Shorter certificate lifespans are a warning shot for quantum readiness
I’ve sat in enough security roadmap meetings across Australia and New Zealand this year to notice a pattern: quantum computing gets a slide, everyone nods, and then the conversation moves on to whatever’s actually on fire that quarter. That’s fair enough — it’s easy to file quantum risk under ‘2030 problem’ and get back to patching. Except one part of that timeline just stopped being theoretical, and I don’t think most ANZ security teams have clocked it yet.
In April 2025, the CA/Browser Forum voted to shrink the maximum lifespan of SSL/TLS certificates in stages: six months by March 2026, three months by March 2027, and 47 days by March 2029.1 That first cutover is basically here with the certificates issued in March 2026 nearing expiration at the start of October. The main justification is one of security hygiene, because a shorter certificate life means a smaller window if a key gets compromised. I think there’s a second reason, whether the CA/Browser Forum meant it this way or not. It’s forcing organisations to practise something they’re going to need anyway: the ability to replace cryptographic trust quickly, at scale.
The part everyone skips over
NIST finalised its first post-quantum cryptography (PQC) standards back in August 2024.2 The guidance since then hasn’t really changed much: expect RSA and ECC, the algorithms nearly everything runs on today, to be considered unsafe by somewhere around 2030. For ANZ organisations sitting under APRA’s CPS 234,3 the Essential Eight,4 or equivalent expectations from New Zealand’s NCSC, that’s not a comfortable amount of runway. Those frameworks already assume you’re managing cryptographic risk proactively rather than scrambling once a regulator or a customer asks about it.
There’s also a threat that’s live today, not in 2030: ‘Harvest now, decrypt later’. Someone captures your encrypted traffic now and just holds onto it until a quantum computer capable of breaking it exists. Sectigo’s 2025 State of Crypto Agility Report found 60% of organisations globally are very or extremely concerned about that exact scenario, but only 14% have actually gone through and worked out which of their systems would be exposed if it happened.6 I’d guess ANZ isn’t far off that. In most conversations I have here, people know the threat exists long before anyone’s actually inventoried for it.
Two deadlines, one underlying problem
It’s worth being honest about why certificate lifespans and quantum readiness keep coming up in the same conversation. They’re not really two separate initiatives, even though most organisations file them that way. The certificate deadline is the near-term, concrete version of a capability question, while quantum readiness is the long-term version of the same question. Can you actually replace trust across your environment quickly, without half of it breaking on the way through? Get reasonably good at that now, on the certificate side, and you’re most of the way towards being ready for the bigger shift. If you treat them as unrelated line items on two different spreadsheets, you’ll end up solving roughly the same problem twice.
Globally, fewer than one in five organisations said they're ready for monthly certificate renewals, and only 5% have automated the process. I haven’t seen ANZ-specific numbers yet (that data’s coming later this year) but I’d be surprised if the picture here looks any better. Most of the certificate estates I hear about are still tracked manually, sometimes literally on someone’s laptop. That's a certificate lifespan problem today. By the time PQC migration is mandatory, it will be a much bigger one.
What actually needs to happen
Two things need to happen. First, stop treating the certificate lifespan change as a Q1 compliance task and start treating it as what it actually is: a live trial run for how well your organisation manages cryptographic change under a deadline. Second, get quantum readiness onto the board or audit committee agenda now, framed as operational resilience rather than a distant IT concern. There’s a reason the world didn’t implode during Y2K: boards made it their mandate to make sure it was handled with tools and resources. The same thing applies to quantum readiness.
Boards across the region are starting to ask about it. Having an actual answer, even an early one, is a very different position to be in than getting the question cold.
None of this requires solving quantum computing today. It mostly requires not waiting for the deadline to make you deal with a problem you already know is coming.
1. Sectigo 2025, 'CA/Browser Forum passes ballot to reduce SSL/TLS certificates to 47 day maximum term, endorsed by Sectigo', sectigo.com, <<https://www.sectigo.com/resource-library/sectigo-cab-reduce-ssl-tls-certificates-lifespan-47-days>>
2. National Institute of Standards and Technology 2024, 'NIST Releases First 3 Finalized Post-Quantum Encryption Standards', nist.gov, <<https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards>>
3. Australian Prudential Regulation Authority 2019, 'Information security requirements for all APRA-regulated entities', apra.gov.au, <<https://www.apra.gov.au/consultations/information-security-requirements-all-apra-regulated-entities>>
4. Australian Signals Directorate 2023, 'Essential Eight maturity model', cyber.gov.au, <<https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model>>
Autonomous AI agents increasing data risks: report
AI systems surfacing sensitive data to unauthorised users are now the second most common form of...
Why the Five Eyes AI warning should change the Board's cyber agenda
If you don't test your identity recovery in a real-life crisis scenario, you are...
The next cyber threat has arrived and identity security is key for survival
Frontier AI is poised to reshape cybercrime by making sophisticated attacks faster, cheaper and...
