Your certificate is going to last 47 days

Not a threat and not an opinion: it is the calendar the industry has already agreed. In 184 days the maximum drops to 100, and in 2029 to 47. What you renew once a year today becomes four times, then eight.

At that rate manual renewal stops being an inconvenience and becomes an outage waiting to happen. ACME settles it: your server asks for and renews the certificate by itself, with nobody writing down a date.

200days · today

The maximum in force since March 2026.

100days · 03·2027

Four renewals a year for every certificate.

47days · 03·2029

Eight a year. By hand, this no longer holds.

What ACME is

An open protocol, not anyone's product

ACME — Automatic Certificate Management Environment — is an IETF standard, RFC 8555. It is the same protocol Let's Encrypt uses, and the one certbot, acme.sh, Caddy, Traefik, cert-manager and nearly everything else speaks. Your server proves it controls the domain, asks for the certificate and renews it when the time comes. No emails, no CSRs pasted by hand, no dates.

The difference from Let's Encrypt is not the protocol: it is what stands behind the certificate — a warranty, organisation validation if you need it, support with a name attached, and issuance that does not depend on a free tier's rate limit.

  • NGINX
  • Apache
  • Docker
  • Kubernetes
  • Traefik
  • Caddy

Plus cPanel, Plesk, IIS, HAProxy, Synology, pfSense and anything else that speaks ACME: it is a standard, not an integration of ours.

The comparison

By hand against automated

8 renewals a year per certificate, from March 2029 365 days ÷ a 47-day maximum
80 a year if you run ten domains one every 4.5 working days
26h a year spent only on renewing those ten 80 renewals × 20 minutes each
0 with ACME: nothing to note down, nothing to remember the server renews before expiry
By handACME
Issuing the first one5steps: CSR, validate, download, install, restart1command, and minutes
Renewals a year in 20298for every certificate0of them yours
With ten domains80a year0— the same work as with one
Hours a year on that26hours of somebody's time0after setting it up once
If nobody remembersThe site goes downDoes not apply
Who does itA person, with a reminderThe server

The certificates

Which one is yours

They come in two shapes. The difference is not the quality of the certificate — the same authority issues both — but how you ask for it.

ACME Certificate-as-a-Service

An account that issues whenever you want

We hand you EAB credentials and your ACME client asks the authority for certificates all year, without coming back to the shop.

  • Unlimited issuance through the year
  • The price covers 1 name; additional ones are quoted per name
  • Wildcard available, quoted separately
  • For anyone running several domains or infrastructure that moves

Plan + Automate

A brand certificate, already automated

The same RapidSSL or GeoTrust as always, with the automation included in the price. You buy one and it keeps renewing itself.

  • One certificate: one domain, or a wildcard depending which
  • Automatic renewal included, at no extra cost
  • Site seal and the brand's warranty
  • For one site, or a few, that are not going to change
Certificate Shape Covers Additional names Warranty Price per year
RapidSSLRapidSSL Plan + Automate (DV) Plan + Automate 1 domain USD$10K $44.90 $63
ComodoPositiveSSL ACME Certificate-as-a-Service (DV) ACME CaaS 1 domain up to 100, priced per name USD$50K $49.90 $260
SectigoSectigo ACME Certificate-as-a-Service (DV) ACME CaaS 1 domain up to 100, priced per name USD$500K $69.90 $299
GeoTrustGeoTrust DV Plan + Automate Plan + Automate 1 domain USD$500K $79.90 $168
RapidSSLRapidSSL Wildcard Plan + Automate (DV) Plan + Automate *.yourdomain.com USD$10K $199 $236
GeoTrustGeoTrust DV Wildcard Plan + Automate Plan + Automate *.yourdomain.com USD$500K $299 $708

How it works

Three steps, and then nothing

Your server certbot · acme.sh · Caddy with your EAB credentials The authority Sectigo · GeoTrust · RapidSSL the same one that issues by hand 1 · proves it controls the domain 2 · issues and installs the certificate, in minutes 3 · repeats by itself, before every expiry — whether that is 200 days or 47
You install a client

certbot, acme.sh, or whichever your panel or proxy already ships. Many servers already have one.

You point it at the authority

With the EAB credentials we hand you. Once, and it is done.

You forget about it

The client validates, issues, installs and renews before expiry. Whether that is 200 days or 47.

Questions

What people ask

What about Let's Encrypt, which is free?

Same protocol, and it works. What it does not carry is a warranty, organisation validation, or anybody to call. For a personal site it is enough; for a company answering for its mail or its payments, usually not.

Do I have to generate a CSR?

No. The ACME client does it for you at each issuance, with a fresh key.

Does it do wildcards?

Yes, validating over DNS. On the CaaS products a wildcard is quoted separately; the wildcard Plan + Automate ones already include it.

What are EAB credentials?

A key pair that binds your ACME client to your account with the authority. We hand them over at purchase and they are configured once.

Can I automate an OV or EV certificate?

Issuance yes; the organisation validation happens once and lasts, so the renewals after it are automatic. Write to us and we will look at your case.

What if I already have certificates with you?

They can be migrated without waiting for expiry. We do it with you and without an interruption.

Not sure where to start?

Tell us which server you run and how many domains you have, and we will tell you which ACME client suits you and which of these certificates. If you would rather not touch it, we install it for you.

Tell us about your setup