Summary
- Newfold Digital is moving new certificate purchases, renewals and reissues to DigiCert while leaving existing certificates in place until their next replacement.
- Shorter certificate lifetimes increase the importance of completed deployment and exception handling; the announcement does not establish a completed migration or an end-to-end automation rate.
A certificate can be successfully issued while a website still presents the old one. That distinction is the useful place to start with Newfold Digital's choice of DigiCert. The commercial promise is simpler security for small businesses. Delivering it requires someone to own the entire replacement, including the part after a certificate authority has done its work.
In its September 10 announcement, Newfold says DigiCert will handle SSL/TLS certificate issuance and fulfillment across the relevant Network Solutions Group and Bluehost Group businesses. Existing certificates are to remain in use until renewed or reissued. This is a transition through ordinary service events, not an instruction to replace every certificate on announcement day.
The roughly six million customers cited by Newfold describe the wider group. They are not a count of certificates awaiting migration. Nor does the release disclose a total contract value, a completed rollout percentage or a measured reduction in support work. Those missing denominators matter to any attempt to estimate the partnership's economics.
The deadline has already shortened
The current CA/Browser Forum requirements set a 200-day maximum for publicly trusted subscriber TLS certificates issued from March 15, 2026 until before March 15, 2027. The maximum becomes 100 days from March 15, 2027 and 47 days from March 15, 2029. The often-cited 398 days is the earlier limit, not the general ceiling for certificates issued today.
These are issue-date rules. They do not retrospectively shorten every existing certificate. And a maximum is not a recommended renewal schedule: a provider needs room for validation trouble, deployment errors and recovery before expiry.
Domain-control evidence has its own clock. From March 2029, the permitted reuse window for domain and IP-address validation falls to ten days. That is not an instruction to renew every certificate every ten days. It means that issuing a replacement may require fresher evidence than its predecessor's lifetime might suggest.
Fulfillment is not the finish line
Automation can reduce the routine work. RFC 8555 defines ACME for automating certificate issuance and domain validation. It is useful background, not evidence that this partnership uses ACME everywhere. The release does not specify a universal installation mechanism across Newfold's certificate products.
The operating question therefore extends beyond whether an order succeeded. Does the intended endpoint present the replacement? Is a failed validation owned by the hosting team, the customer or a supplier? Can staff identify the affected service without reconstructing its history from invoices?
A staged transition can avoid a single forced cutover, but it also leaves old and new issuer cohorts running together. The apparent convenience is earned only if that coexistence remains legible to support teams. Newfold has announced who will fulfill future certificates; the market still needs evidence of how consistently those replacements reach the services that need them.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
