Analysis finds upcoming certificate changes could cause unexpected renewal failures, as ProteQC
launches a free tool to help identify potential issues

LONDON, UNITED KINGDOM, October 7, 2026 /EINPresswire.com/ — ProteQC, an independent, vendor-neutral post-quantum cryptography (PQC) advisory firm, today published new research highlighting a potentially overlooked certificate security risk facing organisations ahead of major changes taking effect on March 15, 2027.

Beginning that day, publicly trusted Certificate Authorities (CAs) will be required to process additional Certificate Authority Authorization (CAA) parameters that many do not process today. ProteQC’s analysis of the world’s most popular websites found the new RFC 8657 controls almost entirely absent, the main exposure is not that existing records will break, but that the organisations that most need to control which CAs issue their certificates lack this control and may be adopting it for the first time under deadline pressure.

At the same time, public TLS certificates will move to a maximum 100-day lifetime for newly issued certificates, while domain-validation evidence older than 100 days can no longer be reused. Together, these changes mean organisations will need to validate and renew certificates much more frequently, increasing the importance of automated certificate management and accurate configurations.

A DEADLINE THAT MAY BE FLYING UNDER THE RADAR:

ProteQC reviewed published guidance from major national cybersecurity authorities, including NCSC, CISA, ENISA, BSI and ANSSI. As of September 29, 2026, ProteQC found no dedicated national-agency advisory specifically naming either the March 2027 start of RFC 8657 processing or the 100-day validation-reuse deadline. While certificate lifecycle changes have been widely discussed across the PKI industry, ProteQC believes the combined operational impact deserves greater attention outside the specialist community.

“For most organisations, certificates are something that should simply work in the background. What our measurement shows is that the control becoming mandatory in March is simply not there — and with certificates moving to a much shorter lifecycle, the time to put it in place correctly is before the deadline, not under it,” said Tim D. Williams, Chief Technology Officer of ProteQC.

ProteQC LAUNCHES FREE CAA HEALTH CHECK:

To help the industry prepare, ProteQC has launched a free browser-based CAA checker that allows organisations to quickly review a domain’s current CAA configuration and identify potential issues ahead of the March 2027 changes.

Organisations should also use the coming deadline as an opportunity to review their broader certificate management practices, including inventorying publicly trusted certificates and domains, assigning clear ownership, automating issuance and validation, and treating domain validation as a recurring process rather than an annual task.

A PREVIEW OF THE POST-QUANTUM CHALLENGE AHEAD:

The March 2027 changes also point to a much larger challenge facing enterprises: preparing their cryptographic infrastructure for the transition to post-quantum cryptography.

The same capabilities required to manage the upcoming certificate changes, understanding cryptographic assets, establishing ownership, automating processes and responding to externally imposed technology deadlines, will become increasingly important as organisations begin their broader PQC migrations.

“This may look like a certificate issue, but it exposes a much bigger readiness question,” said BJ Miller, Chief Executive Officer of ProteQC. “Organizations need to know what cryptographic assets they have, who owns them and how quickly they can make changes when standards or requirements change. Those same fundamentals will be critical as enterprises prepare for the transition to post-quantum cryptography.”

WHAT ORGANISATIONS SHOULD DO BEFORE 15 MARCH 2027:

1) Inventory every publicly trusted certificate and domain, with a named owner and its validation method.
2) Put automated issuance and validation (ACME or equivalent) on the critical path — renewal is not finished until the new certificate is serving.
3) Audit CAA records for RFC 8657 parameters: correct them against the live CA account, apply them consistently to standard and wildcard issuance, or remove them — and test against a CA that already enforces them. A free client-side check at https://proteqc.com/caa-checker shows a domain’s current position in seconds — no registration, nothing sent to ProteQC (the public DNS resolver sees the query).
5) Treat domain validation as a recurring quarterly control, not an annual event.

Organisations can access ProteQC’s free CAA checker at proteqc.com/caa-checker.

About ProteQC
ProteQC is a vendor-neutral post-quantum cryptography (PQC) advisory firm enabling organisations to achieve crypto-agility and mitigate quantum-era risk. The firm delivers training, assessments, strategy development, and ongoing advisory support to financial institutions, healthcare providers, critical infrastructure operators and their extended supply chains.

Ana Perez
ProteQC
+1 281-400-3161

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Media gallery

About The Author