Skip to main content

    EV Domain Validation Reuse: The 398-Day Number Is Gone

    Ballot SC102 deleted the 398-day domain reuse cap from the EV Guidelines. EV domain validation now follows the Baseline Requirements: 200 days, then 100.

    MS
    My-SSL Team
    ·
    12 min read
    ·
    Published September 14, 2026
    ·
    Last updated September 14, 2026

    The short answer

    Since ballot SC102 passed on July 14, 2026, the EV Guidelines no longer state their own domain validation reuse period. The Domain Name entry in section 3.2.2.14.3 now points at section 4.2.1 of the Baseline Requirements, so the names in an EV certificate run on the same reuse clock as DV and OV: 200 days for certificates issued on or after March 15, 2026, 100 days from March 15, 2027, and 10 days from March 15, 2029. The 398-day figure that EV documentation carried for years is gone from the text, and it had already stopped applying in March 2026, because the Baseline Requirements apply to EV certificates too and a certificate authority has to satisfy both documents. The organization data behind an EV certificate is a separate clock and still sits at 398 days.

    Ballot SC102 replaced the hardcoded 398-day domain reuse period in the EV Guidelines with a reference to Baseline Requirements section 4.2.1A left box represents EV Guidelines section 3.2.2.14.3, item 1, Domain Name, with the figure 398 days struck through. An arrow labelled SC102, July 14, 2026 points to a right box representing Baseline Requirements section 4.2.1. Three chips below show what that section currently requires: 200 days from March 15 2026, 100 days from March 15 2027, and 10 days from March 15 2029.Where the EV domain reuse limit comes fromEV Guidelines§3.2.2.14.3(1) Domain Name398 daysSC102July 14, 2026Baseline Requirements§4.2.1 validation data reusewhatever it says todayWhat §4.2.1 says for domain and IP validation200 daysfrom Mar 15, 2026100 daysfrom Mar 15, 202710 daysfrom Mar 15, 2029EV now inherits each step without a further EV ballot.
    The important part is the arrow, not the numbers: EV stopped carrying its own copy of the limit, so it can no longer drift out of date the way it did between March and July 2026.

    What ballot SC102 actually changed

    SC102 edited three places in the EV Guidelines, and every edit deletes something rather than adds it. The Domain Name entry in section 3.2.2.14.3 lost its hardcoded 398-day reuse period and now refers to section 4.2.1 of the Baseline Requirements. Section 3.2.2.14.1(6) lost its WHOIS and RDAP same-registrant re-check. Section 6.3.2 stopped stating an EV validity limit and defers to the Baseline Requirements as well.

    The Server Certificate Working Group passed it unanimously, 19 votes to zero among certificate issuers and 2 to zero among browser vendors, and the 30-day intellectual property review that follows every CA/Browser Forum ballot closed on August 13, 2026. A ballot that only removes text is easy to skim past, and this one carried no compliance deadline to force anyone to read it.

    What makes it worth reading is the direction of the change. Before SC102, the EV Guidelines held their own copy of a number that the Baseline Requirements had started moving on a schedule. A copy of a moving number goes stale by definition, and this one did. Replacing it with a reference means the next two steps in that schedule reach EV automatically.

    Why 398 days stopped applying in March 2026

    The EV Guidelines are written as a supplement to the Baseline Requirements, not as a replacement for them, and the Baseline Requirements apply to EV certificates as well. Where the two documents set different limits on the same thing, a certificate authority has to satisfy both, which in practice means the stricter limit governs. Ballot SC-081v3 cut domain validation reuse to 200 days for certificates issued on or after March 15, 2026, and from that date the 200 was the operative number for EV even though the EV text still read 398.

    So between March and July 2026 the EV rulebook and the rule a CA enforced disagreed, in a document that procurement teams and auditors read literally. That is the gap SC102 closed. Nobody had to change a validation pipeline on July 14 because the pipelines were already on 200 days.

