily for unsupported use cases. Contact your vendors for assistance with edge cases.