SSL Automation: ACME Certificates from PositiveSSL and Sectigo
From 2029 a certificate lives 47 days — set automatic renewal up once and stop watching expiry dates. CA warranty — $50 000
Buy an ACME certificate for 15,90 €
SSL automation means issuing, installing and renewing a certificate over the ACME protocol, with no human involved. It is no longer a convenience: from 15 March 2026 a certificate lives 200 days at most, from 2027 — 100, from 2029 — 47 days, eight reissues a year and more. An ACME subscription costs from €15.90 a year and works with any standard client: certbot, acme.sh, lego, Caddy, Traefik and cert-manager, plus the tools of cPanel, Plesk and DirectAdmin. The Plan + Automate versions from RapidSSL and GeoTrust install and renew the certificate on Apache, NGINX and IIS themselves. Only DV certificates are issued automatically: ACME cannot run a company check.
Certificates with automation
An ACME subscription or ready-made auto-installation, depending on your infrastructure
PositiveSSL ACME Certificate-as-a-Service (DV)
| Domain validation, issued in 5–15 minutes |
| One domain and its www |
| CA warranty $50 000 |
| Free reissues, unlimited servers |
Sectigo ACME Certificate-as-a-Service (DV)
| Domain validation, issued in 5–15 minutes |
| One domain and its www |
| CA warranty $500 000 |
| Free reissues, unlimited servers |
RapidSSL Plan + Automate
| Domain validation, issued in 5–15 minutes |
| One domain and its www |
| CA warranty $10 000 |
| Free reissues, unlimited servers |
Price per year. An ACME subscription reissues the certificate as many times as needed within the term.
Why this became mandatory
The CA/Browser Forum is cutting certificate lifetime in three steps
from 15 March 2026
200 days
two renewals a year
from 15 March 2027
100 days
four renewals a year
from 15 March 2029
47 days
eight renewals and more
with automation
0
manual steps a year
The rule applies to every authority and to every certificate type — DV, OV and EV.
Three ways to automate
The choice depends on where your sites live
An ACME subscription
Works with any ACME client: certbot, acme.sh, Caddy, Traefik or cert-manager in Kubernetes. Fits your own servers and containers.
Auto-installation on the server
The Plan + Automate versions install and renew the certificate on Apache, NGINX and IIS with one command, with expiry alerts.
Control panels
cPanel, Plesk and DirectAdmin speak ACME natively — the certificate is fetched and renewed by the panel itself.
How ACME is set up
Configure it once and it runs on its own
Order the subscription
You pick an ACME certificate and a term and pay. The credentials for the issuance directory appear in your panel.
Configure the client
You put the directory URL and the key into certbot, acme.sh or your panel configuration. We help with the exact command for your server.
Domain validation
The client passes validation itself — with a file on the site or a DNS record, depending on how it is configured.
Renewal without you
The client requests a new certificate in advance, installs it and reloads the web server. Nothing is required from you.
How this differs from Let's Encrypt
The mechanics are the same — the ACME protocol. What differs is what stands behind the certificate:
- A CA warranty — $50,000 with PositiveSSL ACME and $500,000 with Sectigo ACME; free certificates carry none.
- Support. If the client fails validation or automatic renewal breaks, we sort it out.
- Rate limits. Free authorities cap the number of issuances per week; a paid subscription does not.
- Reporting. Every issued certificate is visible in the panel, which helps once there are dozens of them.
When there is nothing to automate with
Sometimes the server is old, the panel has no ACME support, or the certificate is needed on a device where no client can be installed. Then the manual route remains — and it can still be made easier:
- pay for three years at once so payment does not come up every year;
- order installation from us and we will set up the switch to HTTPS;
- turn on expiry reminders in the panel.
Frequently asked questions about automation
ACME, clients and renewal
A protocol for automated certificate issuance. Software on your server requests the certificate, passes domain validation and installs the files itself.
Any standard one: certbot, acme.sh, lego, Caddy, Traefik, cert-manager in Kubernetes and the built-in tools of cPanel and Plesk.
As many as you need within the paid term: the subscription is built for regular reissues.
Yes, IIS has ACME clients such as win-acme, and the Plan + Automate versions install the certificate on IIS by themselves.
The panel warns you before the certificate expires and support helps fix the client. The certificate stays valid until the end of its term.
Only DV certificates are issued automatically: ACME cannot perform a company check. For OV and EV the installation is automated, not the validation.
No. Validation runs over an HTTP file or a DNS record, and neither needs a separate address.
ACME if you run your own servers and have an admin. Plan + Automate if you want a ready-made tool to handle installation and renewal without setup.