    The number outlived the rule in one place that matters, though: written material produced before March 2026. Vendor knowledge-base pages, internal runbooks, renewal checklists and procurement templates that quote 398 days for EV domain validation are not describing a stricter-than-required practice. They are simply wrong now, and the way it surfaces is a renewal that asks for a fresh DNS record or HTTP token when someone expected last year's check to still count.

    Which clock covers domains, which covers you

    An EV order runs on two independent reuse clocks. Domain and IP validation, which proves you control each name in the certificate, follows Baseline Requirements section 4.2.1 and currently allows evidence up to 200 days old. The organization items in EV Guidelines section 3.2.2.14.3 — legal existence, registered address, verified method of communication, and the authority of the people who request and approve the certificate — still cap out at 398 days.

    An EV order runs two validation reuse clocks: 200 days for domain and IP validation and 398 days for organization identity dataTwo panels side by side. The left panel, highlighted in gold, covers domain and IP validation governed by Baseline Requirements section 4.2.1 with a maximum age of 200 days that keeps shrinking. The right panel covers organization identity items governed by EV Guidelines section 3.2.2.14.3 with a maximum age of 398 days that is not on a published reduction schedule.Two reuse clocks in one EV orderThe domains in the certificateBaseline Requirements §4.2.1200 daysand still fallingEvery name in the SAN listDNS record, HTTP token orthe other §3.2.2.7 methodsRe-done per name, not per orderThe organization behind itEV Guidelines §3.2.2.14.3398 daysno published next stepLegal existence and identityAddress of place of businessVerified method of communicationSigner and approver authority
    Only the left panel moved in July 2026. Planning an EV renewal off the right-hand number is how teams end up surprised by a domain check they thought was still fresh.
    What the CA validatedGoverning sectionMaximum ageOn a reduction schedule?
    Control of each domain or IP in the certificateBR §4.2.1200 daysYes — 100 days in 2027, 10 days in 2029
    Legal existence, identity and assumed nameEVG §3.2.2.14.3398 daysNo published next step
    Address of place of business and operational existenceEVG §3.2.2.14.3398 daysNo published next step
    Verified method of communication and signing authorityEVG §3.2.2.14.3398 daysNo published next step

    Both clocks start when the certificate authority collected the evidence, not when you ordered and not when the certificate was issued. That is easy to forget for the domain clock in particular, because a DNS record you published for an order in January has been ageing ever since, whatever you do with the certificate it produced. The organization side of this, including what a re-verification actually involves, is covered in our article on the 398-day clock on your company data.

    One practical consequence of the split: an EV renewal can stall on either clock independently, and the fixes are nothing alike. A stale domain check needs a DNS record or an HTTP file and takes minutes. Stale organization data needs registry lookups, a call to a verified number, and sometimes a signed document. If you buy EV SSL certificates from us, both validations sit with Certum, the publicly trusted CA that issues them from its own roots, rather than being split across an intermediary.

    Is the WHOIS registrant re-check gone?

    Yes, as an EV-specific step. Before SC102, the domain reuse path in EV Guidelines section 3.2.2.14.1(6) asked the certificate authority to confirm through WHOIS or RDAP that the domain was still registered to the same registrant before it reused an earlier validation. That requirement is gone. EV domain re-validation now runs through the ordinary Baseline Requirements methods in section 3.2.2.7, the same ones behind a DV order, with no extra registrant lookup layered on top.

    Removing a check sounds like a weakening, so it is worth being precise about what the check was doing. It compared a registrant record against an earlier one. Registrar redaction has made that comparison thin for years: many WHOIS and RDAP responses now return a privacy-service placeholder rather than the registrant, so the values being compared were often two copies of the same redaction notice.

    The substantive protection against a domain changing hands is the reuse window itself, and it is shrinking fast. A registrant re-check mattered more when validation could be 398 days old than it does at 200 days, and it will matter less again at 10 days, when the CA re-proves control from scratch for practically every issuance.

    Did EV certificate validity change too?

