Automation will help, but with 90-, 100-, and eventually 47-day cycles, the margin for unnoticed renewal failures shrinks fast. One bad deploy, broken ACME challenge, or DNS hiccup, and you’re suddenly inside the failure window before anyone notices.
It’s a good time for teams to review their cert workflows, not just issuance, but visibility and alerting too. I built SSL Guardian with that trend in mind, but even if you’re rolling your own monitoring, this change is going to raise the bar for how tightly we need to watch certs.
But until there’s a widely adopted alternative (DANE, peer-to-peer trust, Web of Trust 2.0?), we’re stuck maintaining vigilance within this system. And unfortunately, the shorter cert lifecycles and increasing complexity only make that harder.