SSL Automation: ACME Certificates from PositiveSSL and Sectigo

From 2029 a certificate lives 47 days — set automatic renewal up once and stop watching expiry dates. CA warranty — $50 000

Buy an ACME certificate for 15,90 €
Automatic SSL issuance and renewal over ACME

SSL automation means issuing, installing and renewing a certificate over the ACME protocol, with no human involved. It is no longer a convenience: from 15 March 2026 a certificate lives 200 days at most, from 2027 — 100, from 2029 — 47 days, eight reissues a year and more. An ACME subscription costs from €15.90 a year and works with any standard client: certbot, acme.sh, lego, Caddy, Traefik and cert-manager, plus the tools of cPanel, Plesk and DirectAdmin. The Plan + Automate versions from RapidSSL and GeoTrust install and renew the certificate on Apache, NGINX and IIS themselves. Only DV certificates are issued automatically: ACME cannot run a company check.

Certificates with automation

An ACME subscription or ready-made auto-installation, depending on your infrastructure

15.9 year

PositiveSSL ACME Certificate-as-a-Service (DV)

Domain validation, issued in 5–15 minutes
One domain and its www
CA warranty $50 000
Free reissues, unlimited servers
14.9 year

RapidSSL Plan + Automate

Domain validation, issued in 5–15 minutes
One domain and its www
CA warranty $10 000
Free reissues, unlimited servers

Price per year. An ACME subscription reissues the certificate as many times as needed within the term.

Why this became mandatory

The CA/Browser Forum is cutting certificate lifetime in three steps

from 15 March 2026

200 days

two renewals a year

from 15 March 2027

100 days

four renewals a year

from 15 March 2029

47 days

eight renewals and more

with automation

0

manual steps a year

The rule applies to every authority and to every certificate type — DV, OV and EV.

Three ways to automate

The choice depends on where your sites live

1

An ACME subscription

Works with any ACME client: certbot, acme.sh, Caddy, Traefik or cert-manager in Kubernetes. Fits your own servers and containers.

2

Auto-installation on the server

The Plan + Automate versions install and renew the certificate on Apache, NGINX and IIS with one command, with expiry alerts.

3

Control panels

cPanel, Plesk and DirectAdmin speak ACME natively — the certificate is fetched and renewed by the panel itself.

How ACME is set up

Configure it once and it runs on its own

1

Order the subscription

You pick an ACME certificate and a term and pay. The credentials for the issuance directory appear in your panel.

2

Configure the client

You put the directory URL and the key into certbot, acme.sh or your panel configuration. We help with the exact command for your server.

3

Domain validation

The client passes validation itself — with a file on the site or a DNS record, depending on how it is configured.

4

Renewal without you

The client requests a new certificate in advance, installs it and reloads the web server. Nothing is required from you.

How this differs from Let's Encrypt

How this differs from Let's Encrypt

The mechanics are the same — the ACME protocol. What differs is what stands behind the certificate:

  • A CA warranty — $50,000 with PositiveSSL ACME and $500,000 with Sectigo ACME; free certificates carry none.
  • Support. If the client fails validation or automatic renewal breaks, we sort it out.
  • Rate limits. Free authorities cap the number of issuances per week; a paid subscription does not.
  • Reporting. Every issued certificate is visible in the panel, which helps once there are dozens of them.
See all certificates
When there is nothing to automate with

When there is nothing to automate with

Sometimes the server is old, the panel has no ACME support, or the certificate is needed on a device where no client can be installed. Then the manual route remains — and it can still be made easier:

  • pay for three years at once so payment does not come up every year;
  • order installation from us and we will set up the switch to HTTPS;
  • turn on expiry reminders in the panel.
Order installation

Frequently asked questions about automation

ACME, clients and renewal

A protocol for automated certificate issuance. Software on your server requests the certificate, passes domain validation and installs the files itself.

Any standard one: certbot, acme.sh, lego, Caddy, Traefik, cert-manager in Kubernetes and the built-in tools of cPanel and Plesk.

As many as you need within the paid term: the subscription is built for regular reissues.

Yes, IIS has ACME clients such as win-acme, and the Plan + Automate versions install the certificate on IIS by themselves.

The panel warns you before the certificate expires and support helps fix the client. The certificate stays valid until the end of its term.

Only DV certificates are issued automatically: ACME cannot perform a company check. For OV and EV the installation is automated, not the validation.

No. Validation runs over an HTTP file or a DNS record, and neither needs a separate address.

ACME if you run your own servers and have an admin. Plan + Automate if you want a ready-made tool to handle installation and renewal without setup.