    Not in practice. Maximum certificate validity comes from section 6.3.2 of the Baseline Requirements, which caps certificates issued on or after March 15, 2026 at 200 days regardless of validation level. EV Guidelines section 6.3.2 restated the limit separately, and that duplicate is what SC102 replaced with a reference. The limit a certificate authority enforces is unchanged; only the place you read it moved.

    This is worth stating plainly because the EV Guidelines carried their own validity ceiling for years, and a separate number in a separate document invites the assumption that EV runs on a separate schedule. It does not. An EV certificate issued today expires on the same schedule as a DV certificate issued the same day.

    What happens in 2027 and 2029

    EV inherits the Baseline Requirements schedule automatically now, with no further EV ballot needed. Maximum certificate validity falls to 100 days on March 15, 2027 and 47 days on March 15, 2029. Domain and IP validation reuse falls to 100 days on that same 2027 date, then to 10 days on March 15, 2029 — a far steeper cut than the certificate lifetime beside it.

    Domain validation reuse matches certificate validity in 2026 and 2027 but falls far below it in 2029Three pairs of horizontal bars. In March 2026 both maximum certificate validity and maximum domain validation age are 200 days, and in March 2027 both are 100 days, so one domain check can cover one certificate. In March 2029 certificate validity is 47 days while domain validation may be only 10 days old, so a validation cached from the previous issuance is always stale.Certificate lifetime vs how old the domain check may beCertificate validityMax age of domain checkFrom Mar 15, 2026200 days200 daysFrom Mar 15, 2027100 days100 daysFrom Mar 15, 202947 days10 daysThe gold bar shrinking faster than the grey one is the change worth planning for.
    Through 2027 the two numbers match, so one domain check can carry one certificate. In 2029 they stop matching, and cached validation stops being useful at all.

    The 47-day figure gets the headlines, and it is the wrong number to plan around. Watch the ratio instead. Today, and again after March 2027, the certificate lifetime and the maximum age of the domain check are the same, so a validation performed for one certificate can still be within its window when the replacement is issued. One check, one certificate.

    From March 2029 that stops working. A 47-day certificate replaced on schedule needs domain validation that is at most 10 days old, so evidence gathered for the previous issuance is always stale by the time the next one comes around. Every issuance needs its own fresh proof of control. That is the step that removes the last place a manual DNS edit could hide, and it is the reason the 10-day number deserves more attention than the 47-day one.

    What to change in your EV planning

    Two things: correct the number wherever it is written down, and stop treating the domain check as an annual event. Beyond that, the useful change is in what you track. Most certificate inventories record when each certificate expires. Very few record when each domain was last validated, and after March 2026 those are two different dates that drift apart.

    • Grep your runbooks for 398. Renewal checklists and procurement templates written before March 2026 carry a number that no longer applies to domain validation. The organization-data references to 398 days are still correct, so fix the domain ones and leave the rest.
    • Keep validation reachable, not just openable. A DNS provider you can automate against, or a permanently writable /.well-known/ path, beats a change request you file twice a year. At 10-day reuse, opening a window per renewal stops being viable.
    • Track the validation date per name. For a multi-domain EV certificate, each name in the SAN list has its own validation age. Adding a name to an existing certificate needs that name validated now, whatever the certificate's other names were validated at.
    • Keep the two clocks separate in your calendar. Organization re-verification is the slow one that involves third parties and can add days nobody controls. Domain re-validation is the fast one, and it is now the one that comes round more often.
    • Do not expect an EV exception again. The EV Guidelines now point at the Baseline Requirements for both of these numbers, so EV will follow each future step without a separate announcement to read.

    Frequently Asked Questions

    Get instant answers to common questions about SSL certificates and our services.

    Still Have Questions?

    Our SSL experts are available 24/7 to help with any questions about certificates, installation, or technical issues.

    If your next EV order is coming up

    The reuse rules are identical wherever you buy, so the thing worth comparing is how much of the re-validation your provider handles and how quickly it reaches the CA. Our OV and EV certificates are issued by Certum from its own publicly trusted roots, so the validated organization record and the domain checks stay with the CA that signs your certificate.

    Related reading